Anti-key escrow SM9 cryptographic system and its collaborative cryptographic method and system
Patent Information
- Application Number
- CN202611107891.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-24
- Publication Date
- 2026-09-22
AI Technical Summary
目前尚缺乏同时实现消除密钥托管和私钥分布式保护、覆盖SM9全部四项密码功能的方案
[0035]本发明有益效果:本发明适用于云计算、移动支付、物联网等私钥安全存储受限的场景。(1)消除密钥托管,KGC即使被攻破也无法恢复用户完整私钥。(2)私钥分布式保护,攻击者需同时攻破客户端和协同服务器。(3)盲化技术实现信息论安全隐私保护。(4)协同/非协同模式公钥一致,验证方无需区分。(5)解密、封装、密钥交换共用统一盲化框架。(6)密钥交换支持单侧/双侧协同。
Smart Images

Figure CN122802146A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of information security and cryptography, specifically relating to an anti-escrow SM9 cryptographic system and its collaborative cryptographic method and system. Background Technology
[0002] The SM9 identifier cryptographic algorithm (GM / T 0044-2016) is my country's national cryptographic industry standard, belonging to the Identity-Based Cryptography (IBC) system, encompassing four cryptographic functions: digital signature, key exchange, key encapsulation, and public-key encryption. In the IBC system, the user's public key is directly derived from their identity identifier, eliminating the overhead of digital certificate management.
[0003] However, the IBC system has an inherent key escrow problem. The Key Generation Center (KGC) holds the master private key for signing. and the signature master public key Regarding user identity KGC computation , Directly calculate the scalar of the complete signature private key. KGC possesses each user's complete private key and can impersonate any user.
[0004] Certificateless public-key cryptography (CL-PKC) was proposed by Al-Riyami and Paterson in 2003. In CL-PKC, a user's complete private key is determined by a portion of the KGC private key and a user-defined secret value. my country's GM / T 0130-2023 standard specifies a certificateless public-key mechanism based on SM2.
[0005] In mobile internet and cloud computing scenarios, even without key escrow, private keys stored on a single device remain at risk of being stolen. Collaborative cryptography divides the private key into multiple shares and stores them distributed, transforming private key protection from a single point of failure to a distributed security problem.
[0006] SM2 is an elliptic curve cryptography for prime fields, with the private key structure as follows: SM9 is an identifier cipher based on bilinear pairing, with a private key structure of... Involving bilinear pairs Because the two elliptic curve groups have fundamentally different algebraic structures, the SM2 scheme cannot be directly translated to SM9. Existing patent CN201410437599 discloses an SM2 collaborative scheme, but it is based on a certificate-based system. GM / T 0130-2023 proposes a certificate-free SM2 system but does not address collaborative computation. Currently, there is a lack of a scheme that simultaneously eliminates key escrow and distributed private key protection, covering all four cryptographic functions of SM9. Summary of the Invention
[0007] To address the shortcomings of existing technologies, this invention provides an anti-escrow SM9 cryptosystem and its collaborative cryptographic method and system. Firstly, this invention transforms the SM9 identifier cryptosystem into an anti-escrow system, eliminating the control of the key generation center over the user's private key. Then, based on this, it provides collaborative signature, collaborative decryption, collaborative key encapsulation / decapsulation, and collaborative key exchange methods to achieve distributed protection of the private key, covering all four cryptographic functions of the SM9 identifier cryptosystem.
[0008] An anti-escrow SM9 signature key and its collaborative signature key system are proposed, which adopt a two-layer progressive structure.
[0009] First layer (system layer): SM9 cryptosystem resistant to key escrow. Users introduce a KGC-agnostic autonomous secret. This makes the complete private key become Signature verification uses the modified signature public key. Encryption, encapsulation, and key exchange use a modified encryption public key. Modifying the public key cannot be done from the identity. Calculated separately.
[0010] The second layer (collaborative layer): Collaborative cryptography method. Building upon the system layer, the private key is divided using a multiplicative structure. Collaborative signatures utilize random number multiplication for segmentation. Collaborative decryption, encapsulation / decapsulation, and key exchange employ a unified blinding / deblinding framework. Key exchange supports both one-sided and two-sided collaboration without increasing the number of rounds for either party.
[0011] This invention discloses an SM9 signature key generation method that resists key escrow, in which the user introduces a signature system-auto-secret unknown to the key generation center (KGC) into their private key. This makes the scalar of the complete signature private key become ,in Sign the master private key for KGC. Generate intermediate values for the key. For user identification, The order of the SM9 elliptic curve group is given; the method includes the following steps: Step G1: User selects signature system for private secrets , The range of values is ,calculate Group public key components and Group public key components ,send Give it to KGC; Step G2: KGC Verification , and pairing consistency ; Calculate identity hash and key to generate intermediate value ,like Then it will be suspended, among which Generate a function identifier for the private key of the signature system. For identity hash value; generate bound random number , The range of values is ; Calculate the combination point and binding parameters , Additive cyclic group generator, For addition cyclic group generator, For signing, use the master public key; calculate the partial private key. scalar value: ; Calculate the corrected signature public key ;Will Return to user; Step G3: User verification and binding parameters Consistency; Verification Correctness; Calculate the complete private key ,save ,destroy .
[0012] Furthermore, in step G2, KGC accesses a portion of the private key. and binding random numbers Encrypted transmission: KGC selects a temporary random number , The range of values is Calculate the temporary public key ; Calculate the shared key using bilinear pairing: Encryption using a symmetric key derived from KDF. Obtain the ciphertext ;Will Return to user; In step G3, the user utilizes Calculate the same shared key Decryption is performed.
[0013] Furthermore, in step G3, the binding parameters are verified: Recalculate and Check if it matches the value returned by KGC: ; Verification in step G3 The equation for correctness is: ; Left side equals The right side equals If both sides are equal, then correct.
[0014] This invention discloses an encryption method for SM9 signature keys that resists key escrow, using KGC to encrypt the master private key. Encrypting the master public key and encrypted identifier Users introduce independent encrypted autonomous secrets. The encryption private key scalar is ; Correct the encryption public key to ; An intermediate value is generated for the key, and the signing private key is in an addition cyclic group. The public key for signing in the addition cyclic group The encrypted private key in the addition cyclic group The public key in the addition cyclic group Signature system's self-owned secret value and the autonomous secret value of the encryption system They are unrelated.
[0015] Furthermore, the encryption method includes: the sender knowingly modifies the public key of the encryption. and system parameters, for messages encryption; Identity ID B The encrypted autonomous secret value; identity ID B The calculated key generates an intermediate value; For addition cyclic group generator, For addition cyclic group The generator; the encryption steps include: Obtain the recipient's corrected encryption public key ; Select random number , The range of values is ; Calculate the first component of the ciphertext ; calculate ,in It is a multiplicative cyclic group. for Group median, pre-computed constant of the encryption system ; Key Derivation , It is the length that needs to be derived. For the identity identifier of the recipient; Calculate the second component of the ciphertext ; Calculate the third component of the ciphertext ; Output ciphertext .
[0016] This invention discloses a method for decrypting an SM9 encryption key that resists key escrow, comprising: during decryption, the receiver holding the encryption private key. , for Encryption private key: verify for Above effective points; Computational shared secrets , ; Key Derivation ; Decrypt message ; verify If they do not match, then reject; Output plaintext .
[0017] This invention discloses a method for generating an SM9 signature key resistant to key escrow, characterized in that the key encapsulation method includes: using... : Get ; choose , The range of values is ; calculate ; Computational shared secrets ; Derived symmetric key ; Output .
[0018] This invention discloses a method for desealing an encapsulated, escrow-resistant SM9 signature key. During desealing, the recipient: verify ; Computational shared secrets , ; derived , .
[0019] This invention discloses a method for exchanging SM9 signature keys that is resistant to key escrow. During the key exchange, both parties use each other's modified encryption public key: Initiator A generates a random number share for the initiator's signature. , The range of values is Calculate the temporary public value Send to responder B; B generates a random number share for responder's signature. , The range of values is Calculate the temporary public value Send to A; B calculates the pairing value involving the private key. Values that do not involve the private key Temporary value Derived shared key A calculates the pairing value involving the private key. Values that do not involve the private key , Derived shared key ; .
[0020] Furthermore, after the key exchange, a third round of key confirmation is included: initiator A and responder B exchange keys. And the hash value of the identity information, and check for consistency.
[0021] This invention discloses a signing method for an SM9 signing key resistant to key escrow, comprising: The signer holds the complete signing private key scalar. and signing private key points and pre-calculated values Regarding the message sign: Select random number , The range of values is ; calculate ,in Multiplication cyclic group The median value, ; Calculate the signature hash ; Calculate temporary variables ,like Then reselect ; Calculate signature value ,like Then reselect ; Output .
[0022] This invention discloses a method for verifying SM9 signature keys that is resistant to key escrow. During signature verification, the verifier obtains a modified signature public key. : examine and for Effective points; Calculate temporary variables ; Calculate the signature hash ; examine .
[0023] This invention discloses an SM9 collaborative signature key generation method that resists key escrow, and in the presence of KGC, client, and collaborative server, generates the complete private key. Divided into multiplication structures The steps include: Step S1: The client generates a temporary secret value. , The range of values is ,calculate and ,send Give it to the collaboration server; For addition cyclic group generator, For addition cyclic group generator, for The client's public key component, for The client's public key component; Step S2: The collaboration server generates a signature private key share. , The range of values is ,calculate and ,in To maintain secrecy, return Secure storage ; for The user's public key component, for The user's public key component; Step S3: The client sends to KGC , For user identification; Step S4: KGC verifies validity and pair consistency ,calculate , For identity hash value, ; Generate intermediate values for the key. ; To bind random numbers; Combination point ; Binding parameters ; Calculate part of the private key scalar value and corrected signature public key , Sign the master private key for KGC and encrypt it. Then return; Step S5: After client decryption and verification, calculate the share of the merged signature private key. ,save ,destroy and Complete private key .
[0024] Furthermore, when collaborative mode is not enabled, step S2 commands... ,at this time , .
[0025] Furthermore, the encryption system's collaborative key generation employs the same three-way multiplication partitioning framework as the signature system, dividing the complete encrypted private key into... ,in To maintain the autonomy and secrecy of the signature system Independent encrypted autonomous secrets; the method for generating an SM9 cooperative cryptographic signature key resistant to key escrow includes the following steps: Step SE1: The client generates a temporary secret value. , The range of values is ,calculate and ,send Give it to the collaboration server; Step SE2: The collaboration server generates a share of the encrypted private key. , The range of values is ,calculate and ,return Secure storage ; Step SE3, the client sends to KGC ; Step SE4, KGC verifies pair consistency ,calculate , Calculate the scalar value of the encrypted private key. and correcting the public key of encryption ,encryption Then return, Encrypt the master private key for KGC; Step SE5: After the client decrypts and verifies, it calculates the share of the merged encrypted private key. ,save ,destroy and The encrypted private key scalar Excluding combination points and binding parameters The factor is distinct from the private key scalar in the signature portion of claim 14. .
[0026] This invention discloses a collaborative decryption method for SM9 collaborative signature keys that resists key escrow. The blinded collaborative decryption method uses the client share of the encrypted private key. and the share of encrypted private key servers Introducing a random blinding factor Protect client share The method includes: Step U1: Client enters ciphertext ,verify ,generate , The range of values is Each decryption is generated independently, and the blinded request is calculated. ,Will Send to the collaboration server, the client does not send. and ; Step U2: Collaboration Server Verification and Validity, calculate the first auxiliary value Second auxiliary value ,return ; Step U3: Client-side deblinding , In the group exponent domain Blinding factor Precise cancellation, ; KDF key derivation: ; Decrypting the plaintext: ; Verify integrity: Calculate And check with If they agree, then reject; Output plaintext .
[0027] Furthermore, when collaboration mode is not enabled, , The client calculates directly. No blinding or server interaction is required.
[0028] This invention discloses a collaborative signature method for SM9 collaborative signature keys that resist key escrow, using a client-side temporary secret value. and the share of the private key for signing with the collaboration server Partitioning by random number multiplication The two parties complete the signing step by step; the method includes: Step T1: Enter the message to be signed The client generates random numbers. , The range of values is Calculate the random commitment value ,send Give it to the collaboration server; Step T2: The collaborative server generates random numbers. , The range of values is Calculate joint random values Calculate the signature hash ,like Then regenerate Otherwise, calculate the first signature component. Second signature component ,return ; Step T3: The client calculates the final signature value. ,like Then return to step T1; otherwise, output... , equivalent to .
[0029] Furthermore, when collaboration mode is not enabled, , The client generates complete random numbers on its own. Independent calculation .
[0030] Furthermore, during signature verification, the verifier obtains the modified signature public key. : examine and for Effective points; calculate ; Calculate the signature hash ; examine .
[0031] This invention discloses a method for encapsulating and decapsulating a collaborative key for an SM9 collaborative signature key that is resistant to key escrow, comprising the following steps: Step K1, the client inputs the encapsulated ciphertext. ,verify Generate random blinding factor , computation blinding request ,send ; Step K2: The collaborative server calculates the first auxiliary value. Second auxiliary value ,return ; Step K3, Client-side deblinding Derived symmetric key .
[0032] This invention discloses a collaborative key exchange method for SM9 collaborative signature keys that resists key escrow. The one-sided collaborative mode includes the following steps: Phase 1: A Calculation Send to B, B calculates. Send to A, B does not enable collaborative direct computation and derived ; Phase Two: Independent Calculation by A Collaborative computing ; Step X1: Client A generates a random blinding factor. , The range of values is , computation blinding request ,send Give A to the collaborative server; Step X2, Server A calculates the first auxiliary value. Second auxiliary value ,return ; Step X3, Client A deblinding ,calculate Derived shared key ; Key negotiation is complete.
[0033] Furthermore, the bilateral collaborative mode includes the following steps: Both A and B enable collaboration. On side A, collaborative calculations are performed according to steps X1 to X3. Symmetrical collaborative computation on side B ; B client generation ,calculate ,send Give the task to server B, and server B will perform the calculation. Then return, and client B removes the blinding process. .
[0034] Furthermore, it also includes a third round of key confirmation: A is calculated independently. B is calculated independently. Each has its own derivatives When collaboration mode is not enabled, .
[0035] The beneficial effects of this invention are as follows: This invention is applicable to scenarios where the secure storage of private keys is limited, such as cloud computing, mobile payment, and the Internet of Things. (1) Eliminating key escrow, even if KGC is compromised, the user's complete private key cannot be recovered. (2) Distributed protection of private keys, attackers need to compromise both the client and the cooperating server simultaneously. (3) Blinding technology achieves information-theoretic security and privacy protection. (4) Public keys are consistent in both collaborative and non-collaborative modes, and the verifier does not need to distinguish between them. (5) Decryption, encapsulation, and key exchange share a unified blinding framework. (6) Key exchange supports one-sided / two-sided collaboration. Attached Figure Description
[0036] Figure 1 This is a flowchart of the anti-escrow signature key generation process of the present invention.
[0037] Figure 2 This is a flowchart of the anti-key escrow SM9 signature and verification process of the present invention.
[0038] Figure 3 This is a flowchart of the SM9 encryption / decryption process for the anti-key escrow method of the present invention.
[0039] Figure 4 This is a flowchart of the SM9 key encapsulation / decapsulation process for the present invention.
[0040] Figure 5 This is a flowchart of the SM9 key exchange process for the anti-key escrow invention.
[0041] Figure 6 This is a flowchart of the collaborative key generation process of the present invention.
[0042] Figure 7 This is a flowchart of the collaborative signature process of the present invention.
[0043] Figure 8 This is a flowchart of the collaborative decryption process of the present invention.
[0044] Figure 9 This is a flowchart of the collaborative key exchange process of the present invention (one-sided collaboration).
[0045] Figure 10 This is a flowchart of the bilateral collaborative key exchange process of the present invention. Detailed Implementation
[0046] The present invention will now be described in further detail with reference to the accompanying drawings and embodiments.
[0047] Part 1 (System Layer): Examples 1 to 5 describe the SM9 cryptographic system that resists key escrow, where users independently hold their complete private keys and no collaborative computation is involved.
[0048] Part Two (Collaboration Layer): Examples 6 to 11 describe collaborative cryptographic methods based on Part One, dividing the complete private key into two shares: one for the client and one for the collaboration server.
[0049] I. Explanation of Symbols
[0050] The main mathematical symbols involved in this invention and their meanings are as follows.
[0051] ID x : The identity identifier of party x.
[0052] SM9 Elliptic Curve The upper level is The additive cyclic group, whose generator is .
[0053] SM9 Twisted Line The upper level is The additive cyclic group, whose generator is .
[0054] : intermediate level The multiplicative cyclic group.
[0055] : 256-bit large prime number, All modulo operations are performed in the modulo domain. The following will proceed.
[0056] Bilinear pairing mapping Satisfies bilinearity Non-degradability And computability.
[0057] Elliptic curve scalar multiplication, i.e., point... self-added The result of this test.
[0058] SM9 cryptographic hash function, maps input of arbitrary length to The integer in the value is used for identity hash calculation.
[0059] : SM9 cryptographic hash function, used for signature hash and binding parameter calculation.
[0060] Private key generation function identifier, Used in signature systems Used in encryption systems.
[0061] Bit string concatenation operation. Bitwise XOR operation.
[0062] KGC signing master private key, randomly selected from Only KGC holds it.
[0063] KGC encrypted master private key, randomly selected from It is held solely by KGC. Signing and encryption use a separate master key.
[0064] The master public key for signing is public.
[0065] The encrypted master public key is public.
[0066] : Pre-calculated constants for the signature system.
[0067] : Pre-computed constants of the encryption system.
[0068] : Key derivation function. Message authentication code function.
[0069] Special symbols for institutional levels: The user signature system's self-defined secret value, randomly selected from... KGC is unknown.
[0070] User-defined encryption system secret value, randomly selected from... KGC is unknown. Signatures and encryption use independent, autonomous secrets.
[0071] Identity hash value .
[0072] Key generation intermediate value, .
[0073] The private key scalar for the signature portion calculated by KGC. .
[0074] : The private key scalar of the encrypted part calculated by KGC.
[0075] The binding random number selected by KGC during key generation is taken from... .
[0076] Combination point .
[0077] : Bind parameters, .
[0078] : Scalar of the complete signature private key .
[0079] : The complete encrypted private key scalar .
[0080] : Signature private key point. : Encrypted private key point. Note that the signing private key is located at... , encrypted private key in Group allocation is swapped.
[0081] : Modify the signing public key; cannot be obtained from Calculated separately.
[0082] : Correct the encryption public key, it cannot be obtained from Calculated separately.
[0083] User public key component ( group).
[0084] User public key component ( group).
[0085] Special symbols for the collaboration layer: : Client-side temporary secret value, randomly selected from Dispose of safely after use.
[0086] : Share of private key for collaborative server signing, randomly selected from Secure storage. When collaboration is not enabled. .
[0087] : Joint secret (implicit, never directly computed).
[0088] : Client merges signature private key shares, .
[0089] : The multiplication and splitting relationship of the complete signature private key.
[0090] : Client share of encrypted private key. Share of the encrypted private key server.
[0091] : Client public key component. Client public key component ( group).
[0092] : Client signature random number share, taken from . Server signature random number share. Implicit random number. It is never calculated by any single party.
[0093] : A random commitment value sent by the client to the server.
[0094] One of the components of the server signature. The second component of the server signature.
[0095] Blinding factor, randomly selected from Each collaborative decryption / unsealing / key exchange is generated independently.
[0096] Client-side blind request.
[0097] The first auxiliary value calculated by the collaborative server, where for (Decrypt / Unblock) or (Key exchange).
[0098] : The second auxiliary value calculated by the collaborative server.
[0099] The shared secret value in the key encapsulation, using Instead To avoid conflicts with signatures Ambiguity.
[0100] II. Anti-escrow SM9 cryptosystem
[0101] Example 1: Anti-escrow Key Generation
[0102] See Figure 1 This embodiment describes how to eliminate the key escrow problem in standard SM9. In standard SM9, the KGC directly calculates the complete private key. This embodiment requires the user to contribute a secret unknown to KGC to the private key. This makes the complete private key become Therefore, the signature public key is corrected to... .
[0103] Key generation process for signature system.
[0104] Step G1 (User generates public key component): (G1a) User selects random autonomous secret , The range of values is .
[0105] (G1b) calculation model inverse element That is, satisfying The value of .
[0106] (G1c) calculation Public key components in the group:
[0107] (G1d) calculation Public key components in the group:
[0108] Need to provide at the same time and The components in the text are missing because SM9 uses Type-3 pairing. arrive Efficient mapping.
[0109] (G1e) will Send to KGC. In collaborative mode, it can also include... (See Example 6), in non-cooperative mode This can be omitted; the KGC processing logic remains unchanged.
[0110] Step G2 (KGC generates partial private key and corrects public key): (G2a) Verification for The valid point on the curve (not at infinity and on the curve).
[0111] (G2b) verification for The effective points on the surface.
[0112] (G2c) verification and Pairing consistency:
[0113] Both equal This verification ensures that both components are derived from the same secret. generate.
[0114] (G2d) Calculate the identity hash value:
[0115] (G2e) Computation key generation intermediate value:
[0116] like This indicates the identity. This cannot be used for signature key generation; the process will be aborted.
[0117] (G2f) Generate bound random numbers , The range of values is .
[0118] (G2g) Calculate the combination point:
[0119] (G2h) Calculate binding parameters:
[0120] (G2i) Calculate a partial private key scalar:
[0121] (G2j) Calculate the modified signature public key:
[0122] (G2k) for partial private keys and binding random numbers Encrypted transmission is performed. KGC selects a temporary random number. , The range of values is Calculate the temporary public key:
[0123] Calculate the shared key using bilinear pairing and the user's public key component:
[0124] pass from Derivate symmetric encryption keys and MAC keys, and encrypt using authentication encryption algorithms such as SM4-GCM, AES-GCM, or SM4-CCM. Encrypted transmission provides both confidentiality and integrity protection.
[0125] (G2l) will Return to user. (The rest of the text is missing.) The ciphertext (including the authentication tag) is encrypted using SM4-GCM.
[0126] Step G3 (User verification and merging of private keys): (G3a) Recover the shared key. The user utilizes their own... Calculate the same shared key:
[0127] The shared key is the same as that calculated by KGC. (Through...) Derived symmetric key, obtained by SM4-GCM decryption GCM certification label verification ensures that the data has not been tampered with.
[0128] (G3b) Verify binding parameters. Recalculate. and Check that the value returned by KGC is consistent:
[0129] (G3c) Verify partial private key Verify the correctness of the equation. Calculate and verify:
[0130] left ;right If both sides are equal, then... correct.
[0131] (G3d) Calculate the scalar of the complete signature private key:
[0132] (G3e) Secure Storage .
[0133] (G3f) Safe Disposal , , and These intermediate values are no longer needed.
[0134] In non-collaborative mode, users directly hold the signature system's proprietary secret value. and the scalar of the fully signed private key In collaborative mode (see Part Two, Example 6), joint secrecy is employed. , The multiplication and splitting relationship of the complete signature private key. It was divided into shares held by the client and the collaboration server, respectively. This is a temporary secret value for the client. Merge the signing private key shares for the client. Sign the private key share for the collaboration server, complete and It never appears in a single entity.
[0135] Encryption system key generation. Encryption system key generation is entirely analogous to signature systems, using a separate cryptographic master private key. Encrypting the master public key and encrypted identifier The encrypted private key scalar is Correct the encryption public key to Note that in the signature system, the private key is... Group, public key in Group; Private key in the encryption system Group, public key in The two groups are interchangeable. The generation of the signing private key and the encryption private key are two independent processes, with the user controlling their secrets. and Unrelated. Partial private key of the encryption system. The verification equation is: .
[0136] Example 2: Anti-key escrow SM9 signature and verification.
[0137] See Figure 2 This embodiment describes the modified signing and verification process. The signing process is exactly the same as the standard SM9 form, the only difference being that the verifier needs to obtain the modified signature public key. .
[0138] Signature process.
[0139] The signer holds the full signing private key. (Scalar) and signature private key point and pre-calculated values Regarding the message sign: (S1a) Select a random number , The range of values is .
[0140] (S1b) Calculation Group median: .
[0141] (S1c) will Convert to a bit string and calculate the signature hash: , for Integers in the range.
[0142] (S1d) calculation .like Then return to step (S1a) and select again. .
[0143] (S1e) Calculate the signature value: .like (Elliptic curve infinity), return to step (S1a).
[0144] (S1f) Output signature Signature format It is exactly the same as the standard SM9.
[0145] Verification and signature process.
[0146] The verifier knows the signer's identity. Modify the signature public key (Requires prior acquisition; cannot be obtained from...) Implicit computation), signature master public key and pre-calculated values Enter message and signature : (S2a) Inspection for Integers in the range.
[0147] (S2b) Inspection for The valid point on the curve (not at infinity and on the curve).
[0148] (S2c) Calculation: ,in .
[0149] (S2d) will Convert to bit string, calculate .
[0150] (S2e) Inspection If they are equal, the signature is valid; otherwise, it is invalid.
[0151] The only difference from standard SM9 signature verification: a modified public key is used in step (S2c). Instead of Implicit Derivation .because Verify equation Established.
[0152] Example 3: Anti-escrow SM9 Encryption and Decryption
[0153] See Figure 3 This embodiment describes the modified encryption and decryption process.
[0154] Why is it necessary to modify the encryption public key? In standard SM9 encryption, the sender obtains the encryption public key from... Implicit computation When encrypting In this scheme, the private key is encrypted. Include If the standard is still used... During decryption extra The factor caused decryption to fail. Therefore, the sender must use the modified encryption public key. .
[0155] The revised encryption process.
[0156] The sender knows that the receiver has modified the encryption public key. and system parameters, for messages encryption: (E1a) Obtain the recipient's corrected encryption public key The public key cannot be obtained from... Separate calculations can be performed using a list of public keys published through KGC signatures, a directory service, or the First Message Exchange (TOFU).
[0157] (E1b) Select random number , The range of values is .
[0158] (E1c) Calculate the first component of the ciphertext: .
[0159] (E1d) calculation Intermediate value (exactly the same as standard SM9): .
[0160] (E1e) Key Derivation: .like If all zeros are present, return to step (E1b).
[0161] (E1f) Symmetric Encryption: .
[0162] (E1g) Message Authentication Code: .
[0163] (E1h) Output ciphertext The encrypted format is exactly the same as the standard SM9.
[0164] Decryption process.
[0165] The recipient holds the encrypted private key. : (E2a) Verification for The effective points on the surface.
[0166] (E2b) Computation of shared secrets: .because and They cancel each other out in the pairing index. .
[0167] (E2c) Key Derivation: .
[0168] (E2d) Decrypt plaintext: .
[0169] (E2e) Verify integrity: Calculate And check with If they are consistent, then reject.
[0170] (E2f) Output plaintext .
[0171] Example 4: Anti-escrow SM9 key encapsulation / decapsulation
[0172] See Figure 4 Key Encapsulation Mechanism (KEM) is used for the secure transmission of symmetric keys. To avoid ambiguity, it uses... This indicates that the encapsulation shares a secret. Consistent with cryptographic analysis, the encapsulation uses a modified public key. .
[0173] Packaging process.
[0174] Sender known : (E3a) Obtain the recipient's corrected encryption public key .
[0175] (E3b) Select random number , The range of values is .
[0176] (E3c) Compute Encapsulated Ciphertext: .
[0177] (E3d) Computation shared secret: .
[0178] (E3e) Derived symmetric key: .
[0179] (E3f) Output . Used for subsequent symmetric encryption. Send to the recipient.
[0180] The process of lifting the lockdown.
[0181] The recipient holds : (E4a) Verification for The effective points on the surface.
[0182] (E4b) Computation of shared secrets: .
[0183] (E4c) Derived symmetric key: .
[0184] because and They cancel each other out in the pairing index. ,therefore .
[0185] Example 5: Anti-escrow SM9 key exchange
[0186] See Figure 5 A calculation in standard SM9 key exchange This scheme requires the use of a modified encryption public key.
[0187] Round A, Round 1 (Initiator): (C1a) A obtains B's corrected encryption public key .
[0188] (C1b) A generates random numbers , The range of values is .
[0189] (C1c)A calculates the provisional public value: .
[0190] (C1d)A will Send to B.
[0191] Second round on side B (responder): (C2a) B obtains A's modified encryption public key. .
[0192] (C2b)B generates random numbers , The range of values is .
[0193] (C2c)B calculates the provisional public value: .
[0194] (C2d)B calculates the pairing value involving the private key: This step is the only operation on side B involving the private key.
[0195] (C2e)B calculates values that do not involve the private key: .
[0196] (C2f)B Calculation: .
[0197] (C2g)B Derived Shared Key: .
[0198] (C2h)B will Send to A.
[0199] Side A completed: (C3a) A calculates a value that does not involve the private key: .
[0200] (C3b)A calculates the pairing value involving the private key: This step is the only operation on side A involving the private key.
[0201] (C3c)A Calculation: .
[0202] (C3d)A Derived Shared Key: .
[0203] because and They cancel each other out in the pairing index. , ,therefore .
[0204] Optional third round of key confirmation: A and B exchange keys. The hash value of the identity is used to check for consistency. Key verification only involves hash comparison, does not require a private key, and is unaffected by the modifications made to this scheme.
[0205] Public key distribution method.
[0206] Modify public key and It can be distributed in the following ways: (1) KGC signs the modified public key when generating the key and then publishes it. The verifier / encryptor / exchange party verifies the authenticity of the public key through the KGC signature; (2) Distribution through directory services or public key infrastructure; (3) Exchange on first use (TOFU), which is suitable for peer-to-peer scenarios. KGC interface uniformly accepts In collaborative mode, it can be accompanied by In non-cooperative mode Omitted, the KGC processing logic remains unchanged.
[0207] Part Two: Collaborative Cryptography Methods
[0208] The following embodiments, based on the first part of the anti-key escrow system, further divide the user's private key into two parties, so that the complete private key never appears in any single entity.
[0209] Example 6: Collaborative Key Generation
[0210] Collaborative signature key generation: See Figure 6 This embodiment further divides the complete private key generated in the first part into multiplicative components. .
[0211] Step P1 (Client generates secret value): (P1a) The client generates a random secret value. , The range of values is .
[0212] (P1b) Calculation model inverse element .
[0213] (P1c) Calculation Group public key components: .
[0214] (P1d) calculation Group public key components: .
[0215] (P1e) will Send to the collaboration server.
[0216] Step P2 (Cooperative server generates shares): (P2a) The collaborative server generates random shares. , The range of values is .
[0217] (P2b) Calculation model inverse element .
[0218] (P2c) Calculate the joint public key components: ,in It is a joint secret (implicit, never directly computable).
[0219] (P2d) Calculate the joint public key components: .
[0220] (P2e) Return Secure storage for clients .
[0221] If collaborative mode is not enabled, the collaborative server will not participate, making ,at this time , The subsequent process will not be affected.
[0222] Step P3 (Client requests partial private key from KGC): The client will... Send to KGC. Used for transmitting the private key for the KGC encryption part.
[0223] Step P4 (KGC generates partial private key): KGC performs the same operation as step G2 in Example 1: (a) Verification and Validity and pair consistency (b) Calculation , (c) Generate bound random numbers (d) Calculate the combination point and binding parameters (e) Calculate a portion of the private key and corrected signature public key (f) Use encryption Then return to the client.
[0224] Step P5 (Client completes key setup): (P5a) Use Decryption Recalculate And verify.
[0225] (P5b) Verification Correctness (verification equation is the same as step G3 in Example 1).
[0226] (P5c) Calculate the merged private key share:
[0227] (P5d) Safe Storage .
[0228] (P5e) Safe Disposal , and These values are no longer needed.
[0229] Complete private key relationship derivation. The key generation is now complete, and the client holds it. Collaboration server holds Fully signed private key It never appears in any single entity.
[0230] Collaborative key generation for the encryption system. The collaborative key generation for the encryption system uses the same three-way multiplication partitioning framework as the signature system, which involves generating the complete encrypted private key. Divided into The client holds Collaboration server holds The differences from signature systems are twofold: first, they use a separate cryptographic master private key. Encrypting the master public key and encrypted identifier Users introduce independent encrypted autonomous secrets , and the secret of signature autonomy They are unrelated; secondly, the derivation of the SM9 encrypted private key does not contain combination points or binding parameters. The factor is such that the scalar value of the encrypted private key calculated by KGC is... The client will no longer multiply by when merging. The specific steps are as follows: Step SE1: The client generates a temporary secret value. , The range of values is Calculate its modulus inverse element ,calculate Group public key components and Group public key components ,Will Send to the collaboration server.
[0231] Step SE2: The collaborative server generates a share of the encrypted private key. , The range of values is Calculate its modulus inverse element Calculate the joint public key components and ,in This is a cryptographic joint secret (implicitly existing and never directly computed). Returned to the client, securely stored If collaborative mode is not enabled, then... ,at this time , The subsequent process will not be affected.
[0232] Step SE3: The client identifies the user. , Joint public key components and Send to KGC. Unlike signature systems, the private key is not included in the encryption part. Factors, no need to attach .
[0233] Step SE4: KGC Verification and Validity and pairing consistency Calculate the identity hash value and key to generate intermediate value ; Calculate the scalar value of the encrypted private key ,in Calculate the master private key for KGC encryption; calculate the modified public key for encryption. Use the same secure channel protocol as the signature system. After SM4-GCM authentication and encryption, the data is returned to the client.
[0234] Step SE5: Client decrypts to obtain After verifying its correctness, the share of the merged encrypted private key is calculated. Store safely Safe disposal , and .
[0235] Derivation of complete encrypted private key relationships. , and the system-level encryption private key Consistent definitions. Generated client shares. With server share A blinded framework directly used in Example 8 (collaborative decryption), Example 9 (collaborative decryption), and Example 10 (collaborative key exchange). Decryption correctness verification: Ciphertext components. ,pair ,in and Cancellation and Cancellation, correct recovery This is precisely the correction of public key premultiplication. To offset the private key Its function.
[0236] Example 7: Collaborative Signature
[0237] See Figure 7 This embodiment describes how the client and the collaborating server collaborate to complete an SM9 signature. The client holds a share of the signing private key. Collaboration server holds .
[0238] Signature formula transformation.
[0239] Standard Signature ,in , Suppose that the random number is divided by multiplication. , Generated by the client, Generated by the server. Defines the server signature components. and Then the client can synthesize .
[0240] Step T1 (Client initiates signature request): (T1a) Enter the message to be signed .
[0241] (T1b) Generate random numbers , The range of values is .
[0242] (T1c) calculation model inverse element .
[0243] (T1d) Calculate the random commitment value:
[0244] (T1e) will Send to the collaboration server.
[0245] Step T2 (Cooperation server calculates signature components): (T2a) Generate random numbers , The range of values is .
[0246] (T2b) Calculation model inverse element .
[0247] (T2c) Calculate the joint random value:
[0248] At this time, the combined random number Implicitly determined, but the server is unaware of it. The specific value (because it is unknown) ).
[0249] (T2d) will Convert to a bit string and calculate the signature hash: .
[0250] (T2e) If Regenerate And return to step (T2c).
[0251] (T2f) Calculate the first signature component:
[0252] (T2g) Calculate the second signature component:
[0253] (T2h) will Returned to the client.
[0254] Step T3 (Client completes signing): (T3a) Calculate the final signature value:
[0255]
[0256] Expand: .
[0257] (T3b) If (Elliptic curve infinity), return to step T1 to re-sign.
[0258] (T3c) Output signature .
[0259] Signature format Exactly the same as standard SM9, the verifier uses the signature verification method in step S2c. Verify signature validity. The verifier does not need to distinguish whether the signature was generated through collaborative mode.
[0260] When collaboration is not enabled , The client selects the random number itself. Independent calculation .
[0261] Example 8: Collaborative Decryption with Blinding
[0262] See Figure 8This embodiment describes how to collaboratively complete SM9 decryption by both the client and the collaborative server without revealing the secrets of either party.
[0263] The core operation of SM9 decryption is calculating the pairing value. ,in For encrypted components, The encrypted private key is split between the two parties. If the client sends it directly... Give it to the server, and the server can deduce from it. Information. This scheme introduces a random blinding factor. This prevents the server from extracting information from the received data. .
[0264] Step U1 (Client-side blinding): (U1a) Input ciphertext .
[0265] (U1b) Verification for The valid point on the curve (not at infinity and on the curve).
[0266] (U1c) generates random blinding factor , The range of values is Each decryption operation generates a unique random number.
[0267] (U1d) Compute blinding request:
[0268] because exist Uniform randomness in the middle exist The upper part is evenly distributed, therefore exist Uniformly distributed in the group, completely independent The value. Even if the collaborative server has unlimited computing power, it cannot obtain it from... Extract Any information.
[0269] (U1e) will Send to the collaboration server. Note that the client does not send. and The server does not handle plaintext data.
[0270] Step U2 (Collaborative Server Computation): (U2a) Verification for The effective points on the surface.
[0271] (U2b) verification for The effective points on the surface.
[0272] (U2c) using its own share of encrypted private key Calculate the first auxiliary value:
[0273] exist In the group exponent domain, Equivalent to .
[0274] (U2d) Calculate the second auxiliary value:
[0275] exist In the group exponent domain, Equivalent to . Includes , and The blending effect Only contains The effect.
[0276] (U2e) will Returned to the client.
[0277] Step U3 (Client deblinding and decryption completed): (U3a) in Perform deblinding operation in the group:
[0278] Deblinding principle: In In the group exponent domain, The index is , The index is Adding the two together:
[0279] Blinding factor The contribution was precisely canceled out. Therefore:
[0280] (U3b) Key Derivation: .
[0281] (U3c) Decrypt plaintext: .
[0282] (U3d) Verify integrity: Calculate And check with If they are consistent, then reject.
[0283] (U3e) Output plaintext .
[0284] Random blinding factor make exist Uniformly distributed in the group: exist Evenly distributed on top Completely independent The value; this is perfect blinding in the information theory sense, meaning that even if the collaborative server has unlimited computing power, it cannot obtain it. extract Any information.
[0285] When collaboration is not enabled , The client calculates directly. No blinding or server interaction is required.
[0286] Example 9: Cooperative Key Encapsulation / Decapsulation
[0287] This embodiment describes how to use the blinding / deblinding framework of Embodiment 8 for collaborative key encapsulation / decapsulation.
[0288] Key Observation. A comparison of the core operations involved in decryption and unlocking of the private key: during decryption... In the process of lifting the lockdown Both are completely identical in mathematical structure—they are... one element and Chinese user encrypted private key Bilinear pairing, i.e. The structure. The difference lies only in subsequent processing: decryption requires... Decryption after deriving the key And verify Unsealing directly A symmetric key is derived using KDF. Therefore, the blinding / deblinding protocol of Example 8 can be used unchanged for collaborative desealing.
[0289] Step K1 (Client-side blinding): (K1a) Input Encapsulated Ciphertext .
[0290] (K1b) verification for The effective points on the surface.
[0291] (K1c) generates random blinding factor , The range of values is .
[0292] (K1d) Compute blinding request: .
[0293] (K1e) will Send to the collaboration server.
[0294] Step K2 (Collaborative Server Computation): (K2a) verification and Validity.
[0295] (K2b) Calculate the first auxiliary value: .
[0296] (K2c) Calculate the second auxiliary value: .
[0297] (K2d) return For the client.
[0298] Step K3 (Client-side deblinding): (K3a) calculation The deblinding principle is exactly the same as step U3 in Example 8. Items precisely offset, .
[0299] (K3b) Derived symmetric key: .
[0300] From an implementation perspective, collaborative decryption can fully reuse the underlying code of collaborative decryption. (When collaboration is not enabled) The client calculates directly. .
[0301] Example 10: Collaborative Key Exchange
[0302] See Figure 9 and Figure 10 This embodiment describes how to use the blinding / deblinding framework for SM9 key exchange. Key exchange involves private key pairing operations—on side A. Side B —Similarly possess structure( This is a temporary public value sent by the other party. (Using our own encrypted private key), employing the same blinding protocol as in Example 8. The remaining operations ( , , KDF (Knowledge, Technology, and Validation) only involves public parameters or temporary random numbers, which can be completed independently by the client.
[0303] Key exchange is a two-party protocol, and both A and B may enable collaboration, resulting in three scenarios: collaboration only by A (one-sided), collaboration only by B (symmetric, one-sided), and collaboration by both A and B (two-sided).
[0304] Unilateral coordination ( Figure 9 Assume A enables collaboration (). ), B is not enabled.
[0305] Phase 1 (Exchange temporary public values, no coordination required): (X1a)A calculation ,send Give it to B.
[0306] (X1b)B calculation ,send Give it to A.
[0307] (X1c)B does not enable collaboration and computes directly. (Involves private keys) , , derived .
[0308] Phase Two (A-side Collaborative Computing) ): A received Then, calculate independently. (Does not involve private keys). Collaborative computation is required. .
[0309] Step X2 (Blinding Client A): (X2a) Generate random blinding factor , The range of values is .
[0310] (X2b) Compute blinding request: .
[0311] (X2c) will Send to A's collaborative server.
[0312] Step X3 (A Collaborative Server Calculation): (X3a) Verification for Above effective points, for The above is a valid point.
[0313] (X3b) Calculate the first auxiliary value: .
[0314] (X3c) Calculate the second auxiliary value: .
[0315] (X3d) Return Give it to client A.
[0316] Step X4 (Client A completes deblinding): (X4a) Deblinding: The principle of deblinding is exactly the same as step U3 in Example 8.
[0317] (X4b) calculation .
[0318] (X4c) Derived Shared Key: .
[0319] Key negotiation is complete.
[0320] Bilateral synergy ( Figure 10 Both A and B have enabled collaboration.
[0321] Phase 1 (Exchange of Temporary Public Values): Exactly the same as unilateral coordination, A and B exchange... and .
[0322] Phase Two (Parallel Collaborative Computation on Both Sides): Side A performs collaborative calculations according to steps X2-X4. (As mentioned above).
[0323] B-side symmetrical collaborative computation : (a) Client B generates blinding factor , The range of values is .
[0324] (b) Client B calculation ,Will Send to B's collaborative server.
[0325] (c) B Collaborative Server Computation and ,return .
[0326] (d) Client-side deblinding .
[0327] The collaborative processes on side A and side B are completely parallel—they process different data. right ), using different private key shares ( right The blinding factors are generated independently. There is no need for direct communication between the two collaborative servers.
[0328] Phase Three (Completed Independently): A. Independent Calculation B is calculated independently. Each has its own derivatives Collaboration does not increase the number of communication rounds between A and B (it always consists of 2 rounds plus an optional 3rd round for key confirmation). Additional interactions only occur between their respective clients and the collaboration server (one round trip for each). In bilateral collaboration, both sides can execute in parallel without increasing latency. Whether A uses collaboration is completely transparent to B—B cannot distinguish whether A performs direct computation. It can be accomplished through collaboration, or vice versa.
[0329] When collaboration is not enabled This degenerates into the standard key exchange process of Example 5.
[0330] Example 11: Compatibility between cooperative and non-cooperative modes
[0331] An important feature of this invention is the transparent compatibility between cooperative and non-cooperative modes.
[0332] In both modes, the user modifies the public key in exactly the same way: This public key only depends on (by user identity) and the master private key (Confirm) and (Determined during key generation), and completely independent of whether collaboration is enabled in subsequent signing, decryption, unsealing, or key exchange.
[0333] This means that: the verifier does not need to know whether the signer is using collaborative mode; the encryptor / encapsulator does not need to know whether the decryptor / uncapsulator is using collaborative mode; and the key exchange partner does not need to know whether it is using collaborative mode. The public key distribution and authentication processes remain consistent. Users can configure [the system] without changing their public key. (Incoordination) or Switch between two modes for random values (with collaboration enabled).
[0334] Security Analysis
[0335] Key security. Full private key. Recovery requires simultaneous acquisition of joint secrets. (or client share) and server share ) and KGC key parameters In the following six attack scenarios, attackers will not be able to recover the complete private key. : (1) Only KGC was breached (gained) ): Lack of joint secrets From the public recover This is an elliptic curve discrete logarithm problem.
[0336] (2) Only the client is compromised (gaining access) ):Lack From collaborative signature interaction data China Resumption This is an elliptic curve discrete logarithm problem.
[0337] (3) Only the collaborative server was compromised (gained) ):Lack In collaborative interaction data It does not appear directly.
[0338] (4) KGC colludes with the client ( Known: Still missing ,recover The problem is reduced to the discrete logarithm problem.
[0339] (5) KGC colludes with the server ( (Known): It was destroyed after key generation, from recover This is a discrete logarithm problem.
[0340] (6) Client-server cooperation ( Known: Recoverable This is allowed by design and is equivalent to the user having the full private key.
[0341] Collaborative signature privacy. The collaborative server receives... for Elements in a group. Mapping yes arrive The double radiation, therefore exist Uniformly distributed in the middle, excluding Any information received by the client. No signatures beyond the final public release will be provided. Additional information available.
[0342] Blinding safety. Blinding factor. make exist They are evenly distributed within the group. The collaborative server is unaware of this. Unable to perform deblinding operation Therefore, the final result of decryption / unsealing / key exchange cannot be calculated. The three operations of collaborative decryption, collaborative unsealing, and collaborative key exchange use the exact same blinding / deblinding protocol (the core operations are all...). (Structure), inheriting the exact same security properties.
[0343] Malicious collaboration server. Malicious collaboration server tampering. or (or in key exchange) This only results in a denial of service (decryption failure or) This method does not reveal the share of the private key. An optional third round of key verification during key exchange can detect such attacks. (Blinding factor) Protected even under active attack ,because The uniform distribution property does not depend on the behavior of the server.
[0344] System Implementation. This invention can be implemented as a system comprising the following modules: (1) a KGC server module, responsible for system initialization, generating master key pairs, generating partial private keys and correcting public keys for users; (2) a client module, running on the user device, responsible for generating self-secret values, merging private key shares, initiating collaborative signature and decryption requests; and (3) a collaborative server module, acting as a cloud server, responsible for securely storing private key shares. and 1. Participate in collaborative signature and blinded auxiliary calculation; (4) Communication module, a secure communication channel between entities, which can use protocols such as TLS / SSL to protect data transmission; (5) Key management module, responsible for the secure storage, use and destruction of keys, which can use hardware security module (HSM) or trusted execution environment (TEE) to protect key keys.
[0345] The above are merely preferred embodiments of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to the embodiments, those skilled in the art can still modify the technical solutions described in the foregoing embodiments or make equivalent substitutions for some of the technical features. However, any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. A method for generating an SM9 signature key resistant to key escrow, characterized in that, The user introduces a signature system-auto-secret into the private key that is unknown to the Key Generation Center (KGC). This makes the scalar of the complete signature private key become ,in Sign the master private key for KGC. Generate intermediate values for the key. For user identification, The order of the SM9 elliptic curve group is given; the method includes the following steps: Step G1: User selects signature system for private secrets , The range of values is ,calculate Group public key components and Group public key components ,send Give it to KGC; Step G2: KGC Verification , and pairing consistency ; Calculate identity hash and key to generate intermediate value ,like Then it will be suspended, among which Generate a function identifier for the private key of the signature system. For identity hash value; generate bound random number , The range of values is ; Calculate the combination point and binding parameters , For addition cyclic group generator, For addition cyclic group generator, For signing, use the master public key; calculate the partial private key. scalar value: ; Calculate the corrected signature public key ;Will Return to user; Step G3: User verification and binding parameters Consistency; Verification Correctness; Calculate the complete private key ,save ,destroy .
2. The method for generating an SM9 signature key against key escrow according to claim 1, characterized in that, In step G2, KGC accesses a portion of the private key. and binding random numbers Encrypted transmission: KGC selects a temporary random number , The range of values is Calculate the temporary public key ; Calculate the shared key using bilinear pairing: Encryption using a symmetric key derived from KDF. Obtain the ciphertext ;Will Return to user; In step G3, the user utilizes Calculate the same shared key Decryption is performed.
3. The method for generating an SM9 signature key against key escrow according to claim 1, characterized in that, Verify the binding parameters in step G3: Recalculate and Check if it matches the value returned by KGC: ; Verification in step G3 The equation for correctness is: ; Left side equals The right side equals If both sides are equal, then correct.
4. An encryption method for generating an anti-escrow SM9 signature key according to claim 1, characterized in that, Use KGC to encrypt the master private key. Encrypting the master public key and encrypted identifier Users introduce independent encrypted autonomous secrets. The encryption private key scalar is ; Correct the encryption public key to ; An intermediate value is generated for the key, and the signing private key is in an addition cyclic group. The public key for signing in the addition cyclic group ; Encrypting private key in addition cyclic group The public key in the addition cyclic group Signature system's self-owned secret value and the autonomous secret value of the encryption system They are unrelated.
5. The encryption method for the anti-escrow SM9 signature key according to claim 4, characterized in that, Encryption methods include: the sender knowing the recipient's modified public key. and system parameters, for messages encryption; Identity ID B The encrypted autonomous secret value; identity ID B The calculated key generates an intermediate value; For addition cyclic group generator, For addition cyclic group The generator; the encryption steps include: Obtain the recipient's corrected encryption public key ; Select random number , The range of values is ; Calculate the first component of the ciphertext ; calculate ,in It is a multiplicative cyclic group. for Group median, pre-computed constant of the encryption system ; Key Derivation , It is the length that needs to be derived. For the identity identifier of the recipient; Calculate the second component of the ciphertext ; Calculate the third component of the ciphertext ; Output ciphertext .
6. A decryption method for an anti-escrow SM9 encryption key generated according to claim 4 or 5, characterized in that, include: The recipient holds the encrypted private key during decryption. , for Encryption private key: verify for Above the effective points; Computational shared secrets , ; Key Derivation ; Decrypt message ; verify If they do not match, then reject; Output plaintext .
7. A key encapsulation method for an anti-escrow SM9 signature key generated according to claim 1, characterized in that, Key encapsulation methods include: using key encapsulation... : Get ; choose , The range of values is ; calculate ; Computational shared secrets ; Derived symmetric key ; Output .
8. A method for desealing an anti-escrow SM9 signature key encapsulated according to claim 7, characterized in that, Recipient upon lifting of lockdown: verify ; Computational shared secrets , ; Derivation , .
9. A method for exchanging an anti-escrow SM9 signature key generated according to claim 1, characterized in that, During key exchange, both parties use each other's modified encryption public key: Initiator A generates a share of the initiator's signature random number. , The range of values is Calculate the temporary public value Send to responder B; B generates a random number share for responder's signature. , The range of values is Calculate the temporary public value Send to A; B calculates the pairing value involving the private key. Values that do not involve the private key Temporary value Derived shared key A calculates the pairing value involving the private key. Values that do not involve the private key , Derived shared key ; .
10. The method for exchanging SM9 signature keys against key escrow according to claim 9, characterized in that, Following the key exchange, a third round of key confirmation is also included: Initiator A and Response B exchange keys. And the hash value of the identity information, and check for consistency.
11. A signing method for an anti-escrow SM9 signing key generated according to claim 1, characterized in that, Signature methods include: The signer holds the complete signing private key scalar. and signing private key points and pre-calculated values Regarding the message sign: Select random number , The range of values is ; calculate ,in Multiplication cyclic group The median value, ; Calculate the signature hash ; Calculate temporary variables ,like Then reselect ; Calculate signature value ,like Then reselect ; Output .
12. A method for verifying an SM9 signature key generated according to claim 11, characterized in that, During signature verification, the verifier obtains the modified signature public key. : examine and for Effective points; Calculate temporary variables ; Calculate the signature hash ; examine .
13. A method for generating an SM9 collaborative signature key that is resistant to key escrow, based on the method described in any one of claims 1-12, characterized in that, With the participation of KGC, client, and collaboration server, the full private key will be... Divided into multiplication structures The steps include: Step S1: The client generates a temporary secret value. , The range of values is ,calculate and ,send Give it to the collaboration server; For addition cyclic group generator, For addition cyclic group generator, for The client's public key component, for The client's public key component; Step S2: The collaboration server generates a signature private key share. , The range of values is ,calculate and ,in To maintain secrecy, return Secure storage ; for The user's public key component, for The user's public key component; Step S3: The client sends to KGC , For user identification; Step S4: KGC verifies validity and pair consistency ,calculate , For identity hash value, ; Generate intermediate values for the key. ; To bind random numbers; Combination point ; Binding parameters ; Calculate part of the private key scalar value and corrected signature public key , Sign the master private key for KGC and encrypt it. Then return; Step S5: After client decryption and verification, calculate the share of the merged signature private key. ,save ,destroy and Complete private key .
14. The method for generating an SM9 collaborative signature key against key escrow according to claim 13, characterized in that, When collaborative mode is not enabled, in step S2, the command is... ,at this time , .
15. The method for generating an SM9 collaborative signature key against key escrow according to claim 13, characterized in that, The encryption system's collaborative key generation employs the same three-way multiplication partitioning framework as the signature system, dividing the complete encrypted private key into... ,in To ensure the signature system's autonomy and secrecy Independent encrypted autonomous secrets; The method for generating an SM9 collaborative cryptographic signature key that is resistant to key escrow includes the following steps: Step SE1: The client generates a temporary secret value. , The range of values is ,calculate and ,send Give it to the collaboration server; Step SE2: The collaboration server generates a share of the encrypted private key. , The range of values is ,calculate and ,return Secure storage ; Step SE3, the client sends to KGC ; Step SE4, KGC verifies pair consistency ,calculate , Calculate the scalar value of the encrypted private key. and correcting the public key of encryption ,encryption Then return, Encrypt the master private key for KGC; Step SE5: After the client decrypts and verifies, it calculates the share of the merged encrypted private key. ,save ,destroy and The encrypted private key scalar Excluding combination points and binding parameters The factor is distinct from the private key scalar in the signature portion of claim 14. .
16. A collaborative decryption method for an SM9 collaborative signature key generated according to claim 15, characterized in that, A collaborative decryption method with blinding, using the client share of the encrypted private key generated by the method of claim 15. and the share of encrypted private key servers Introducing a random blinding factor Protect client share The method includes: Step U1: Client enters ciphertext ,verify ,generate , The range of values is Each decryption is generated independently, and the blinded request is calculated. ,Will Send to the collaboration server, the client does not send. and ; Step U2: Collaboration Server Verification and Validity, calculate the first auxiliary value Second auxiliary value ,return ; Step U3: Client-side deblinding , In the group exponent domain Blinding factor Precise cancellation, ; KDF key derivation: ; Decrypting the plaintext: ; Verify integrity: Calculate And check with If they agree, then reject; Output plaintext .
17. The method for resisting SM9 collaborative decryption with escrow as described in claim 16, characterized in that, When collaboration mode is not enabled , The client calculates directly. No blinding or server interaction is required.
18. A collaborative signature method for generating an anti-escrow SM9 collaborative signature key according to claim 13, characterized in that, Use client temporary secret value and the private key share for signing with the collaboration server Partitioning by random number multiplication The two parties complete the signing step by step; the method includes: Step T1: Enter the message to be signed The client generates random numbers. , The range of values is Calculate the random commitment value ,send Give it to the collaboration server; Step T2: The collaborative server generates random numbers. , The range of values is Calculate joint random values Calculate the signature hash ,like Then regenerate Otherwise, calculate the first signature component. Second signature component ,return ; Step T3: The client calculates the final signature value. ,like Then return to step T1; otherwise, output... , equivalent to .
19. The collaborative signature method for an anti-escrow SM9 collaborative signature key according to claim 18, characterized in that, When collaboration mode is not enabled , The client generates complete random numbers on its own. Independent calculation .
20. The collaborative signature method for an anti-escrow SM9 collaborative signature key according to claim 18 or 19, characterized in that, When verifying a signature, the verifier obtains the corrected signature public key. : examine and for Effective points; calculate ; Calculate the signature hash ; examine .
21. A method for encapsulating and decapsulating a collaborative key for an anti-escrow SM9 collaborative signature key generated according to claim 13, characterized in that, The steps include the following: Step K1, the client inputs the encapsulated ciphertext. ,verify Generate random blinding factor , computation blinding request ,send ; Step K2: The collaborative server calculates the first auxiliary value. Second auxiliary value ,return ; Step K3, Client-side deblinding Derived symmetric key .
22. A collaborative key exchange method for an anti-escrow SM9 collaborative signature key generated according to claim 13, characterized in that, The collaborative key exchange method, in one-sided collaborative mode, includes the following steps: Phase 1: A Calculation Send to B, B calculates. Send to A, B does not enable collaborative direct computation and derived ; Phase Two: Independent Calculation by A Collaborative computing ; Step X1: Client A generates a random blinding factor. , The range of values is , computation blinding request ,send Give A to the collaborative server; Step X2, Server A calculates the first auxiliary value. Second auxiliary value ,return ; Step X3, Client A deblinding ,calculate Derived shared key ; Key negotiation is complete.
23. The collaborative key exchange method for anti-escrow SM9 collaborative signature keys according to claim 22, characterized in that, The two-sided collaborative mode includes the following steps: Both A and B enable collaboration. On side A, collaborative calculations are performed according to steps X1 to X3. Symmetrical collaborative computation on side B ; B client generation ,calculate ,send Give the task to server B, and server B will perform the calculation. Then return, and client B removes the blinding process. .
24. The collaborative key exchange method for anti-escrow SM9 collaborative signature keys according to claim 22 or 23, characterized in that, It also includes a third round of key verification: A is computed independently. B is calculated independently. Each has its own derivatives ; When collaboration mode is not enabled .
25. An SM9 signature key resistant to key escrow and its collaborative signature key system, characterized in that: The first layer is a key escrow-resistant system: the user introduces an autonomous secret to make the complete private key contain a KGC-agnostic factor, eliminating key escrow; encryption, key encapsulation, and key exchange use a modified encryption public key instead of the standard SM9 identity implicit derived public key; The second layer is a collaborative cryptographic method: the private key is split into a product of two shares, one for the client and one for the collaborative server, using a multiplicative structure, and the complete private key never appears in any single entity; the collaborative signature is synthesized by splitting random numbers into standard signatures; collaborative decryption, key encapsulation and decapsulation, and key exchange adopt a unified blinding / deblinding collaborative framework to achieve information-theoretic security and privacy protection; key exchange supports one-sided and two-sided collaboration without increasing the number of interaction rounds between the communicating parties.
Citation Information
Patent Citations
Signing and decrypting method and system applied to cloud computing and based on SM2 algorithm
CN104243456A