Quantum-resistant electronic signature generation method and apparatus, and quantum-resistant electronic signature verification method and apparatus

By using specific matrix operations and quadratic multivariate polynomial construction in the imbalanced oil and vinegar algorithm, an electronic signature that resists quantum computer attacks is generated, which solves the problem of weak attack resistance in the existing technology and achieves higher security and efficiency.

WO2025107786A1PCT designated stage expired Publication Date: 2025-05-30BEIJING YANQI LAKE INSITITUE OF MATHEMATICAL SCI & APPL

Patent Information

Application Number
PCT/CN2024/114815
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-11-22
Filing Date
2024-08-27
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

The existing multivariable public key cryptographic signature algorithm has the problem of weak resistance to quantum computer attacks.

Method used

The public and private keys are generated based on the target imbalance algorithm, and the center map is represented by the first matrix, the second matrix and the third matrix. The center matrix is ​​determined by summing the product results with the third matrix, and then the signature and verification signature are generated.

Benefits of technology

Improved security against quantum computer attacks, using specially constructed quadratic multivariate polynomials by increasing the rank sum of the center map, reducing signature difficulty and improving attack resistance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024114815_30052025_PF_FP_ABST
    Figure CN2024114815_30052025_PF_FP_ABST
Patent Text Reader

Abstract

The present disclosure relates to a quantum-resistant electronic signature generation method and apparatus, and a quantum-resistant electronic signature verification method and apparatus. The generation method comprises: generating a public key and a private key on the basis of a target unbalanced oil and vinegar algorithm, wherein center mapping of the target unbalanced oil and vinegar algorithm comprises a first matrix, a second matrix and a third matrix, elements in the first matrix and in the second matrix are linear polynomials related to n variables, and elements in the third matrix are quadratic oil and vinegar polynomials related to n variables; the n variables are oil variables and vinegar variables in the target unbalanced oil and vinegar algorithm, and n is a positive integer; acquiring a target message; using the private key to sign the target message so as to generate a target signature; and sending the target message, the target signature and the public key to the second terminal so as to verify the target signature. According to the present disclosure, the first matrix, the second matrix and the third matrix are used for modifying the center mapping, so that the signature difficulty is reduced, and the operation speed is improved while the attack resistance is improved.
Need to check novelty before this filing date? Find Prior Art

Description

A quantum-resistant electronic signature generation method, verification method, and device

[0001] This application claims priority to the Chinese patent application filed with the China Patent Office on November 22, 2023, with application number 202311568899.2 and invention name “A quantum-resistant electronic signature generation method, verification method and device”, the entire contents of which are incorporated by reference into this application. Technical Field

[0002] The present disclosure relates to the field of computer technology, and in particular to a quantum-resistant electronic signature generation method, verification method, and device. Background Art

[0003] A quantum computer is a physical device that follows the laws of quantum mechanics to perform high-speed mathematical and logical operations, store, and process quantum information. Many commonly used cryptographic algorithms, such as the asymmetric RSA (Ron Rivest, Adi Shamir, Leonard Adleman) and elliptic curve cryptography (ECC), are vulnerable to attacks by quantum computers. Research on quantum-resistant cryptography is becoming increasingly important.

[0004] In electronic signatures, multivariate public key cryptography (MPKC) signature algorithms started relatively early in post-quantum cryptography, and corresponding research has been carried out extensively. The main improvements are concentrated on the construction and selection of central mappings. However, existing multivariate public key cryptography signature algorithms still have the problem of weak anti-attack capabilities.

[0005] Summary of the Invention

[0006] In view of this, the present disclosure proposes a quantum-resistant electronic signature generation method, an electronic signature verification method, an electronic signature generation device, an electronic signature verification device, an electronic device, and a computer-readable storage medium.

[0007] According to one aspect of the present disclosure, a method for generating a quantum-resistant electronic signature is provided, which is applied to a first terminal. The method includes:

[0008] Generate a public key and a private key based on a target unbalanced oil and vinegar algorithm; wherein the central mapping of the target unbalanced oil and vinegar algorithm includes a first matrix, a second matrix, and a third matrix, wherein the elements in the first matrix and the second matrix are linear polynomials with respect to n variables, and the elements in the third matrix are quadratic oil and vinegar polynomials with respect to the n variables; the n variables are the oil variable and the vinegar variable in the target unbalanced oil and vinegar algorithm, and n is a positive integer;

[0009] Get target message;

[0010] Signing the target message using the private key to generate a target signature;

[0011] The target message, the target signature, and the public key are sent to a second terminal, so that the second terminal verifies the target signature using the target message and the public key.

[0012] In one possible implementation, the generating of a private key based on a target imbalanced oil-vinegar algorithm includes:

[0013] Randomly generate m first linear polynomials about the n variables, and construct an m*m order circulant matrix as the first matrix according to the first linear polynomials, where m is a positive integer;

[0014] Randomly generate m*s second linear polynomials about the n variables, and construct an m*s order matrix as the second matrix according to the second linear polynomials, where s is a positive integer;

[0015] Randomly generate m*s target quadratic polynomials about the n variables, and construct an m*s order matrix as the third matrix based on the target quadratic polynomials;

[0016] Randomly generate a first reversible matrix of order t*t and a second reversible matrix of order n*n, where t=m*s, and use the first matrix, the second matrix, the third matrix, the first reversible matrix, and the second reversible matrix as the private key.

[0017] In one possible implementation, generating a public key based on a target imbalanced oil-vinegar algorithm includes:

[0018] constructing a center map according to the first matrix, the second matrix, and the third matrix;

[0019] A composite mapping of the first reversible matrix, the central mapping, and the second reversible matrix is ​​used as the public key.

[0020] In a possible implementation, constructing a center mapping according to the first matrix, the second matrix, and the third matrix includes:

[0021] multiplying the first matrix by the second matrix to obtain a product result;

[0022] A sum operation is performed on the product result and the third matrix to obtain the center mapping.

[0023] In a possible implementation, signing the target message using the private key to generate a target signature includes:

[0024] Processing the target message to generate a corresponding hash value;

[0025] Establishing an m*s order target message matrix according to a mapping result of the first reversible matrix to the hash value;

[0026] Randomly generating a value for the vinegar variable;

[0027] Randomly generate a value for each element in the first matrix;

[0028] Establishing a system of linear equations according to the values ​​of each element in the first matrix, the second matrix, the third matrix and the target message matrix;

[0029] Substituting the value of the vinegar variable into the linear equation system and solving it to obtain the value of the oil variable;

[0030] The target signature is generated according to the value of the oil variable, the value of the vinegar variable, and the second reversible matrix.

[0031] According to another aspect of the present disclosure, a quantum-resistant electronic signature verification method is provided, which is applied to a second terminal, and the method further includes:

[0032] Receive a target message, a target signature, and a public key; wherein the public key is generated based on a target unbalanced oil-vinegar algorithm, and the central mapping of the target unbalanced oil-vinegar algorithm includes a first matrix, a second matrix, and a third matrix, wherein the elements in the first matrix and the second matrix are linear polynomials with respect to n variables, and the elements in the third matrix are quadratic oil-vinegar polynomials with respect to the n variables; the n variables are the oil variable and the vinegar variable in the target unbalanced oil-vinegar algorithm, and n is a positive integer;

[0033] Performing a calculation using the public key and the target message to obtain a calculation result;

[0034] The operation result is compared with the target signature. If the operation result is the same as the target signature, the verification result is verification passed; otherwise, the verification result is verification failed.

[0035] In a possible implementation, the center mapping is determined by performing a sum operation on a product of the first matrix and the second matrix and the third matrix.

[0036] According to another aspect of the present disclosure, a quantum-resistant electronic signature generation device is provided, which is applied to a first terminal. The device includes: a public-private key pair module, which is used to generate a public key and a private key based on a target unbalanced oil-vinegar algorithm; wherein the central mapping of the target unbalanced oil-vinegar algorithm includes a first matrix, a second matrix, and a third matrix, wherein the elements in the first matrix and the second matrix are linear polynomials with respect to n variables, and the elements in the third matrix are quadratic oil-vinegar polynomials with respect to the n variables; the n variables are the oil variable and the vinegar variable in the target unbalanced oil-vinegar algorithm, and n is a positive integer; an acquisition module, which is used to acquire a target message; a signature module, which is used to sign the target message using the private key to generate a target signature; and a sending module, which is used to send the target message, the target signature, and the public key to a second terminal, so that the second terminal verifies the target signature using the target message and the public key.

[0037] In one possible implementation, the public-private key pair module is further used to: randomly generate m first linear polynomials about the n variables, and construct an m*m order circulant matrix as the first matrix based on the first linear polynomials, where m is a positive integer; randomly generate m*s second linear polynomials about the n variables, and construct an m*s order matrix as the second matrix based on the second linear polynomials, where s is a positive integer; randomly generate m*s target quadratic polynomials about the n variables, and construct an m*s order matrix as the third matrix based on the target quadratic polynomials; randomly generate a first reversible matrix of order t*t and a second reversible matrix of order n*n, where t=m*s, and use the first matrix, the second matrix, the third matrix, the first reversible matrix, and the second reversible matrix as the private key.

[0038] In a possible implementation, the public-private key pair module is further used to: construct a central mapping based on the first matrix, the second matrix and the third matrix; and use a composite mapping of the first reversible matrix, the central mapping and the second reversible matrix as the public key.

[0039] In a possible implementation, the public-private key pair module is further configured to: multiply the first matrix by the second matrix to obtain a product result; and perform a sum operation on the product result and the third matrix to obtain the central mapping.

[0040] In one possible implementation, the signature module is further used to: process the target message to generate a corresponding hash value; establish an m*s order target message matrix based on the mapping result of the first reversible matrix to the hash value; randomly generate the value of the vinegar variable; randomly generate the value of each element in the first matrix; establish a linear equation system based on the value of each element in the first matrix, the second matrix, the third matrix and the target message matrix; substitute the value of the vinegar variable into the linear equation system for solution to obtain the value of the oil variable; and generate the target signature based on the value of the oil variable, the value of the vinegar variable and the second reversible matrix.

[0041] According to another aspect of the present disclosure, a quantum-resistant electronic signature verification device is provided, which is applied to a second terminal, and the device includes: a receiving module, configured to receive a target message, a target signature, and a public key; wherein the public key is generated based on a target unbalanced oil-vinegar algorithm, and the central mapping of the target unbalanced oil-vinegar algorithm includes a first matrix, a second matrix, and a third matrix, wherein the elements in the first matrix and the second matrix are linear polynomials with respect to n variables, and the elements in the third matrix are quadratic oil-vinegar polynomials with respect to the n variables; the n variables are the oil variable and the vinegar variable in the target unbalanced oil-vinegar algorithm, and n is a positive integer; an operation module, configured to perform an operation on the target message using the public key to obtain an operation result; and a comparison module, configured to compare the operation result with the target signature; if the operation result is the same as the target signature, the verification result is verification passed; otherwise, the verification result is verification failed.

[0042] In a possible implementation, the center mapping is determined by performing a sum operation on a product of the first matrix and the second matrix and the third matrix.

[0043] According to another aspect of the present disclosure, an electronic device is provided, comprising: a processor; and a memory for storing processor-executable instructions; wherein the processor is configured to implement the above-mentioned quantum-resistant electronic signature generation method or quantum-resistant electronic signature verification method when executing the instructions stored in the memory.

[0044] According to another aspect of the present disclosure, a computer-readable storage medium is provided, on which computer program instructions are stored, wherein when the computer program instructions are executed by a processor, the above-mentioned quantum-resistant electronic signature generation method or quantum-resistant electronic signature verification method is implemented.

[0045] According to another aspect of the present disclosure, a computer program product is provided, including a computer-readable code, or a non-volatile computer-readable storage medium carrying the computer-readable code. When the computer-readable code runs in a processor of an electronic device, the processor in the electronic device executes the above-mentioned quantum-resistant electronic signature generation method or quantum-resistant electronic signature verification method.

[0046] Through various aspects of the disclosed embodiments, by modifying the construction method of the central mapping, based on a relatively mature and highly resistant unbalanced oil and vinegar algorithm, the central mapping is represented by a first matrix, a second matrix, and a third matrix. For example, the central matrix can be determined by summing the product of the first matrix and the second matrix with the third matrix. This allows solving the central mapping to generate a signature in two steps: solving a linear equation, converting the quadratic equation into a linear equation, reducing the difficulty of signing, and the rank of the central mapping is higher, further improving the anti-attack capability. At the same time, the third matrix prevents the final public key from being easily decomposed into the form of a matrix product, and each element of the third matrix adopts a specially constructed quadratic oil and vinegar multivariate polynomial form, which can convert the quadratic polynomial equation into a linear equation by randomly guessing some variables. Ultimately, the first terminal only needs to solve the linear equation system, and the second terminal only needs to calculate the value of the quadratic multivariate equation system. However, the attacker needs to solve the difficult mathematical problem of the multivariable quadratic equation system. This improves the operating efficiency when inverting, maintains the high anti-attack capability, and achieves a faster computing speed.

[0047] Further features and aspects of the present disclosure will become apparent from the following detailed description of exemplary embodiments with reference to the attached drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0048] The accompanying drawings, which are incorporated in and constitute a part of the specification, illustrate exemplary embodiments, features, and aspects of the disclosure and, together with the description, serve to explain the principles of the disclosure.

[0049] FIG1 shows a schematic structural diagram of an electronic signature system according to an embodiment of the present disclosure.

[0050] FIG2 shows a flow chart of a method for generating an electronic signature according to an embodiment of the present disclosure.

[0051] FIG3 shows a flow chart of a method for generating a public key and a private key according to an embodiment of the present disclosure.

[0052] FIG4 shows a flow chart of a method for generating a target signature according to an embodiment of the present disclosure.

[0053] FIG5 shows a flow chart of a quantum-resistant electronic signature verification method according to an embodiment of the present disclosure.

[0054] FIG6 shows a structural diagram of a quantum-resistant electronic signature generation device according to an embodiment of the present disclosure.

[0055] FIG7 shows a structural diagram of a quantum-resistant electronic signature verification device according to an embodiment of the present disclosure.

[0056] FIG8 shows a schematic structural diagram of an electronic device according to an embodiment of the present disclosure. DETAILED DESCRIPTION

[0057] Various exemplary embodiments, features, and aspects of the present disclosure will be described in detail below with reference to the accompanying drawings. The same reference numerals in the accompanying drawings represent elements with the same or similar functions. Although various aspects of the embodiments are shown in the accompanying drawings, the drawings are not necessarily drawn to scale unless otherwise indicated.

[0058] The word “exemplary” is used exclusively herein to mean “serving as an example, example, or illustration.” Any embodiment described herein as “exemplary” is not necessarily to be construed as preferred or advantageous over other embodiments.

[0059] In addition, numerous specific details are provided in the following detailed description to better illustrate the present disclosure. Those skilled in the art will appreciate that the present disclosure can be practiced without certain specific details. In some instances, methods, means, components, and circuits well known to those skilled in the art are not described in detail in order to highlight the main points of the present disclosure.

[0060] Various exemplary embodiments, features, and aspects of the present disclosure will be described in detail below with reference to the accompanying drawings. The same reference numerals in the accompanying drawings represent elements with the same or similar functions. Although various aspects of the embodiments are shown in the accompanying drawings, the drawings are not necessarily drawn to scale unless otherwise indicated.

[0061] References to "one embodiment" or "some embodiments" in this specification mean that a particular feature, structure, or characteristic described in conjunction with that embodiment is included in one or more embodiments of the present disclosure. Thus, phrases such as "exemplary," "in one embodiment," "in some other embodiments," and "in other embodiments" appearing in various places in this specification do not necessarily refer to the same embodiment, but rather mean "one or more but not all embodiments," unless otherwise specifically emphasized. The terms "including," "comprising," "having," and variations thereof mean "including but not limited to," unless otherwise specifically emphasized.

[0062] In the present disclosure, "at least one" means one or more, and "more than one" means two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can mean: including the existence of A alone, the existence of A and B at the same time, and the existence of B alone, where A and B can be singular or plural. The character " / " generally indicates that the previous and next associated objects are in an "or" relationship. "At least one of the following items" or similar expressions refers to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b, or c can mean: a, b, c, ab, ac, bc, or abc, where a, b, c can be single or multiple.

[0063] In addition, numerous specific details are provided in the following detailed description to better illustrate the present disclosure. Those skilled in the art will appreciate that the present disclosure can be practiced without certain specific details. In some instances, methods, means, components, and circuits well known to those skilled in the art are not described in detail in order to highlight the main points of the present disclosure.

[0064] To facilitate understanding, the following first provides an exemplary description of the application scenarios of the quantum-resistant electronic signature generation and verification scheme in the embodiments of the present disclosure.

[0065] Figure 1 shows a schematic diagram of the structure of an electronic signature system according to an embodiment of the present disclosure. As shown in Figure 1, the electronic signature system may include: a first terminal 10 and a second terminal 20. The first terminal 10 may also be referred to as a terminal for generating electronic signatures. The first terminal 10 uses a signature algorithm to generate its own public key pair, namely a public key and a private key. The private key is a key known only to the first terminal 10 and is used to sign messages to be sent. The public key is a key used to verify electronic signatures. The public key can be shared publicly, and the first terminal 10 can send its public key to other terminals (including the second terminal 20). The first terminal 10 uses its own private key to process a message, generate an electronic signature, and then sends the electronic signature and the message to the second terminal 20. The second terminal 20 may also be referred to as a terminal for verifying electronic signatures. After receiving the electronic signature and message sent by the first terminal 10, the second terminal 20 uses the received public key of the first terminal 10 to process the electronic signature and the received message, verifying the validity of the electronic signature, thereby proving that the received electronic signature and message were sent by the first terminal 10.

[0066] Exemplarily, the electronic signature system may further include a secure third-party organization 30, such as a Certificate Authority (CA), which authenticates the legitimacy of the public key. For example, the CA may generate a certificate for the public key of the first terminal 10 to bind the first terminal 10 to its own public key. The first terminal 10 may send the authenticated public key to other terminals (including the second terminal 20). Upon receiving the message and electronic signature, the second terminal 20 processes the electronic signature and the received message using the authenticated public key to verify the validity of the electronic signature.

[0067] Exemplarily, a message can be any type of data, such as an email, an installation package, an image, a document, etc., without limitation. Exemplarily, the first terminal 10 and the second terminal 20 can be electronic devices or components with data processing capabilities, such as personal computers, smartphones, wearable devices, servers, and processors. As an example, the first terminal 10 is user A's computer, and the second terminal 20 is user B's computer. In a scenario where user A sends an email to user B, the email is the message; user A's computer generates a public-private key pair using a signature algorithm and shares the authenticated public key with user B. User A's computer processes the email using the private key, generates an electronic signature, and then sends the email and electronic signature together to user B's computer. After receiving the email and electronic signature, user B's computer processes the electronic signature and email using user A's public key to verify the validity of the electronic signature. As another example, the first terminal 10 is the service provider's server, and the second terminal 20 is the computer of user C. In a scenario where user C needs to download a software installation package, the software installation package is a message; user C can download the service provider's software installation package online, and the server can generate a public-private key pair through a signature algorithm, and share the authenticated public key with user C. The server uses the private key to process the software installation package and generate an electronic signature, and then sends the software installation package and the electronic signature to user C's computer. After receiving the software installation package and the electronic signature, user C's computer uses the service provider's public key to process the electronic signature and the software installation package to verify the validity of the electronic signature.

[0068] Among them, the above-mentioned signature algorithm can be a multivariate public key cryptographic signature algorithm, which is a quantum-resistant public key cryptographic signature method. The private key is composed of a multivariate quadratic polynomial group that is easy to calculate the inverse and two reversible linear transformations that conceal its structure. The result of the composite mapping of the multivariate quadratic polynomial group and the two reversible linear transformations is used as the public key. The security of multivariate public-key cryptographic signature algorithms is based on the difficulty of solving non-deterministic polynomials (NP) in the multivariate quadratic polynomial (MQ) problem. To improve security against quantum computers, signature algorithms such as Hidden Field Equations, Unbalanced Vinegar, and Rainbow have emerged. Improvements to these signature algorithms focus on the construction and selection of central mappings. However, the Hidden Field Equations (HFE) signature algorithm has been found to be recoverable under a MinRank attack. The Tame Transformation Method (TTM) signature algorithm has also been found to be crackable when the rank of the quadratic matrix of the central mapping is low. Therefore, the anti-attack capability of multivariate public-key cryptographic signature algorithms still needs to be improved.

[0069] To address the above technical issues, the present disclosure proposes a multivariate, quantum-resistant electronic signature generation and verification method (described below), which can be used for electronic signatures requiring high security against quantum computers. Research on MinRank attacks has shown that low-rank matrices are insecure under these attacks, so when selecting a secure central mapping, its rank should be as high as possible. In the embodiment of the present disclosure, by modifying the construction method of the central mapping, a first matrix, a second matrix, and a third matrix are used to represent the central mapping on the basis of a relatively mature and highly resistant unbalanced oil and vinegar algorithm. For example, the central matrix can be determined by summing the product of the first matrix and the second matrix with the third matrix, so that solving the central mapping can be divided into two steps to solve the linear equation, converting the quadratic equation into a linear equation, reducing the difficulty of signing, and the rank of the central mapping is higher, further improving the anti-attack ability. At the same time, the third matrix makes it difficult to decompose the final public key into the form of a matrix product, and each element of the third matrix adopts a specially constructed quadratic multivariable oil and vinegar polynomial form, which can convert the quadratic polynomial equation into a linear equation by randomly guessing some variables. Ultimately, the first terminal only needs to solve the linear equation system, and the second terminal only needs to calculate the value of the quadratic multivariable equation system. However, the attacker needs to solve the difficult mathematical problem of the multivariable quadratic equation system, which improves the operating efficiency when inverting, maintains the high anti-attack ability, and achieves a faster computing speed.

[0070] It should be noted that the above-mentioned application scenarios described in the embodiments of the present disclosure are intended to more clearly illustrate the technical solutions of the embodiments of the present disclosure, and do not constitute a limitation on the technical solutions provided by the embodiments of the present disclosure. Ordinary technicians in this field can know that the technical solutions provided by the embodiments of the present disclosure are also applicable to similar technical problems when other similar or new scenarios emerge.

[0071] The following describes in detail the quantum-resistant electronic signature generation method provided by the embodiments of the present disclosure.

[0072] FIG2 shows a flow chart of a method for generating an electronic signature according to an embodiment of the present disclosure. The method can be applied to a first terminal, for example, the first terminal 10 in the electronic signature system of FIG1 . As shown in FIG2 , the method may include:

[0073] Step 201: Generate a public key and a private key based on a target unbalanced oil and vinegar algorithm.

[0074] Among them, the central mapping of the target unbalanced oil and vinegar algorithm includes a first matrix, a second matrix and a third matrix, the elements in the first matrix and the second matrix are linear polynomials about n variables, and the elements in the third matrix are quadratic oil and vinegar polynomials about the n variables.

[0075] The n variables are the oil variable and the vinegar variable in the target unbalanced oil and vinegar algorithm, and n is a positive integer; the specific value of n can be set according to needs and is not limited to this.

[0076] The target unbalanced oil and vinegar algorithm is an improved algorithm based on the existing unbalanced oil and vinegar signature algorithm. For example, the central mapping can include a first matrix, a second matrix and a third matrix; after constructing the central mapping, the public key and the private key can be obtained.

[0077] Exemplarily, the center mapping may be determined by performing a sum operation on a product of the first matrix and the second matrix and the third matrix.

[0078] Step 202: Get the target message.

[0079] The target message is the message to be signed.

[0080] Exemplarily, the first terminal obtains the target message in response to the user's operation on the input interface of the first terminal. For example, in response to the user's operation of writing an email through a computer interface, the computer can obtain the email.

[0081] Step 203: Use the private key to sign the target message to generate a target signature.

[0082] Step 204: Send the target message, the target signature, and the public key to the second terminal, so that the second terminal verifies the target signature using the target message and the public key.

[0083] Exemplarily, after generating the above-mentioned public key, the first terminal can first send the public key to the authentication center. After the authentication center authenticates the legitimacy of the public key, it sends the authenticated public key to the second terminal, and the second terminal saves the public key of the first terminal locally; then, after generating the above-mentioned target signature, the first terminal can send the target message and the target signature to the second terminal. After receiving the target message and target signature, the second terminal can use the locally stored public key of the first terminal to process the target signature and target message to verify the validity of the target signature.

[0084] In this way, through the above steps 201-204, the first terminal has signed the target message, and the second terminal can then verify the signature, ensuring the security of the target message. For example, in a scenario where a user needs to download a software installation package from a server, since the software installation package may be tampered with by other people, or other people may impersonate the service provider, the server can generate a public key and a private key using a target unbalanced oil and vinegar algorithm and share the authenticated public key with the user. The server then uses the private key to process the software installation package and generate an electronic signature, which indicates that the software installation package originates from the service provider. The service provider then sends the software installation package and the electronic signature to the user through the server, so that after the user receives the software installation package and the electronic signature, they can verify that the electronic signature is the service provider's signature using the service provider's public key.

[0085] In the disclosed embodiment, by modifying the construction method of the central mapping, a first matrix, a second matrix, and a third matrix are used to represent the central mapping on the basis of a relatively mature and highly resistant unbalanced oil and vinegar algorithm. For example, the central matrix can be determined by summing the product of the first matrix and the second matrix with the third matrix. This allows the central mapping to generate a signature in two steps: solving a linear equation, converting the quadratic equation into a linear equation, reducing the difficulty of signing, and the rank of the central mapping is higher, further improving the anti-attack ability. At the same time, the third matrix prevents the final public key from being easily decomposed into the form of a matrix product, and each element of the third matrix adopts a specially constructed quadratic multivariate polynomial form, which can convert the quadratic polynomial equation into a linear equation by randomly guessing some variables. Ultimately, the first terminal only needs to solve the linear equation system, and the second terminal only needs to calculate the value of the quadratic multivariate equation system. However, the attacker needs to solve the difficult mathematical problem of the multivariable quadratic equation system. This improves the operating efficiency when inverting, maintains the high anti-attack ability, and achieves a faster computing speed.

[0086] The specific process of generating the public key and the private key based on the target unbalanced oil and vinegar algorithm in step 201 is described below.

[0087] FIG3 shows a flow chart of a method for generating a public key and a private key according to an embodiment of the present disclosure. As shown in FIG3 , the method may include the following steps:

[0088] Step 301: randomly generate m first linear polynomials about the n variables, and construct an m*m order circulant matrix as the first matrix based on the first linear polynomials;

[0089] Wherein, m is a positive integer. The specific value of m can be set according to needs and is not limited to this.

[0090] For example, when generating the first matrix, only the first row needs to be generated, and the generation of other rows only requires a right shift transformation. In this way, by generating m first linear polynomials about the n variables, an m*m order circulant matrix can be constructed.

[0091] For example, in the polynomial ring Randomly generate m first linear polynomials, and the variables in each first linear polynomial are x1, x2, ..., x n , represents a finite field of order q.

[0092] For example, the first matrix can be expressed by the following formula (1):

[0093] Among them, A is an m*m order circulant matrix, that is, the first matrix, the elements in the A matrix (a1, a2…a m ) are all polynomial rings Linear polynomial on .

[0094] Step 302: randomly generate m*s second linear polynomials about the n variables, and construct an m*s order matrix as the second matrix based on the second linear polynomials;

[0095] Wherein, s is a positive integer. The specific value of s can be set according to needs and is not limited to this.

[0096] For example, in the polynomial ring Randomly generate m*s (i.e., ms) second linear polynomials, and the variables in each second linear polynomial are x1, x2, ..., x n , represents a finite field of order q.

[0097] For example, the second matrix can be expressed by the following formula (2):

[0098] Among them, B is an m*s order random matrix, that is, the second matrix, and the elements in the B matrix (b1, b2…b ms ) are all polynomial rings Linear polynomial on .

[0099] Step 303: randomly generate m*s target quadratic polynomials about the n variables, and construct an m*s order matrix as the third matrix based on the target quadratic polynomials.

[0100] For example, in the polynomial ring Randomly generate m*s quadratic polynomials, and the variables in each quadratic polynomial are x1, x2,…, x n , represents a finite field of order q.

[0101] For example, the third matrix can be expressed by the following formula (3):

[0102] Among them, C is a random matrix of order m*s, that is, the third matrix, and the elements in the C matrix (c1, c2…c ms ) is a polynomial ring Quadratic multivariate polynomials on oil and vinegar.

[0103] The quadratic oil and vinegar multivariate polynomial is defined as follows:

[0104] The following formula (4) expresses that in the polynomial ring The previous special quadratic multivariate polynomial f:

[0105] Among them, x1,…,x n represents the n variables in the quadratic oil and vinegar multivariate polynomial f; n is the number of variables in the unbalanced oil and vinegar algorithm, o represents the number of oil variables in n variables; a ij Represents the polynomial x i x j The coefficient of b i Represents the monomial x i The coefficient of , c is a constant term. Among them, each variable and coefficient is in the finite field Inside.

[0106] Step 304: Randomly generate a first reversible matrix of order t*t and a second reversible matrix of order n*n, where t=m*s, and use the first matrix, the second matrix, the third matrix, the first reversible matrix, and the second reversible matrix as the private key.

[0107] For example, in a finite field A t*t order reversible matrix and an n*n order reversible matrix are randomly generated. The reversible matrix can be expressed by the following formula (5):

[0108] Wherein, T is the first reversible matrix, S is the second reversible matrix; represents a finite field of order q; n represents the number of variables in the target imbalanced oil and vinegar algorithm, Representing a finite field The t*t order matrix inside, Representing a finite field The n*n matrix inside.

[0109] In this way, through the above steps 301-304, a private key is generated. Further, the following steps 305 and 306 can be executed to generate a public key.

[0110] Step 305: Construct a center map according to the first matrix, the second matrix, and the third matrix.

[0111] In one possible implementation, constructing a central mapping based on the first matrix, the second matrix, and the third matrix includes: multiplying the first matrix by the second matrix to obtain a product result; and summing the product result with the third matrix to obtain the central mapping.

[0112] For example, the center map F can be expressed by the following formula (6):

[0113] Among them, A is the first matrix, B is the second matrix, and C is the third matrix. Represents a composition of mappings.

[0114] Step 306: Use the composite mapping of the first reversible matrix, the central mapping, and the second reversible matrix as the public key.

[0115] The first reversible matrix is ​​the first reversible matrix in the above step 304, for example, it can be the reversible matrix T represented by formula (5); the second reversible matrix is ​​the second reversible matrix in the above step 304, for example, it can be the reversible matrix S represented by formula (5).

[0116] In existing multivariate public-key cryptographic signature algorithms, to make equations easy to solve for terminals possessing the private key, while difficult for terminals possessing only the public key, a corresponding multivariate quadratic polynomial is constructed as the central mapping F. The public key is simply obtained by matrix multiplication of the central mapping F with a reversible matrix. The reversible matrix masks the properties of the central mapping F, making it indistinguishable from solving a general multivariate quadratic equation. This reversible matrix constitutes part of the private key; the remainder of the private key depends on how the central mapping F is constructed.

[0117] For example, the public key P can be expressed by the following formula (7):

[0118] Where F represents the central mapping, T represents the first reversible matrix, and S represents the second reversible matrix. In this way, the public key P can be generated by formula (7), where the matrices A, B, C, T, and S are used as private keys.

[0119] The specific process of signing the target message using the private key to generate the target signature in the above step 203 is described below.

[0120] FIG4 shows a flow chart of a method for generating a target signature according to an embodiment of the present disclosure. As shown in FIG4 , the method may include the following steps:

[0121] Step 401: Process the target message and generate a corresponding hash value.

[0122] Exemplarily, the target message may be hashed by processing the target message through a preset hash function to generate a hash value of a fixed length.

[0123] For example, the hash value can be generated by the following formula (8):

[0124] Where H represents the hash function, doc represents the target message, and the generated hash value d is of length m*s. For example, it can be written as d=(d1, d2…, d m*s ).

[0125] Step 402: Establish an m*s order target message matrix according to the mapping result of the first reversible matrix to the hash value.

[0126] For example, the mapping result of the target message hash value can be generated by the following formula (9):

[0127] y=T -1 (d)…………………………………………..(9)

[0128] Where y=(y1,y2…,ym*s ), represents the mapping result, T is the first reversible matrix, d=(d1,d2…,d m*s ) represents the hash value of the target message.

[0129] Furthermore, the mapping result can be expressed in matrix form by the following formula (10):

[0130] Among them, Y is the target message matrix, and the elements in the Y matrix (y1, y2…y ms ) is the mapping value of the hash value of the target message matrix.

[0131] Step 403: Randomly generate the value of the vinegar variable.

[0132] For example, in a finite field Randomly generated v represents the number of vinegar variables; that is, in the finite field V random numbers are generated internally as the value of the vinegar variable, thereby fixing the value of the vinegar variable among the n variables in the target unbalanced oil-vinegar algorithm, and the value of the oil variable among the n variables remains to be determined.

[0133] Step 404: Randomly generate values ​​for each element in the first matrix.

[0134] For example, (u1,u2,…,u m ), and then generate the circulant matrix shown in the following formula (11):

[0135] Let the matrix A=U in the above formula (1), that is, the value of each element in the circulant matrix U is assigned to the first matrix A, thereby fixing the value of each element in the first matrix.

[0136] Step 405: Establish a system of linear equations according to the values ​​of each element in the first matrix, the second matrix, the third matrix and the target message matrix.

[0137] For example, since the first matrix, the second matrix, the third matrix and the center map have the relationship shown in the above formula (6), the equation group shown in the following formula (12) can be established:

[0138] U*B+C=Y................................(12)

[0139] Where U is the circulant matrix shown in equation (11), the values ​​of the elements in this matrix are the values ​​of the elements in the first matrix, B is the second matrix, C is the third matrix, and Y is the target message matrix shown in equation (10). Thus, the randomly generated U fixes the values ​​of the elements in the first matrix A, and U*B is converted into a linear transformation, making the system of equations shown in equation (12) a linear system of equations.

[0140] Step 406: Substitute the value of the vinegar variable into the linear equation system to solve it and obtain the value of the oil variable.

[0141] In this step, the value of the vinegar variable randomly generated in step 403 is substituted into each polynomial in the linear system of equations, such as into the m*s second linear polynomials with respect to n variables in the second matrix, and into the m*s target quadratic oil-vinegar polynomials with respect to n variables in the third matrix, so that the elements in the second matrix and the third matrix are all linear polynomials with respect to the oil variable. In this way, the values ​​of all vinegar variables in the linear system of equations are fixed. After the values ​​of the vinegar variables are fixed, the product terms of the oil variable and the vinegar variable in the linear system of equations are converted to linear terms, and the product terms of the vinegar variable and the vinegar variable are converted to constant terms, thereby converting the linear system of equations into a linear system of equations with respect to the oil variable. Among them, by substituting the value of the vinegar variable into the m*s second linear polynomials about n variables in the second matrix, and the m*s target quadratic oil-vinegar polynomials about n variables in the third matrix, combined with the values ​​of each element in the first matrix and the values ​​of the elements in the target message matrix, m*s linear equations about the oil variable can be obtained; by substituting the value of the vinegar variable into the first matrix, combined with the values ​​of each element in the first matrix, m linear equations about the oil variable can be obtained; thus, the linear equation group is a linear equation group including m*s+m linear equations about the oil variable.

[0142] For example, the randomly generated vinegar variable (x o+1 ,x o+2 ,…,x n ) is substituted into the equation group shown in the above equation (12), which contains m*s+m equations about the oil variables (x1, x2,…, x o ), so that the value of the oil variable can be solved. It can be understood that when the number of oil variables o≥m*s+m, the probability of finding a solution to the above linear equations is very high, thus achieving the solution of F(x1,x2,…,x n )=(y1,y2,…,y ms ); If the system of equations has no solution, then repeat the above step 404 to regenerate the values ​​of each element in the first matrix, and execute the following steps until the oil variables (x1, x2, ..., x o ) value.

[0143] Step 407: Generate the target signature according to the value of the oil variable, the value of the vinegar variable, and the second reversible matrix.

[0144] The process of generating a signature is actually the process of solving the original image of the composite mapping. For example, solving the mapping shown in the above formula (6) The process of the original image, in the above solution y = T -1 (d) and x = F -1 (y), and according to the values ​​of the variables (x1, x2, ..., x n ) and the reversible matrix S, and further solve to obtain the target signature Sign = S -1 (x).

[0145] In the disclosed embodiment, each element in the first and second matrices is a linear polynomial. This allows the quadratic equation formed by the product of the first and second matrices to be converted into a linear equation by first assuming the values ​​of the elements in the first matrix and then solving for the variables in the second matrix. Furthermore, since each element in the third matrix is ​​a quadratic oil-vinegar multivariate polynomial, the unique structure of the quadratic oil-vinegar multivariate polynomial allows the system of equations, once the value of the vinegar variable is guessed, to be converted from a quadratic system of equations involving the oil and vinegar variables into a linear system of equations involving the oil variable, making signature generation easier.

[0146] The following describes in detail the quantum-resistant electronic signature verification method provided by the embodiments of the present disclosure.

[0147] FIG5 shows a flowchart of a quantum-resistant electronic signature verification method according to an embodiment of the present disclosure. This method can be applied to a second terminal, for example, the second terminal 20 in the electronic signature system of FIG1 . As shown in FIG5 , the method may include the following steps:

[0148] Step 501: Receive a target message, a target signature, and a public key; wherein the public key is generated based on a target unbalanced oil-vinegar algorithm, and the central mapping of the target unbalanced oil-vinegar algorithm includes a first matrix, a second matrix, and a third matrix. The elements in the first matrix and the second matrix are linear polynomials with respect to n variables, and the elements in the third matrix are quadratic oil-vinegar polynomials with respect to the n variables; the n variables are the oil variable and the vinegar variable in the target unbalanced oil-vinegar algorithm, and n is a positive integer.

[0149] In a possible implementation, the center mapping is determined by performing a sum operation on a product of the first matrix and the second matrix and the third matrix.

[0150] Step 502: Perform an operation on the target message using the public key to obtain an operation result;

[0151] Exemplarily, the second terminal processes the target message using a hash function to obtain a hash value corresponding to the target message, and decrypts the hash value corresponding to the target message using the public key of the first terminal to obtain a calculation result. The hash function used to generate the hash value corresponding to the target message is the same as the hash function used to generate the hash value corresponding to the target signature.

[0152] Step 503: Compare the operation result with the target signature. If the operation result is the same as the target signature, the verification result is verification passed; otherwise, the verification result is verification failed.

[0153] Exemplarily, the operation result is compared with the target signature. If the operation result is the same as the target signature, the target signature is verified, indicating that the target signature and the message are sent by the terminal to which the public key belongs. If the operation result is different from the target signature, the target signature is not verified, indicating that the target signature or the message is not sent by the terminal to which the public key belongs. For example, in a scenario where a user needs to download a software installation package from a server, the user can store the public key of the authenticated service provider locally in advance. After the user receives the software installation package and the electronic signature, the user can perform an operation on the software installation package using the service provider's public key to obtain the operation result, and compare the operation result with the electronic signature. If the operation result is the same as the electronic signature, it indicates that the electronic signature is the signature of the service provider. If they are different, it indicates that the software installation package may have been tampered with by other persons, or that other persons may have impersonated the service provider. This verifies the integrity of the message and the identity of the message sender.

[0154] Based on the same inventive concept of the above method embodiment, the embodiment of the present disclosure also provides a quantum-resistant electronic signature generation device, which can be used to execute the technical solution described in the above quantum-resistant electronic signature generation method embodiment.

[0155] FIG6 shows a structural diagram of a quantum-resistant electronic signature generation device according to an embodiment of the present disclosure, which is applied to a first terminal. As shown in FIG6 , the device may include: a public-private key pair module 601, configured to generate a public key and a private key based on a target unbalanced oil-vinegar algorithm; wherein the central mapping of the target unbalanced oil-vinegar algorithm includes a first matrix, a second matrix, and a third matrix, wherein the elements in the first matrix and the second matrix are linear polynomials with respect to n variables, and the elements in the third matrix are quadratic oil-vinegar polynomials with respect to the n variables; the n variables are the oil variable and the vinegar variable in the target unbalanced oil-vinegar algorithm, and n is a positive integer; an acquisition module 602, configured to acquire a target message; a signature module 603, configured to sign the target message using the private key to generate a target signature; and a sending module 604, configured to send the target message, the target signature, and the public key to a second terminal, so that the second terminal verifies the target signature using the target message and the public key.

[0156] In the disclosed embodiment, the construction method of the central mapping is modified. On the basis of a relatively mature and highly resistant unbalanced oil and vinegar algorithm, the central mapping is represented by a first matrix, a second matrix, and a third matrix. For example, the central matrix can be determined by summing the product of the first matrix and the second matrix with the third matrix, so that solving the central mapping can be divided into two steps to solve the linear equation, and the quadratic equation is converted into a linear equation, which reduces the difficulty of signing. The rank of the central mapping is higher, further improving the anti-attack ability. At the same time, the third matrix makes it difficult for the final public key to be easily decomposed into the form of a matrix product, and each element of the third matrix adopts a specially constructed quadratic multivariate polynomial form, which can transform the quadratic polynomial equation into a linear equation by randomly guessing some variables. Ultimately, the first terminal only needs to solve the linear equation system, and the second terminal only needs to calculate the value of the quadratic multivariate equation system. However, the attacker needs to solve the difficult mathematical problem of the multivariable quadratic equation system, which improves the operating efficiency when inverting, continues the high anti-attack ability, and achieves a faster computing speed.

[0157] In one possible implementation, the public-private key pair module 601 is further configured to: randomly generate m first linear polynomials about the n variables, and construct an m*m order circulant matrix based on the first linear polynomials as the first matrix, where m is a positive integer; randomly generate m*s second linear polynomials about the n variables, and construct an m*s order matrix based on the second linear polynomials as the second matrix, where s is a positive integer; randomly generate m*s target quadratic polynomials about the n variables, and construct an m*s order matrix based on the target quadratic polynomials as the third matrix; randomly generate a first reversible matrix of order t*t and a second reversible matrix of order n*n, where t=m*s, and use the first matrix, the second matrix, the third matrix, the first reversible matrix, and the second reversible matrix as the private key.

[0158] In a possible implementation, the public-private key pair module 601 is further used to: construct a central mapping based on the first matrix, the second matrix and the third matrix; and use a composite mapping of the first reversible matrix, the central mapping and the second reversible matrix as the public key.

[0159] In a possible implementation, the public-private key pair module 601 is further configured to: multiply the first matrix by the second matrix to obtain a product result; and perform a sum operation on the product result and the third matrix to obtain the central mapping.

[0160] In one possible implementation, the signature module 603 is further used to: process the target message to generate a corresponding hash value; establish an m*s order target message matrix based on the mapping result of the first reversible matrix to the hash value; randomly generate the value of the vinegar variable; randomly generate the value of each element in the first matrix; establish a linear equation system based on the value of each element in the first matrix, the second matrix, the third matrix and the target message matrix; substitute the value of the vinegar variable into the linear equation system for solution to obtain the value of the oil variable; and generate the target signature based on the value of the oil variable, the value of the vinegar variable and the second reversible matrix.

[0161] The embodiments of the present disclosure further provide a quantum-resistant electronic signature verification device, which can be used to implement the technical solution described in the above-mentioned quantum-resistant electronic signature verification method embodiment.

[0162] FIG7 shows a structural diagram of a quantum-resistant electronic signature verification device according to an embodiment of the present disclosure, which is applied to a second terminal. As shown in FIG7 , the device may include: a receiving module 701, configured to receive a target message, a target signature, and a public key; wherein the public key is generated based on a target unbalanced oil-vinegar algorithm, and the central mapping of the target unbalanced oil-vinegar algorithm includes a first matrix, a second matrix, and a third matrix, wherein the elements in the first matrix and the second matrix are linear polynomials with respect to n variables, and the elements in the third matrix are quadratic oil-vinegar polynomials with respect to the n variables; the n variables are the oil variable and the vinegar variable in the target unbalanced oil-vinegar algorithm, and n is a positive integer; an operation module 702, configured to perform an operation on the target message using the public key to obtain an operation result; and a comparison module 703, configured to compare the operation result with the target signature. If the operation result is the same as the target signature, the verification result is verification passed; otherwise, the verification result is verification failed.

[0163] In the disclosed embodiment, a public key is used to perform an operation on a target message to obtain an operation result, and the operation result is compared with the target signature, thereby verifying the integrity of the message and the identity of the message sender.

[0164] In a possible implementation, the center mapping is determined by performing a sum operation on a product of the first matrix and the second matrix and the third matrix.

[0165] The technical effects and specific descriptions of the devices shown in Figures 6 and 7 and their various possible implementation methods can be found in the above method embodiments and will not be repeated here.

[0166] It should be understood that the division of the modules in the above device is only a division of logical functions. In actual implementation, they can be fully or partially integrated into a physical entity, or they can be physically separated. In addition, the modules in the device can be implemented in the form of a processor calling software; for example, the device includes a processor, the processor is connected to a memory, and the memory stores instructions. The processor calls the instructions stored in the memory to implement any of the above methods or realize the functions of the modules of the device, wherein the processor is, for example, a general-purpose processor, such as a central processing unit (CPU) or a microprocessor, and the memory is a memory within the device or a memory outside the device. Alternatively, the modules in the device can be implemented in the form of hardware circuits, and the functions of some or all modules can be realized by designing the hardware circuits. The hardware circuit can be understood as one or more processors. For example, in one implementation, the hardware circuit is an application-specific integrated circuit (ASIC), which realizes the functions of some or all of the above modules by designing the logical relationship of the components in the circuit. For another example, in another implementation, the hardware circuit can be implemented by a programmable logic device (PLD). Taking a field programmable gate array (FPGA) as an example, it can include a large number of logic gate circuits, and the connection relationship between the logic gate circuits is configured by configuring the configuration file, thereby realizing the functions of some or all of the above modules. All modules of the above devices can be implemented in the form of software called by the processor, or in the form of hardware circuits, or in part by the form of software called by the processor, and the rest by hardware circuits.

[0167] In the embodiments of the present disclosure, a processor is a circuit capable of processing signals. In one implementation, the processor may be a circuit capable of reading and executing instructions, such as a CPU, a microprocessor, a graphics processing unit (GPU), a digital signal processor (DSP), a neural-network processing unit (NPU), a tensor processing unit (TPU), etc. In another implementation, the processor may implement certain functions through the logical relationship of a hardware circuit, and the logical relationship of the hardware circuit may be fixed or reconfigurable, such as a hardware circuit implemented by an ASIC or PLD, such as an FPGA. In a reconfigurable hardware circuit, the process of the processor loading a configuration document to implement the hardware circuit configuration can be understood as the process of the processor loading instructions to implement the functions of some or all of the above modules.

[0168] It can be seen that each module in the above apparatus can be one or more processors (or processing circuits) configured to implement the above embodiment methods, such as: CPU, GPU, NPU, TPU, microprocessor, DSP, ASIC, FPGA, or a combination of at least two of these processor forms. In addition, each module in the above apparatus can be fully or partially integrated together, or can be implemented independently, without limitation.

[0169] The present disclosure also provides an electronic device comprising: a processor; and a memory for storing processor-executable instructions; wherein the processor is configured to implement the method of the above embodiment when executing the instructions. For example, the steps of the method shown in Figures 2, 3, 4, or 5 can be performed.

[0170] Figure 8 shows a schematic structural diagram of an electronic device according to an embodiment of the present disclosure. Exemplarily, the electronic device may be the first terminal 10 or the second terminal 20 in Figure 1 above; as shown in Figure 8, the electronic device may include: at least one processor 801, a communication line 802, a memory 803 and at least one communication interface 804.

[0171] The processor 801 can be a general-purpose central processing unit, a microprocessor, a specific application integrated circuit, or one or more integrated circuits for controlling the execution of the program of the disclosed solution; the processor 801 can also include a heterogeneous computing architecture of multiple general-purpose processors, for example, it can be a combination of at least two of a CPU, a GPU, a microprocessor, a DSP, an ASIC, and an FPGA; as an example, the processor 801 can be a CPU+GPU or a CPU+ASIC or a CPU+FPGA.

[0172] Communication link 802 may include a pathway for transmitting information between the aforementioned components.

[0173] The communication interface 804 uses any transceiver or other device for communicating with other devices or communication networks, such as Ethernet, RAN, wireless local area networks (WLAN), etc.

[0174] The memory 803 can be a read-only memory (ROM) or other types of static storage devices that can store static information and instructions, a random access memory (RAM) or other types of dynamic storage devices that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed optical disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program codes in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory can be independent and connected to the processor via a communication line 802. The memory can also be integrated with the processor. The memory provided in the embodiment of the present disclosure can generally be non-volatile. Among them, the memory 803 is used to store computer-executable instructions for executing the disclosed solution, and is controlled by the processor 801 for execution. The processor 801 is used to execute the computer-executable instructions stored in the memory 803, thereby implementing the method provided in the above embodiments of the present disclosure; illustratively, the steps of the method shown in Figures 2, 3, 4 or 5 above can be executed.

[0175] Optionally, the computer-executable instructions in the embodiments of the present disclosure may also be referred to as application code, which is not specifically limited in the embodiments of the present disclosure.

[0176] Exemplarily, the processor 801 may include one or more CPUs, for example, CPU0 in FIG8 ; the processor 801 may also include a CPU and any one of a GPU, an ASIC, and an FPGA, for example, CPU0+GPU0 or CPU 0+ASIC0 or CPU0+FPGA0 in FIG8 .

[0177] For example, an electronic device may include multiple processors, such as processor 801 and processor 807 in FIG8 . Each of these processors may be a single-core (single-CPU) processor, a multi-core (multi-CPU) processor, or a heterogeneous computing architecture including multiple general-purpose processors. A processor herein may refer to one or more devices, circuits, and / or processing cores for processing data (e.g., computer program instructions).

[0178] In a specific implementation, as an embodiment, the electronic device may further include an output device 805 and an input device 806. The output device 805 communicates with the processor 801 and can display information in a variety of ways. For example, the output device 805 can be a liquid crystal display (LCD), a light emitting diode (LED) display device, a cathode ray tube (CRT) display device, or a projector, etc. For example, it can be a display device such as a vehicle-mounted HUD, AR-HUD, or a display. The input device 806 communicates with the processor 801 and can receive user input in a variety of ways. For example, the input device 806 can be a mouse, a keyboard, a touch screen device, or a sensing device, etc.

[0179] The embodiments of the present disclosure provide a computer-readable storage medium having computer program instructions stored thereon, which, when executed by a processor, implement the method of the above embodiments. For example, the steps of the method shown in Figures 2, 3, 4, or 5 can be executed.

[0180] Embodiments of the present disclosure provide a computer program product, which may include, for example, computer-readable code or a non-volatile computer-readable storage medium carrying computer-readable code. When the computer program product is executed on a computer, the computer executes the method described in the above embodiments. For example, the steps of the method shown in FIG. 2 , FIG. 3 , FIG. 4 , or FIG. 5 may be executed.

[0181] The present disclosure may be a system, method and / or computer program product. The computer program product may include a computer-readable storage medium carrying computer-readable program instructions for causing a processor to implement various aspects of the present disclosure.

[0182] A computer-readable storage medium can be a tangible device that can hold and store instructions for use by an instruction execution device. A computer-readable storage medium can be, for example, but not limited to, an electrical storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination thereof. More specific examples (a non-exhaustive list) of computer-readable storage media include: a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a static random access memory (SRAM), a portable compact disc read-only memory (CD-ROM), a digital versatile disk (DVD), a memory stick, a floppy disk, a mechanical encoding device, such as a punch card or a raised structure in a groove on which instructions are stored, and any suitable combination thereof. As used herein, a computer-readable storage medium is not to be construed as a transient signal per se, such as a radio wave or other freely propagating electromagnetic wave, an electromagnetic wave propagating through a waveguide or other transmission medium (e.g., a light pulse through a fiber optic cable), or an electrical signal transmitted through an electrical wire.

[0183] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to each computing / processing device, or downloaded to an external computer or external storage device via a network, such as the Internet, a local area network, a wide area network, and / or a wireless network. The network can include copper transmission cables, fiber optic transmission, wireless transmission, routers, firewalls, switches, gateway computers, and / or edge servers. The network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards the computer-readable program instructions to be stored in the computer-readable storage medium in each computing / processing device.

[0184] The computer program instructions for performing the operations of the present disclosure may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state setting data, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages ​​such as Smalltalk, C++, and conventional procedural programming languages ​​such as "C" language or similar programming languages. Computer-readable program instructions may be executed entirely on a user's computer, partially on a user's computer, as an independent software package, partially on a user's computer, partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., utilizing an Internet service provider to connect via the Internet). In some embodiments, an electronic circuit, such as a programmable logic circuit, a field programmable gate array (FPGA), or a programmable logic array (PLA), may be personalized by utilizing the state information of the computer-readable program instructions. The electronic circuit may execute the computer-readable program instructions, thereby realizing various aspects of the present disclosure.

[0185] Various aspects of the present disclosure are described herein with reference to flowcharts and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the present disclosure. It should be understood that each block of the flowcharts and / or block diagrams, and combinations of blocks in the flowcharts and / or block diagrams, can be implemented by computer-readable program instructions.

[0186] These computer-readable program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, thereby producing a machine, so that when these instructions are executed by the processor of the computer or other programmable data processing device, a device is generated that implements the functions / actions specified in one or more blocks in the flowchart and / or block diagram. These computer-readable program instructions can also be stored in a computer-readable storage medium, where these instructions cause the computer, programmable data processing device, and / or other device to operate in a specific manner. Thus, the computer-readable medium storing the instructions comprises an article of manufacture that includes instructions for implementing various aspects of the functions / actions specified in one or more blocks in the flowchart and / or block diagram.

[0187] Computer-readable program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other device, so that a series of operational steps are performed on the computer, other programmable data processing apparatus, or other device to produce a computer-implemented process, thereby causing the instructions executed on the computer, other programmable data processing apparatus, or other device to implement the functions / actions specified in one or more blocks in the flowchart and / or block diagram.

[0188] The flow charts and block diagrams in the accompanying drawings show the possible architecture, functions and operations of the systems, methods and computer program products according to multiple embodiments of the present disclosure. In this regard, each box in the flow chart or block diagram can represent a part of a module, program segment or instruction, and the part of the module, program segment or instruction contains one or more executable instructions for realizing the prescribed logical function. In some alternative implementations, the functions marked in the box can also occur in a sequence different from that marked in the accompanying drawings. For example, two consecutive boxes can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flow chart, and the combination of the boxes in the block diagram and / or flow chart can be implemented by a dedicated hardware-based system that performs the prescribed function or action, or can be implemented by a combination of dedicated hardware and computer instructions.

[0189] While various embodiments of the present disclosure have been described above, the foregoing description is intended to be illustrative, non-exhaustive, and not limited to the disclosed embodiments. Many modifications and variations will be apparent to those skilled in the art without departing from the scope and spirit of the described embodiments. The terminology used herein is selected to best explain the principles of the embodiments, their practical applications, or technological improvements in the marketplace, or to enable others skilled in the art to understand the embodiments disclosed herein.

Claims

1. A quantum-resistant electronic signature generation method, characterized in that: Applied to a first terminal, the method includes: Generate a public key and a private key based on a target unbalanced oil and vinegar algorithm; wherein the central mapping of the target unbalanced oil and vinegar algorithm includes a first matrix, a second matrix and a third matrix, the elements in the first matrix and the second matrix are linear polynomials about n variables, and the elements in the third matrix are quadratic oil and vinegar polynomials about the n variables; the n variables are oil variables and vinegar variables in the target unbalanced oil and vinegar algorithm, and n is a positive integer; Get the target message; Signing the target message using the private key to generate a target signature; The target message, the target signature, and the public key are sent to the second terminal, so that the second terminal verifies the target signature using the target message and the public key.

2. The method according to claim 1, characterized in that The method of generating a private key based on the target unbalanced oil and vinegar algorithm includes: Randomly generate m first linear polynomials about the n variables, and construct an m*m order circulant matrix as the first matrix according to the first linear polynomials, wherein m is a positive integer; Randomly generate m*s second linear polynomials about the n variables, and construct an m*s order matrix as the second matrix according to the second linear polynomials, where s is a positive integer; Randomly generate m*s target quadratic oil-vinegar polynomials about the n variables, and construct an m*s order matrix as the third matrix according to the target quadratic oil-vinegar polynomials; A first reversible matrix of order t*t and a second reversible matrix of order n*n are randomly generated, where t=m*s, and the first matrix, the second matrix, the third matrix, the first reversible matrix and the second reversible matrix are used as the private key.

3. The method according to claim 2, characterized in that The method of generating a public key based on a target unbalanced oil and vinegar algorithm includes: Constructing a center map according to the first matrix, the second matrix and the third matrix; A composite mapping of the first reversible matrix, the central mapping, and the second reversible matrix is ​​used as the public key.

4. The method according to claim 3, characterized in that The constructing a center mapping according to the first matrix, the second matrix and the third matrix includes: Multiplying the first matrix by the second matrix to obtain a product result; The product result is summed with the third matrix to obtain the center mapping.

5. The method according to claim 3, characterized in that: The step of signing the target message using the private key to generate a target signature includes: Processing the target message to generate a corresponding hash value; According to the mapping result of the first reversible matrix to the hash value, establish an m*s order target message matrix; Randomly generate a value for the vinegar variable; Randomly generate a value for each element in the first matrix; According to the values ​​of each element in the first matrix, the second matrix, the third matrix and the target message matrix Matrix, establish linear equations; Substituting the value of the vinegar variable into the linear equation system and solving it to obtain the value of the oil variable; The target signature is generated according to the value of the oil variable, the value of the vinegar variable and the second reversible matrix.

6. A quantum-resistant electronic signature verification method, characterized in that: Applied to the second terminal, the method further includes: Receive a target message, a target signature and a public key; wherein the public key is generated based on a target unbalanced oil-vinegar algorithm, the central mapping of the target unbalanced oil-vinegar algorithm includes a first matrix, a second matrix and a third matrix, the elements in the first matrix and the second matrix are linear polynomials about n variables, and the elements in the third matrix are quadratic oil-vinegar polynomials about the n variables; the n variables are oil variables and vinegar variables in the target unbalanced oil-vinegar algorithm, and n is a positive integer; Performing a calculation using the public key and the target message to obtain a calculation result; The operation result is compared with the target signature. If the operation result is the same as the target signature, the verification result is verification passed; otherwise, the verification result is verification failed.

7. The method according to claim 6, characterized in that The center mapping is determined by performing a sum operation on a product result of the first matrix and the second matrix and the third matrix.

8. A quantum-resistant electronic signature generation device, characterized in that: Applied to a first terminal, the device includes: A public-private key pair module, used to generate a public key and a private key based on a target unbalanced oil-vinegar algorithm; wherein the central mapping of the target unbalanced oil-vinegar algorithm includes a first matrix, a second matrix and a third matrix, the elements in the first matrix and the second matrix are linear polynomials about n variables, and the elements in the third matrix are quadratic oil-vinegar polynomials about the n variables; the n variables are the oil variable and the vinegar variable in the target unbalanced oil-vinegar algorithm, and n is a positive integer; An acquisition module is used to acquire target messages; A signature module, used to sign the target message using the private key to generate a target signature; The sending module is used to send the target message, the target signature and the public key to the second terminal, so that the second terminal verifies the target signature by using the target message and the public key.

9. An electronic device, characterized in that: include: processor; a memory for storing processor-executable instructions; Wherein, the processor is configured to implement the method described in any one of claims 1 to 5 or any one of claims 6-7 when executing the instructions stored in the memory.

10. A computer-readable storage medium having computer program instructions stored thereon, characterized in that: When the computer program instructions are executed by a processor, the method described in any one of claims 1 to 5 or the method described in any one of claims 6-7 is implemented.

Citation Information

Patent Citations

  • Quantum-computing-resistant identity-based digital signature scheme

    CN114337995A

  • Multivariate quadratic signature scheme based on central map with oil-oil quadratic terms secure against quantum computers

    US20200145201A1

  • An online and offline circulating unbalanced oil and vinegar signature method

    US20220021541A1

Cited By

  • Quantum attack resistant ubiquitous network data security gateway

    CN120546884A

  • Ubiquitous network data security gateway resistant to quantum attacks

    CN120546884B

  • Multi-party collaborative anti-quantum signature method and system based on homomorphic hash

    CN120979680A

  • Lightweight anti-quantum key agreement protocol method and system for edge computing

    CN121485935A