Post-quantum digital signature system for preserving integrity, authenticity and disallowing repudiation of digitally transmitted message and method thereof
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- UNIVERSITI PUTRA MALAYSIA
- Filing Date
- 2025-07-11
- Publication Date
- 2026-08-06
Smart Images

Figure MY2025050044_06082026_PF_FP_ABST
Abstract
Description
[0001] POST-QUANTUM DIGITAL SIGNATURE SYSTEM FOR PRESERVING INTEGRITY, AUTHENTICITY AND DISALLOWING REPUDIATION OF DIGITALLY TRANSMITTED MESSAGE AND METHOD THEREOF
[0002] FIELD OF THE INVENTION
[0003] The present invention relates generally to post-quantum cryptography. More particularly, the present invention relates to an improved post-quantum cryptographic system for preserving integrity, authenticity, and disallowing repudiation of an electronic message in a transaction over a data communication system between a sender and a recipient through a certifying authority.
[0004] BACKGROUND OF THE INVENTION
[0005] Business, banking, and other crucial facets of our life now depend more and more on computers. More than ever, it is crucial to safeguard computers from malicious software. A communication network is needed to enable data transfer or transaction within a specific community while ensuring there is no unauthorised or unintentional access to the data from outside the community.
[0006] Cryptographic techniques that are thought to be resistant to attack by a quantum computer are known as post-quantum cryptography. It should be noted that Shor's algorithm can effectively break the currently most widely used public-key techniques, which depend on the discrete logarithm problem, the elliptic-curve discrete logarithm problem, and the integer factorization problem. Most current symmetric cryptographic algorithms and hash functions are thought to be relatively secure against assaults by quantum computers, in contrast to the threat that quantum computing poses to current public-key algorithms.
[0007] Many post-quantum cryptography methods share the property of requiring bigger key sizes than conventional "pre-quantum" public key algorithms. Key size, computational efficiency, and ciphertext or signature size all frequently require tradeoffs. Naturally, there have been a lot of studies into post-quantum cryptography techniques that are immune to attacks by quantum computers by cryptographers since the invention of quantum computer. Post-quantum cryptography is a very young field, and most of the post-quantum cryptography algorithms has not undergone sufficient cryptanalysis to be fit for usage in production. The difficulty with post-quantumcryptography algorithms, is that most encryption and digital signature algorithm candidates have a chance of either decryption or verification failure that can be analytically proven. It is important to make sure that the data's confidentiality, integrity, authenticity, and the unique feature that forbids the sender from repudiating are not jeopardised when it is in transit or transmission.
[0008] Therefore, enhanced post-quantum cryptography systems and techniques are required to maintain data secrecy and integrity while addressing the drawbacks and issues of the state of the art. Although there are systems and procedures in the previous art, there is still a great deal of space for advancement for many practical uses of post-quantum cryptography.
[0009] SUMMARY OF THE INVENTION
[0010] Accordingly, to give a fundamental knowledge of various features of the invention, the following presents a condensed summary of the invention. This synopsis does not provide a thorough description of the invention. Its main objective is to provide a basic explanation of some inventive concepts before a more thorough description is provided.
[0011] Accordingly, to maintain the integrity, authenticity, and the unique feature that forbids the sender from repudiating transaction of an electronic message across a data communication system between a sender and a recipient, the present invention offers a post-quantum digital signature system.
[0012] The cryptography system of the present invention may be characterized by a cryptographic unit comprising a memory having a key generation module and a cryptographic module, wherein the key generation module is configured for generating private seeds having a minimum length of 128 bits either from a true random number generator or a pseudo random number generator and comprises an algorithm for generating public-private key pairs which sources from the Modular Reduction Problem (MRP), whilst a trapdoor associated thereof are random elements from a public prime list, wherein the cryptographic module is configured for digitally signing an electronic message and verifying a digital signature of the electronic message, a digital signature algorithm which sources from the MRP, wherein the digital signature algorithm employs a hash function for generating a hash value from the electronic message; and a processor.Preferably, the hash function includes the standard hash algorithm-2 (SHA-2) hash function.
[0013] Preferably, the cryptographic unit is deployed at the sender, the recipient and a certifying authority which is in communication with the sender and the recipient in respect of the transaction thereof.
[0014] Preferably, the certifying authority (CA) residing on a server is configured to authenticate the transaction thereof by verifying an identifier of the sender that is provided by the recipient.
[0015] Preferably, the CA generates and distributes public-private key pairs, where the public key is based on the private key thereof, for each of the sender through a dedicated telecommunication line.
[0016] Preferably, the CA generates and distributes public keys, where the public key is based on the private key thereof, for each of the recipient through a dedicated telecommunication line.
[0017] Preferably, the sender and the recipient have respective identifiers which are assigned by and stored in a database of the certifying authority.
[0018] Preferably, the cryptographic unit determines whether the signature received by the recipient is a forged signature by comparing a signature parameter with a generated value and utilizing a hash value retrieved from the electronic message.
[0019] Preferably, the cryptographic unit determines whether the electronic message transmitted by the sender is unaltered by comparing two generated values and utilizing a hash value retrieved from the electronic message.
[0020] Preferably, the trapdoor are random elements from the public prime list and are unknown to any unauthorized party.
[0021] In accordance with another aspect, the present invention provides a method of preserving integrity, authenticity, and disallowing sender repudiation of an electronic message in a transaction over a data communication system between a sender and a recipient.The method of the present invention may be characterized by the steps of digitally signing the electronic message to generate a digital signature of the electronic message using an algorithm residing in a cryptographic module of a cryptographic unit at the sender’s end, wherein the algorithm sources from the MRP and employs a hash function for generating a hash value from the electronic message; transmitting the digital signature along with an identifier of the sender to the recipient; notifying, by the recipient, receipt of the digital signature and providing the identifier of the sender embedded in the digital signature to a CA; authenticating, by the CA, the transaction thereof by verifying the identifier of the sender; retrieving, by the recipient, the hash value from the electronic message thereof; verifying the digital signature is not a forged signature using an algorithm residing in a cryptographic module of a cryptographic unit at the recipient’s end, wherein the algorithm employs a hash function for generating a hash value from the electronic message; and determining, by the recipient, the electronic message transmitted by the sender is unaltered by comparing two generated values, wherein the algorithm employs a hash function for generating a hash value from the electronic message.
[0022] Preferably, the step of authenticating includes comparing the identifier of the sender and validity information against that of stored in a database of the CA.
[0023] Preferably, the hash function includes the standard hash algorithm-2 (SHA-2) hash function.
[0024] Reading the in-depth explanation provided herein below with proper reference to the accompanying drawings will help better understand the aforementioned as well as other objects, features, aspects, and benefits of the present invention.
[0025] BRIEF DESCRIPTION OF THE DRAWINGS
[0026] A more complete appreciation of the invention and many of the attendant advantages thereof will be readily as the same becomes better understood by reference to the following detailed description when considered in connection with the accompanying drawings, wherein:
[0027] Figure 1 is a schematic block diagram depicting a post-quantum cryptographic system according to one embodiment of the present invention;Figure 2 is a schematic block diagram depicting the sender, the recipient and the CA in a transaction over a data communication system according to one embodiment of the present invention; and
[0028] Figure 3 is a flow diagram showing the steps involved in a method for preserving integrity, authenticity, and disallowing the sender to repudiate data sent according to one embodiment of the present invention.
[0029] It is noted that the drawings may not be to scale. The drawings are intended to depict only typical aspects of the invention, and therefore should not be considered as limiting the scope of the invention. In the drawings, like numberings represent like elements between the drawings.
[0030] DETAILED DESCRIPTION OF THE INVENTION
[0031] It is an object of the present invention to provide a post-quantum digital signature system and a method thereof for preserving integrity, authenticity and disallowing the sender to repudiate sending an electronic message in a transaction over a data communication system between a sender and a recipient that employs an algorithm developed in the present invention entitled KAZ-SIGN that is post quantum secure and is based on the MRP.
[0032] In accordance with one preferred embodiment of the present invention, the post-quantum cryptographic system comprises a cryptographic unit 100 as shown in Figure 1. The cryptographic unit 100 preferably comprises a memory 200 which comprises a key generation module 201 and a cryptographic module 202 and a processor 300. In a minimum configuration, the cryptographic unit 100 is essentially a computer having the processor 300 and the memory 200 that are connected to each other.
[0033] The cryptographic unit 100 is adapted to generate random private parameters of minimum length equal to at least 128 bits. The algorithm to generate the key resides in the key generation module 201 in the memory 200. The algorithm carries out a computation based on the KAZ-SIGN algorithm. It may generate private keys which will next be used to generate public keys to thus consequently enable digital signing and verification of the electronic message for digital signature applications without compromising the integrity, authenticity of theelectronic message and disallowing the sender to repudiate sending the electronic message. This execution utilizes minimum memory requirements.
[0034] The key generation module 201 comprises of an algorithm that once executed is capable of generating random private seeds with a minimum length equal to 128 bits without compromising the security strength of the key. Depending on the security needed, the length of the private seed generated could be made to be greater than 128 bits.
[0035] The key generation module 201 is configured for generating private seeds having a minimum length of 128 bits and for generating public-private key pairs which sources security from the hardness of solving the MRP whilst a trapdoor associated thereof are random elements from a public prime list and requires exponential time to brute force the correct elements from the list. The key generation module 201 preferably employs a true random number generator or a pseudo random number generator.
[0036] The key generation module 201 which implements a trapdoor function in which the private parameters of the modeled system are computationally infeasible to be computed by means of reverse computations based on the public parameters of the modeled system. The sample space for each private key is at minimum of the size 2128.
[0037] The cryptographic module 202 may be adapted for digitally signing the electronic message and verifying a digital signature of the electronic message, a digital signature algorithm of which sources security from the hardness of solving the MRP.
[0038] The cryptographic module 202 is configured to execute the KAZ-SIGN digital signature scheme. It comprises an algorithm that employs a hash function for generating a hash value from the electronic message. Preferably, the hash function includes the standard hash algorithm-2 (SHA-2) hash function.
[0039] In addition to the aforementioned processor 300 and memory 200, the cryptographic unit 100 may also include peripheral hardware such as an electronic data storage device, a network card and other related components as generally known in the art.To understand the fundamental operation of the KAZ-SIGN algorithm of the present invention, the following definitions should be taken into consideration:
[0040] Definition 0.1
[0041] Let H(·) be a hash function. Let φ(·) be the usual Euler-totient function. Let ℓ(·) be the function that outputs the bit length of a given input. Let gcd denote the greatest common divisor. Let CRT denote the Chinese Remainder Theorem algorithm.
[0042] Definition 0.2
[0043] Let N = ∏ji=1pibe a composite number and LN= ℓ(N). Let pkbe a factor of N. Choose α ∈ (2n-1, N). Compute A ≡ α(mod pk).
[0044] The MRP is, upon given the values (A, N, pk), one is tasked to determine α ∈ (2L-1, N).
[0045] Remark 0.1
[0046] Let LPk= ^ pk~) be the bit length of pk. The complexity to obtain a is O(2LN~Lpk). When deploying Grover’s algorithm on a quantum computer, the complexity to / LN~Lpk\
[0047] obtain a is 0 ( 2 2 1. In other words, if pk« N°, for some 6 G (0,1), the complexity to obtain a is V1-5). When deploying Grover’s algorithm on a quantum computer, the complexity to obtain a is O ( N 2 ).
[0048] Definition 1
[0049] The public prime list of j-elements greater than 2 is the list P =
[0050]
[0051] This public list will be embedded within the cryptographic unit 100 executing the KAZ-SIGN algorithm to be distributed among parties intending to execute secure communication with the system of the present invention.
[0052] Definition 2
[0053] A public modular is Q =
[0054]
[0055] Pi, where ptis from the list P and kQ< j. The public modular will be made known to all parties involved in the secure communication provided by the cryptographic unit 100 executing the KAZ-SIGN algorithm.Definition 3
[0056] Let LQ= ℓ(Q) be the bit length of Q. Let q be a random prime and Lq= ℓ(q) ≈ LQ. Next compute a random composite integer given by G0= (210) ∏ki=1piewhere piis from the list P and eifrom ℤ11. Then choose a random prime R. Such R, has its own natural order in ℤG. Let that order be denoted as G1. We can observe the natural relation given by RG≡ 1 mod G0where φ(G0) ≡ 0 mod G1. Let LG= ℓ(G1). Ensure LGqQ= ℓ(G1qQ) is either 256, 384 or 512 (depending on the security level needed). Otherwise, tweak the generation of the parameters (G0, q, Q) accordingly. The system parameters are (k, q, Q, R, G0, G1, LG, LGqQ). The system parameters will be made known to all parties involved in the secure communication provided by the cryptographic unit 100 executing the KAZ-SIGN algorithm.
[0057] Definition 4
[0058] Let k be the security level needed, either 256, 384 or 512. Choose even random α ∈ (2k+L, 2k+L+1). Compute public verification key-1 given by V1≡ α mod G1. Choose random prime a and random ω1both ≈ 232. Then, compute secret parameter b ≡ aφ(φ(G))mod ω1φ(G1). Compute public verification key-2 given by V2≡ Q(αφ(Q)b) mod qQ. Compute secret signing key given by SK ≡ αφ(Q)bmod G1qQ. If SK ≡ 0 mod G1Q, choose new α, compute (V1, V2) and ensure SK ≢ 0 mod G1Q. Output verification keys (V1, V2), keep signing key SK secret and destroy parameter (α, a, b, ω1).
[0059] Definition 5
[0060] Let m ∈ ℤNbe the message to be signed. Let h = H(m), i = 0 and S2= 0. Choose random prime (r1, r2) and random (ω2, ω3) both ≈ 232. Next, compute secret parameter β1≡ r1φ(φ(G))mod ω2φ(G1) and β2≡ r2φ(φ(G))mod ω3φ(G1). Next, compute S1≡ (SK)(hφ(qQ)β1+ hφ(qQ)β2) mod G1qQ. Next, compute Y1≡ (V1φ(Q))(2hφ(qQ)) mod G1Q and SF1= CRT([V2 / Q, Y1], [q, G1Q]). Then, if
[0061] ℓ(S1) ≠ LGqQor S1mod G1qQ - SF1= 0, repeat the process and set i := i + 1; h := h + i and S2:= i. Else, output digital signature, DS = (S1, S2) and destroy (β1, β2, r1, r2, ω2, ω3).Definition 6
[0062] The KAZ-SIGN digital signature forgery detection procedure type – 1 is defined by the procedure of computing w0≡ (S1mod G1qQ) − S. If w0≠ 0, reject the digital signature.
[0063] Definition 7
[0064] The KAZ-SIGN digital signature forgery detection procedure type – 2 is defined by the procedure of computing w1≡ ℓ(S1) − LGqQ. If w1≠ 0, reject the digital signature.
[0065] Definition 8
[0066] The KAZ-SIGN digital signature forgery detection procedure type - 3 is defined by computing the following procedures:
[0067] 1) Y1≡ (V1φ(Q))(2hφ(qQ)) mod G1Q and
[0068] 2) SF1= CRT ([V2 / Q, Y1], [q, G1Q])
[0069] 3) w2≡ (S1mod G1qQ) − SF1
[0070] If w2= 0, reject the digital signature.
[0071] Definition 9
[0072] The KAZ-SIGN digital signature forgery detection procedure type - 4 is defined by computing the following procedures:
[0073] 1) Y2≡ (V1φ(Q))(2hφ(qQ)) mod G1and
[0074]
[0075] 2) SF2= CRT ([V2 / Q, Y2], [qQ / e, G1]) where e = gcd(Q, G1).
[0076]
[0077] 3) w3≡ (S1mod G1qQ / e) − SF2
[0078]
[0079] F2
[0080] If w3= 0, reject the digital signature.
[0081] Definition 10
[0082] The KAZ-SIGN digital signature forgery detection procedure type – 5 is defined by the procedure of computing w4≡ QS1 / 2 mod qQ and w5= w4− V2. If w5≠ 0, reject the digital signature.Definition 11
[0083] The KAZ-SIGN verification of the digital signature is given by computing the values:
[0084] a) h = H(m) + S2
[0085] b) yx= / ?S1mod Go.
[0086] > ((y^Q^2h‘t’^') mod GA
[0087] c
[0088]
[0089] ) y2= ' / mod Go.
[0090] If y1= y2accept the digital signature, else reject the digital signature.
[0091] More particularly, the operation of the key generation algorithm based on the KAZ-SIGN algorithm of the present invention is described with reference to aforementioned Definitions 1-4. While the digital signing and verification procedures are described with reference to the aforementioned Definitions 5-11.
[0092] With reference to Figures 2 to 3, the cryptographic system of the present invention employs a CA to authenticate a transaction between the two correspondents, i.e. the sender and the recipient over a data communication system. The CA residing on a server is configured to authenticate the transaction thereof by verifying an identifier of the sender that is provided by the recipient. The CA, the sender and the recipient are preferably interconnected to each other by a communications link (see thick line). More particularly, the communication link interconnects the sender and the recipient, and the communication link interconnects each respective correspondent, i.e. the sender and the recipient to the CA. These communication links may include but not limited to telephone lines or wireless communication links that thus serve to allow the correspondents and the CA to route messages to the intended recipients.
[0093] Each of the correspondents, i.e. the sender and the recipient, and the CA incorporates the cryptographic unit 100 that contain an algorithm that executes the KAZ-SIGN digital signature algorithm for digitally signing a message and generating its digital signature and verifying a message and its corresponding digital signature. In other words, the cryptographic unit 100 is deployed at the sender and the recipient as well as the CA. Each cryptographic unit 100 employed thereof can perform a hashing mechanism according to the industry standard SHA-2 algorithm or any other suitable hashing mechanism. The cryptographic unit 100 is also capable of generating random seeds needed.Each correspondent in the provisions of the digital signature system of the present invention has a public key and private key and a unique identifier. The public-private key pair is generated randomly by the CA. The public key is derived from the private key which was previously generated.
[0094] With reference to Figures 2 to 3, a transaction involving the recipient and the sender that have been authenticated by the CA will now be described by way of following non-limiting example.
[0095] Example 1
[0096] This transaction involves the sender which is sending a digitally signed message to the recipient.
[0097] The sender has a unique identifier, IDA- The recipient has a verification key pair of the sender (1,72) which was generated randomly by the CA.
[0098] The identifier ID is a unique element that the CA uses to distinguish between correspondents in a particular data-communication system. The CA stores the unique identifier corresponding to correspondent A IDA in its database. The unique identifier IDA conveniently remains the same for all correspondence originating from the sender. Whether the unique identifier IDA falls within the validity period, it shall be a distinguisher as to whether a communication process is valid or not.
[0099] To initiate an exchange of an electronic or digital message, m for example, between the sender and the recipient, the electronic message will be digitally signed and then sent by the sender to the recipient over the communication link. The digital signature, DS = (S1, S2) of the electronic message, m, will be sent together with the sender’s unique identifier, IDA- The digital signature, DS = (S1, S2) was derived using the KAZ-SIGN algorithm as developed by the present invention.
[0100] The signature, DS = (S1, S2), is a result of an operation upon the message to be sent by the sender. The operation conducted by the cryptographic unit 100 is phrased using the language of mathematics which is in line with Definition 5 as follows:-i
[0101]
[0102] =+ h< KqQ)p2} = (SK^fh^Wi + ^(^^)modwhere h is a hash value that results from the computation by a hash function H operating on the message m added with corresponding S2as defined in Definition 5 to be sent to the recipient originating from the sender. That is, h = H(m) + S2.
[0103] Finally, with reference to the sender, the cryptographic unit 100 relays to the recipient the digital signature, DS = (Si, S2) generated thereof. The sender transmits the message m and digital signature together with a unique identifier IDA of the sender intended for the recipient.
[0104] Upon receipt of the sender’s message m and digital signature and its unique identifier ID, the recipient notifies the CA that it has received a message from the sender by sending sender’s unique identifier IDA, to the CA. Said communication by the recipient to the CA of the sender’s unique identifier IDA, was communicated via a dedicated communication link. Upon receiving the notification, the CA returns to the recipient information on the validity of sender’s identity. This was done by the CA through locating the validity information of sender’s identity using sender’s unique identifier IDAinits database of subscribers.
[0105] The next step is the verification process carried out by the recipient where it involves step of verifying the electronic message m which was digitally signed by sender’s private signing key SK and ephemeral signing parameters (r1,r2, )2, )3). The verification process by the recipient by using the language of mathematics which is in line with Definition 6, 7, 8, 9, 10 and 11 as follows:-
[0106] Upon receiving the digital signature, DS = (Si, S2)
[0107] A) Conduct the KAZ-SIGN digital signature forgery detection procedure type - 1 by computing computing w0= (Sxmod G qQ) - S. If w0= 0, reject the digital signature.
[0108] B) Conduct the KAZ-SIGN digital signature forgery detection procedure type - 2 by computing computing
[0109]
[0110] = 11(5^ - LGiqQ. Ifwx#= 0, reject the digital signature.
[0111] C) Conduct the KAZ-SIGN digital signature forgery detection procedure type - 3 by computing:a. Y4= mod G4Q and
[0112] b. SF1= C / ?7’([|,r1], [q, G1Q])
[0113]
[0114] c. w4= (S4mod G4qQ) — SF1
[0115] If w2= 0, reject the digital signature.
[0116] D) Conduct the KAZ-SIGN digital signature forgery detection procedure type - 4 by computing:
[0117] a. Y2= mod G4and
[0118]
[0119] b. SF2= CRT y2l,
[0120]
[0121] GJ) where e = gcd (Q, G.
[0122] \L V J L cr J z
[0123] c. w3= (Si mod G4qQ) — SF2
[0124] If w3= 0, reject the digital signature.
[0125] E) Conduct the KAZ-SIGN digital signature forgery detection procedure type -5 by OS
[0126] computing w4= mod qQ and w5= w4- V2. If w5#= 0, reject the digital
[0127]
[0128] signature.
[0129] F) Conduct the KAZ-SIGN verification of the digital signature is given by computing the values:
[0130] a) h = H(m) + S2
[0131] b) y4= / ?S1mod Go.
[0132] c
[0133]
[0134] ) y2=7'mod Go.
[0135] If Ti = Y2 accept digital signature, else reject the digital signature.
[0136] It is apparent that the execution of the verification computational process by the recipient in accordance with the above equations will be able to verify or reject a digital signature that was received by the recipient with probability equal to 1. This is because, by the design of the KAZ-SIGN algorithm of the present invention, the verification procedure will not fail. That is, the probability of verification failure is 0.
[0137] Henceforth with the implementation of the scheme mentioned above, in orderto verify that the message transmitted by the sender is indeed not a forged signature, the recipient is able to come to a conclusion whether the digital signature is a forged signature or not by conducting the KAZ-SIGN digital signature forgery detection procedures type - 1, type - 2, type - 3, type - 4, and type - 5. If the digital signature fails either one of the KAZ-SIGN digital signature forgery detection procedure, the signature has deemed to be a forged signature and will consequently be rejected by recipient. Hence, the problem of identifying a forged signature and mistake of rejecting a valid signature was solved.
[0138] To verify that the message transmitted by the sender is indeed not altered during transmission, the recipient compares y1and y2which utilizes the hash value of the received electronic message m through the relation h = H(m) + S2.
[0139] If the values of y and y2are equal, the recipient will accept the message, as the message has not been altered en-route from the sender. On the other hand, if the computed values of y and y2are not equal, the message sent by the sender is deemed to have been altered from the original message from the sender and will consequently be rejected by recipient.
[0140] Henceforth with the implementation of the scheme mentioned above, the recipient can come to a conclusion whether the message has been altered or not during transmission, since the message received can be determined whether it has been altered or not by comparing the two verification values. Hence, the problem of the integrity of the message was solved.
[0141] The implementation of the digital signature scheme as described in the preceding paragraphs of the description demonstrates and ensures that a minimal interaction between the individual correspondents, i.e., the sender and the recipient and the CA, hence reducing web traffic. The CA only needs to have a database of all the correspondent’s unique identifiers. The CA only produces the information of the validity of the identifier of the sender when being requested by an enquiring correspondent that furnishes the CA with the unique identifier of a correspondent that sends a message to said enquiring correspondent.2
[0142] The steps involved in the method of the present invention in which a simple transaction of a digitally signed message by a sender to a recipient will now be described in a more concise manner, with reference to Figure 3.
[0143] In step 400, the electronic message was digitally signed to generate a digital signature of the message using the KAZ-SIGN algorithm. Following that, in step 401, the sender transmits the digital signature, to the recipient. The digital signature transmitted also comprises the sender’s unique identifier ID A.
[0144] In the next step, i.e. step 402, the recipient contacted the CA for notifying the receipt of the digital signature from the sender while providing the sender’s unique identifier IDA-
[0145] Subsequently, i.e. step 403, involves the CA verifying the sender’s validity by means of the sender’s unique identifier IDA-
[0146] In step 403, the CA decides as to whether to reject or to accept the unique identifier IDA- If the identifier from sender is still valid, i.e. the CA has a copy of the same identifier in its database and the IDA is still within the validity period, the CA will accept the identifier as an identifier originating from the sender that still has an identifier within the validity period and will subsequently proceed to send to the recipient an acknowledgement to proceed verify the digital signature.
[0147] If, on the other hand, the unique identifier IDA sent by the recipient to the CA is identified either to be not located in the CA’s database or no longer within the validity period, then that identifier does not belong to the sender, hence not a valid identifier from a valid correspondent and consequently the digital signature sent to the recipient can be disregarded. As a result, the CA will reject the identifier.
[0148] Upon completion of step 403, the recipient will proceed to verify whether the received digital signature of the electronic message m is forged or not in step 404 by conducting the KAZ-SIGN digital signature forgery detection procedure type - 1, type - 2, type - 3, type - 4, and type - 5.In the final step of 405, the recipient compares the computed values of y and y2. If the result of the comparison of y and y2yields an identical match, then the recipient thus verifies that the received digital message has not been altered or modified or tampered during transmission.
[0149] The terms “a” and “an,” as used herein, are defined as one or more than one. The term “plurality,” as used herein, is defined as two or more than two. The term “another,” as used herein, is defined as at least a second or more. The terms “including” and / or “having,” as used herein, are defined as comprising (i.e., open language).
[0150] While this invention has been particularly shown and described with reference to the exemplary embodiments thereof, it will be understood by those skilled in the art that various changes in form and details may be made therein without departing from the scope of the invention as defined by the appended claims.
Claims
CLAIMS1. A post-quantum cryptographic system for preserving integrity, authenticity and disallowing repudiation by a sender of an electronic message in a transaction over a data communication system, characterized in that, the post-quantum cryptographic system comprising:a cryptographic unit (100) a memory (200) having a key generation module (201) and a cryptographic module (202);wherein the cryptographic unit (100) are deployed at a sender, a recipient and a CA residing on a server in respect of the transaction thereof;wherein the CA residing on the server is configured to authenticate the transaction thereof by verifying an identifier of the sender that is provided by the recipient;wherein the key generation module (201) is configured for generating private seeds having a minimum length of 128 bits either from a true random number generator or a pseudo random number generator and comprises an algorithm for generating public-private keys which sources from the MRP, whilst a trapdoor associated thereof is a random choice of elements from a public prime list; wherein the cryptographic module (202) is configured for digitally signing the electronic message and verifying a digital signature of the electronic message, a digital signature algorithm of which sources from the MRP, wherein the digital signature algorithm employs a hash function for generating a hash value from the electronic message, and a processor (300).
2. The post-quantum cryptographic system according to Claim 1, wherein the hash function includes the standard hash algorithm-2, SHA-2 hash function or any other suitable hash function.
3. The post-quantum cryptographic system according to Claim 1, wherein the CA generates and distributes a public-private key pair for each of the sender and public key based thereof for each of the recipient through a dedicated telecommunication line.
4. The post-quantum cryptographic system according to Claim 1, wherein the sender and the recipient have respective identifiers which are assigned by and stored in a database of the CA.
5. The post-quantum cryptographic system according to Claim 1, wherein the cryptographic unit (100) determines whether the digital signature received is a forged digital signature by comparing a generated value against a received value together with a hash value retrieved from the electronic message.
6. The post-quantum cryptographic system according to Claim 1, wherein the cryptographic unit (100) determines whether the electronic message transmitted by the sender is unaltered by comparing two generated values together with a hash value retrieved from the electronic message.
7. The post-quantum cryptographic system according to Claim 1, wherein the sender private signing key and sender ephemeral private signing key is unknown to any unauthorized party.
8. The post-quantum cryptographic system according to Claim 1, wherein the trapdoor is the sender private signing key and sender ephemeral private signing key from a public list.
9. A method of preserving integrity, authenticity, and disallowing repudiation by a sender of an electronic message in a transaction over a data communication system between a sender and a recipient, characterized in that, the method comprising the steps of:digitally signing the electronic message to generate a digital signature of the electronic message using an algorithm residing in a cryptographic module of a cryptographic unit at the sender’s end (400), wherein the algorithm is executed by KAZ-SIGN digital signature scheme that sources from the Modular Reduction Problem and employs a hash function for generating a hash value from the electronic message and; transmitting the digital signature along with an identifier of the sender to the recipient (401);notifying, by the recipient, receipt of the digital signature and providing the identifier of the sender embedded in the digital signature to a CA (402);authenticating, by the certifying authority, the transaction thereof by verifying the identifier of the sender (403);determining, by the recipient, the digital signature transmitted by the sender is not a forged digital signature by first computing the value of h, which is a hash value that results from the computation of a hash function H that operates on the messagem received by the recipient originating from the sender through the relation h = H(m), then conducting the KAZ-SIGN digital signature forgery detection procedure type - 1, type - 2, type - 3, type - 4, and type - 5, using an algorithm residing in a cryptographic module of a cryptographic unit at the recipient’s end (404);verifying the digital signature by comparing computed values of y and y2using an algorithm residing in a cryptographic module of a cryptographic unit at the recipient’s end (405), wherein the algorithm utilizes a hash value from the electronic message m.
10. The method according to Claim 9,wherein the step of authenticating (403) includes comparing the identifier of the sender and validity information against that of stored in a database of the CA; andwherein the hash function includes the standard hash algorithm-2, SHA-2 hash function, or any other suitable hash function.