Operation end agent authorization method and device based on multi-party computing

A technology of multi-party computing and authorization devices, applied in secure communication devices, public keys for secure communications, user identity/authority verification, etc., can solve problems that affect the efficiency of the overall signature and reduce the flexibility of the overall signature

Active Publication Date: 2021-05-07
BEIJING CERTIFICATE AUTHORITY
View PDF4 Cites 0 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

However, in practice, it is found that the current electronic signature system needs to rely on the server, management and operation terminals for three-terminal encryption interaction at all times, which affects the efficiency of the overall signature to a certain extent and reduces the flexibility of the overall signature

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Operation end agent authorization method and device based on multi-party computing
  • Operation end agent authorization method and device based on multi-party computing
  • Operation end agent authorization method and device based on multi-party computing

Examples

Experimental program
Comparison scheme
Effect test

Embodiment 1

[0062] Please see figure 1 , figure 1 A schematic flowchart of a multi-party computing-based agent authorization method at the operation end is provided for the embodiment of the present application. Wherein, the multi-party computing-based operation agent authorization method includes:

[0063] S101. Perform multi-party calculation on a preset signature key according to a preset public key cryptographic algorithm to obtain a first key component and a second key component.

[0064] In this embodiment, the public key cryptographic algorithm may be SM2 elliptic curve public key cryptographic algorithm, RSA algorithm or any other elliptic curve algorithm.

[0065] In this embodiment, the first key component and the second key component can be calculated to obtain the above-mentioned signature key, and the operator key and the server key can also be calculated to obtain the above-mentioned signature key. But in practice, the first key component is stored on the management side,...

Embodiment 2

[0088] Please see figure 2 , figure 2 It is a schematic flowchart of a multi-party computing-based operation-end proxy authorization method provided by the embodiment of the present application. Such as figure 2 As shown, wherein, the multi-party computing-based operation-side proxy authorization method includes:

[0089] S201. Perform multi-party calculation on a preset signature key according to a preset public key cryptographic algorithm to obtain a first key component and a second key component.

[0090] In this embodiment, the public key cryptographic algorithm may be an SM2 elliptic curve public key cryptographic algorithm.

[0091] S202. Obtain the order of the base point of the curve included in the preset elliptic curve parameters.

[0092] In this embodiment, this step can follow the curve parameters defined in GB / T32918, and obtain the curve parameters including the curve base point G, order n (ie, the order of the curve base point) and multiple points define...

Embodiment approach

[0119] As an optional implementation, the method also includes:

[0120] When the signature request sent by the operator is received, the signature authorization information is sent to enable the operator to perform the signature operation; the signature request is generated according to the key of the operator.

[0121] As an optional implementation manner, the step of sending the second subcomponent to the operator includes:

[0122] sending the second sub-component to the operator through the second communication channel;

[0123] The steps of sending the first subcomponent to the server include:

[0124] Send the first subcomponent to the server through the first communication channel.

[0125] In this embodiment, the communication channel between the management end (that is, the execution subject) and the operation end may be different from the communication channel between the management end and the server end.

[0126] In this embodiment, prior to the above-mentioned...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

The embodiment of the invention provides an operation end agent authorization method and device based on multi-party computing, and relates to the technical field of encryption, and the method comprises the steps: carrying out the multi-party computing of a preset signature key according to a preset public key cryptographic algorithm, and obtaining a first key component and a second key component; performing multi-party calculation on the first key component to obtain a first sub-component and a second sub-component; sending the second sub-component to an operation end, so that the operation end generates an intermediate key component according to a preset operation end key and the second sub-component, and sending the intermediate key component to a server; and sending the first sub-component to a server, so that the server generates a server key according to the second key component, the first sub-component and the intermediate key component, wherein the operation end key is matched with the server end key. Therefore, by implementing the implementation mode, the authorization method of the key can be improved, so that the key authorization of the operation end agent can be more flexibly carried out on the premise of ensuring the security.

Description

technical field [0001] The present application relates to the technical field of password encryption, and in particular, relates to a method and device for operating agent authorization based on multi-party computing. Background technique [0002] At present, in business scenarios such as e-commerce and e-government, an electronic signature system can usually be used to perform electronic signatures required by the business to meet security and compliance requirements. However, in practice, it is found that the current electronic signature system needs to rely on the server, management and operation terminals for three-terminal encrypted interaction at all times, which affects the efficiency of the overall signature to a certain extent and reduces the flexibility of the overall signature. Contents of the invention [0003] The purpose of the embodiment of this application is to provide a multi-party computing-based operation terminal proxy authorization method and device, ...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
no application Login to View More
Patent Type & AuthorityApplications(China)
IPC IPC(8): H04L9/08H04L9/30H04L9/32H04L29/06
CPCH04L9/0838H04L9/0869H04L9/3066H04L9/3247H04L63/0884
Inventor李向锋夏冰冰傅大鹏张永强
OwnerBEIJING CERTIFICATE AUTHORITY