An Electronic Contract Signing Method and System Against Quantum Attacks
By using quantum cryptographic network and symmetric key algorithms in electronic contract signing, the security risks existing in the PKI-based electronic contract signing method in the prior art are solved, and the security of resisting quantum attacks and unconditional electronic contract signing security are achieved.
Patent Information
- Application Number
- CN202011639032.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-12-31
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2040-12-31
AI Technical Summary
The existing electronic contract signing method based on PKI technology has security risks. Faced with the foreseeable research and construction of quantum computers, there are security concerns for cryptographic systems based on computing complexity.
The quantum cryptographic network is used to distribute shared keys to the signatories through a trusted center, and the symmetric key algorithm is used for signatures. The secure distribution and use of keys is ensured through the quantum confidential channel, and signature hiding and verification are performed during the signature process.
Fundamentally eliminating the security of the traditional electronic contract signing method based on PKI, providing security against quantum attacks, and ensuring unconditional security of electronic contract signing by annotating the used keys.
Smart Images

Figure CN114692128B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of encrypted communication of quantum cryptographic networks, and specifically relates to a method and system for signing electronic contracts against quantum attacks. Background Art
[0002] The statements in this section merely provide background art related to the present disclosure and do not necessarily constitute prior art.
[0003] An electronic contract, also known as an e-commerce contract, emerged with the development of computer technology and automated office technology. Its essence is to transmit information through electronic pulses, which changes the traditional practice of using paper as the original evidence. Its evidence is a set of electronic information. Generally, an electronic contract can be defined as: an electronic contract is an agreement reached between two or more parties through an electronic information network in electronic form to establish, change, or terminate a property-based civil rights and obligations relationship. In short, an electronic contract is a contract concluded in an electronic manner, mainly referring to an agreement reached by the parties to the contract under network conditions.
[0004] The core technology of current electronic contract signing systems is PKI technology. The core of PKI technology is to use digital certificates for authentication. A seal is stamped on an electronic document through an electronic signature, and the digital signature information of the document is embedded in the electronic document to ensure the authenticity, uniqueness, source confirmation, and non-repudiation of the document.
[0005] The prior art expounds that PKI ensures the authenticity of the identities of all parties to the contract through digital certificates, provides a reliable proof of the contract receiving and sending time through a digital time stamp service, uses digital signatures to ensure the confidential integrity of the contract content, and effectively stores and retrieves relevant electronic evidence of contract implementation, thereby realizing the arbitrability and non-repudiation of PKI-based electronic contracts.
[0006] Current electronic contracts are basically implemented based on PKI technology. The identity authentication of signers is realized based on PKI technology, and the RSA asymmetric key is used to achieve non-repudiation signatures of data. As is well known, the RSA asymmetric key encryption algorithm is computationally secure. Facing the research and construction of foreseeable quantum computers, there are security concerns in the cryptographic system based on computational complexity. Therefore, the current method for signing electronic contracts based on asymmetric key technology has security risks. Summary of the Invention
[0007] To address the deficiencies of the prior art, the present disclosure provides a method and system for signing electronic contracts against quantum attacks, fundamentally eliminating the defect that the security of the traditional PKI-based method for signing electronic contracts is based on computational security.
[0008] According to some embodiments, the present disclosure adopts the following technical solutions:
[0009] The first object of the present disclosure is to provide an electronic contract signing method resistant to quantum attacks.
[0010] An electronic contract signing method resistant to quantum attacks includes the following steps:
[0011] The trusted center distributes a shared key to each signatory through a quantum cryptographic network;
[0012] The trusted center generates first signature information and signature hiding information according to a request generated by the first signatory using the shared key, and sends them to the first signatory;
[0013] The first signatory sends the signature hiding information to the second signatory. After the second signatory verifies that the signature hiding information is correct with the trusted center, the second signatory requests second signature information from the trusted center using the shared key, and the trusted center sends the generated second signature information to the second signatory;
[0014] The first signatory receives the second signature information sent by the second signatory. After verifying that the second signature information is correct with the trusted center, the first signatory sends the first signature information to the second signatory;
[0015] After the second signatory verifies that the received first signature information is correct with the trusted center, the electronic contract signing is completed.
[0016] As an optional implementation, if the trusted center verifies that the first signature information is incorrect or the second signatory does not receive the first signature information, the second signatory encrypts and sends the electronic contract, the second signature information, and the signature hiding information to the trusted center;
[0017] The trusted center verifies the correctness of the received data, decrypts the signature hiding information to obtain the first signature information of the first signatory, sends the first signature information to the second signatory, and sends the second signature information to the first signatory;
[0018] After the second signatory receives the first signature information and the first signatory receives the second signature information, they respectively verify the correctness of the received signature information with the trusted center. If both are correct, they each save the received signature information, and the electronic contract signing is completed.
[0019] As an optional implementation, the first signatory encrypts the electronic contract using the first shared key to obtain an electronic contract ciphertext, calculates a message authentication code related to the key using the second shared key, and sends the identity identification code of the trusted center, the number of the first shared key, the number of the second shared password, the identity identification code of the first signatory, the electronic contract ciphertext, and the encrypted message authentication code to the trusted center.
[0020] As an alternative implementation, the second signatory encrypts the electronic contract using the third shared key to obtain the ciphertext of the electronic contract, calculates the message authentication code related to the key using the fourth shared key, and sends the identity identification code of the trusted center, the number of the third shared key, the number of the fourth shared password, the identity identification code of the second signatory, the ciphertext of the electronic contract, and the encrypted message authentication code to the trusted center.
[0021] As a further limitation, the first signature information is encrypted using the first key to obtain the signature hidden information of the first signature information.
[0022] As a further limitation, the second signatory verifies with the trusted center whether the signature ciphertext in the received signature hidden information is the encrypted ciphertext of the first key for the first signature information. After successful verification, the second signatory requests the second signature information from the trusted center.
[0023] As an alternative implementation, each shared key is marked as used after being used.
[0024] As an alternative implementation, the trusted center saves the identity registration information and shared keys of each signatory in a database. Each signatory securely stores the shared key and, together with the shared key in the trusted center's database, divides the shared key according to the length of each use of the shared key and synchronizes the sequential numbering.
[0025] The second objective of the present disclosure is to provide an electronic contract signing system resistant to quantum attacks.
[0026] An electronic contract signing system based on resistance to quantum attacks includes:
[0027] An electronic contract signing server, configured to act as a trusted third party in the electronic contract signing process, distribute shared keys to the signatories of each client through a quantum cryptographic network, perform symmetric key signing on the electronic contract, encrypt the signature information to obtain signature hidden information, divide the keys in the true random number digital signature key library according to the length used for each digital signature, and perform sequential numbering, and verify the electronic contract signature;
[0028] A number of clients, configured to respectively provide information services during the contract signing process for each signatory and communicate with the electronic contract signing server using the shared key.
[0029] As an alternative implementation, the electronic contract signing server distributes the shared key to the authenticated signatories of each client, saves the identity registration information and shared key of the signatory. The client saves the shared key and, together with the shared key in the electronic contract signing server's database, divides the shared key according to the length of each use of the shared key and synchronizes the sequential numbering.
[0030] As an alternative embodiment, each time information is communicated between each client and the electronic contract signing server, keys with different numbers are used in sequence.
[0031] As an alternative embodiment, each client and the electronic contract signing server obtain a shared key through quantum key distribution. When the number of shared keys is lower than a set value, the signatories of each client use unused shared keys to authenticate each other's identities with the contract signing server;
[0032] After successful identity authentication, the contract signing server distributes quantum keys to the signatories of each client through the quantum secure channel of the quantum cryptographic network. The contract signing server and each client encrypt the newly distributed quantum keys with unused keys, use the ciphertext as the new shared key, and divide and sequentially number the new shared key.
[0033] Compared with the prior art, the beneficial effects of the present disclosure are:
[0034] The present disclosure proposes an electronic contract signing method resistant to quantum attacks, which utilizes the characteristics of small mathematical operation amount, fast encryption speed, and easy processing of the symmetric cryptosystem. At the same time, the symmetric key algorithm has the characteristic of resisting quantum attacks, fundamentally eliminating the defect that the security of the traditional electronic contract signing method based on PKI is based on computational security.
[0035] The present disclosure marks the used keys to prevent repeated use, is implemented based on the quantum cryptographic network, adopts the one-time pad encryption method, and has unconditional security.
[0036] The electronic contract signing method provided by the present disclosure strictly follows the fair exchange protocol, ensuring the fairness of electronic contract signing.
[0037] Advantages of additional aspects of the present disclosure will be given in part in the following description, will become apparent in part from the following description, or will be understood through the practice of the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS
[0038] The specification drawings constituting a part of the present disclosure are used to provide a further understanding of the present disclosure. The schematic embodiments and descriptions thereof of the present disclosure are used to explain the present disclosure and do not constitute an improper limitation of the present disclosure.
[0039] Figure 1 It is a relationship diagram between the signatory and the trusted center in the first embodiment;
[0040] Figure 2 It is a flowchart of the electronic contract signing method in the first embodiment;
[0041] Figure 3 It is a system structure diagram of the second embodiment. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0042] The present disclosure will be further described below in conjunction with the accompanying drawings and embodiments.
[0043] It should be noted that the following detailed description is exemplary and is intended to provide further illustration of the present disclosure. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which the present disclosure belongs.
[0044] It should be noted that the terms used herein are only for describing specific embodiments and are not intended to limit the exemplary embodiments according to the present disclosure. As used herein, unless the context clearly indicates otherwise, the singular form is also intended to include the plural form. In addition, it should be understood that when the terms "comprising" and / or "including" are used in this specification, they indicate the presence of features, steps, operations, devices, components, and / or combinations thereof.
[0045] In the case of no conflict, the embodiments in the present disclosure and the features in the embodiments may be combined with each other.
[0046] Embodiment 1:
[0047] A symmetric key algorithm is a cryptographic algorithm that uses the same secret key for both encryption and decryption. The characteristics of this cryptographic system are small mathematical operation amount, fast encryption speed, and easy processing, but the distribution of symmetric keys is relatively difficult. The emergence of quantum cryptographic networks solves the problem of symmetric key distribution. Through quantum cryptographic networks, both parties to encryption can conveniently obtain shared symmetric keys by means of quantum key distribution.
[0048] This embodiment relies on the rich symmetric key resources of quantum cryptographic networks to implement an electronic contract signing method resistant to quantum attacks. Attached Figure 1 is a relationship diagram between the signatory and the trusted center, and the functions of each component are described in detail as follows:
[0049] The trusted center is a third-party trusted institution for digital signature of electronic contracts, identity registration of electronic contract signers, identity authentication of signers during electronic contract signing, and as a trusted third party to resolve disputes in electronic contract signing. A true random number digital signature key library is established in the trusted center for digital signature of electronic contract data. The keys in the key library are divided according to the length used for each digital signature, and the divided keys are sequentially numbered.
[0050] Electronic contract signers, the two parties for electronic contract signing through a trusted center. Before signing an electronic contract, the signers of the electronic contract submit an identity registration application to the trusted center through a quantum cryptographic network terminal using a quantum secure channel. The quantum secure channel has a shared quantum key, and the confidentiality submission of identity registration information is achieved through encryption and decryption with the shared key. After the trusted center accepts the identity registration application of the signer, it reviews the materials submitted by the signer respectively. After passing the review, the trusted center distributes the shared key to the signer through the quantum secure channel of the quantum cryptographic network. The trusted center saves the identity registration information and the shared key of the signer in the database. The signer securely saves the shared key and, together with the shared key in the trusted center database, divides the shared key according to the length of the shared key used each time and synchronizes the sequential numbers.
[0051] This embodiment is a method for signing an electronic contract between two parties. Assume that the two parties participating in the signing of the electronic contract are A and B (A and B respectively represent the identity identification codes of the contract signers, and A and B have completed identity registration at the trusted center in advance), and the contract to be signed by A and B is C (the content of C has been agreed upon by A and B in advance). Attached Figure 2 For the implementation process of electronic contract signing in this embodiment (A is the initiator of contract signing), it is described in detail as follows:
[0052] S1: The initiator A of electronic contract signing sends a request for electronic contract signature information and signature hidden information to the trusted center.
[0053] A encrypts the contract C using the unused shared key K1 with the trusted center to obtain the ciphertext E K1 (C), and calculates the key-related message authentication code HMAC(A||TP||E K1 (C)||N1||N2; K2) (TP is the identity identification code of the trusted center, N1 and N2 respectively represent the serial numbers of the keys K1 and K2, and || represents the data concatenation operation). A sends a request for electronic contract signature information and a request for signature hidden information to the trusted center, and sends A, TP, N1, N2, E K1 (C) and HMAC(A||TP||E K1 (C)||N1||N2; K2) to the trusted center, and marks the keys K1 and K2 as used.
[0054] S2: The trusted center verifies the identity of A, generates the signature information of A for the electronic contract C, encrypts the signature information to generate signature hidden information, and encrypts and sends the signature information and the signature hidden information to A.
[0055] The trusted center receives the signature request, the request for signature hidden information and the data A, TP, N1, N2, E K1(C) and HMAC(A||TP||E K1 (C)||N1||N2; K2), then read from the database the shared key K2 of N2 and A. If K2 has been used, reject A's request; otherwise, verify HMAC(A||B||TP||E K1 (C)||N1||N2; K2). If it is correct, A's identity authentication passes. The trusted center reads from the database the shared key K1 of N1 to decrypt E K1 (C) to obtain contract C, and mark the keys K1 and K2 as used; the trusted center reads from the digital signature key library the unused key SK1 of serial number SN1 to perform a symmetric key signature on contract C, obtaining the data as HMAC(C||A||TP||TS||SN1; SK1), where TS is the timestamp at the time of signature, SN1 is the serial number of the signature key SK1, mark the key SK1 as used, and set DS A =A||TP||TS||SN1||HMAC(A||TP||TS|SN1|C||; SK1) as the signature information of A for the electronic contract C, and encrypt DS with SK1 A to obtain the ciphertext E(DS A ), and use SN1||E(DS A ) as the hidden information of A's signature. The trusted center encrypts DS A ||SN1||E(DS A ) with the shared key with A, and calculates the message authentication code of the ciphertext, and sends DS A ||SN1||E(DS A ) ciphertext and its message authentication code to A.
[0056] S3: A receives the signature information sent by the trusted center, and sends the signature hidden information of A for the electronic contract C to B, and B verifies the correctness of the signature hidden information.
[0057] After A receives DS A ||SN1||E(DS A ) ciphertext and its message authentication code, verify the legality of the data DS A ||SN1||E(DS A ) through the message authentication code. If the verification is successful, decrypt the DS A ||SN1||E(DS A ) ciphertext with the shared key with the trusted center to obtain the data DS A and SN1||E(DS A ), save DS A , and send SN1||E(DS A ) to B. After B receives the data, go to the trusted center to verify SN1||E(DSA ) for correctness (verify whether E(DS A ) is the ciphertext obtained by encrypting the signature information of A in the contract C with the key pair of the trusted center digital signature key library with serial number SN1). If the verification result is incorrect, terminate the electronic contract signing process; otherwise, proceed to the next step.
[0058] S4: B applies to the trusted center for the digital signature of the electronic contract C and sends B's digital signature information to A.
[0059] B encrypts the contract C using the unused shared key K3 with the trusted center to obtain the ciphertext E K3 (C), and calculates the key-related message authentication code HMAC(B||TP||E K1 (C)||N3||N4; K4) (TP is the identification code of the trusted center, N3 and N4 respectively represent the serial numbers of the keys K3 and K4, and || represents the data concatenation operation). B sends an electronic contract signature request to the trusted center and sends B, TP, N3, N4, E K3 (C) and HMAC(B||TP||E K3 (C)||N3||N4; K4) to the trusted center, and marks the keys K3 and K4 as used.
[0060] The trusted center receives the signature request and the data B, TP, N3, N4, E K3 (C) and HMAC(A||TP||E K3 (C)||N3||N4; K4) sent by B. Then, it reads the shared key K4 with B with serial number N4 from the database. If K4 has been used, it rejects the signature request and data sent by B; otherwise, it verifies the correctness of HMAC(B||TP||E K3 (C)||N3||N4; K4). If it is correct, B's identity authentication passes. The trusted center reads the shared key K3 with B with serial number N3 from the database, decrypts E K3 (C) to obtain the contract C, and marks the keys K3 and K4 as used; the trusted center reads the unused key SK2 with serial number SN2 from the signature key library to perform a symmetric key signature on the contract C, and obtains the signature data as HMAC(C||B||TP||TS||SN2; SK2), where TS is the timestamp at the time of signature, SN2 is the serial number of the signature key SK2, marks the key SK2 as used, and sets DS B = B||TP||TS||SN2||HMAC(C||B||TP||TS||SN2; SK2) as B's signature information for the electronic contract C; the trusted center encrypts DS B , and calculates DS using the shared key with BB The message authentication code of the ciphertext, send DS B The ciphertext and its message authentication code to B.
[0061] B receives DS sent by the trusted center B The ciphertext and its message authentication code, use the shared key to verify the correctness of the message authentication code. If the verification is successful, use the shared key to decrypt to obtain DS B , B sends DS B to A.
[0062] S5: After A receives the signature information of B for the electronic contract C sent by B, go to the trusted center to verify the correctness of B's signature information. If it is incorrect, the signing of the electronic contract fails. If it is correct, A sends the signature information of the electronic contract C to B.
[0063] A receives the signature information DS of B for the contract C sent by B B After that, go to the trusted center to verify the correctness of DS B . If it is incorrect, the signing of the electronic contract fails. If it is correct, A sends the signature information DS of the contract C A to B.
[0064] S6: If B receives the signature information of A for the electronic contract C sent by A, B goes to the trusted center to verify the correctness of A's signature information. If it is correct, B saves the signature information and the signing of the electronic contract C is successful, and the signing process ends. If the trusted center verifies that A's signature information is incorrect or B does not receive the signature information of A for the electronic contract C, then B uses the shared key with the trusted center to encrypt the electronic contract C, B's signature information, and A's signature hidden information and send them to the trusted center.
[0065] If B receives the signature information DS of A for the contract C A , B goes to the trusted center to verify the correctness of DS A . If it is correct, B saves DS A , and the signing of the contract C is successful, and the signing process ends. If the trusted center verifies that DS A is incorrect or B does not receive the signature information of A for the contract C, then B uses the shared key with the trusted center to encrypt C, DS B and SN1||E(DS A ) and send them to the trusted center.
[0066] S7: The trusted center verifies the correctness of the received data, decrypts A's signature hidden information to obtain A's signature information, sends A's signature information to B, and sends B's signature information to A.
[0067] The trusted center receives C, DS B and SN1||E(DSA ) After the ciphertext of B and SN1||E(DS A ) is obtained, verify DS B and SN1||E(DS A ) for correctness. Decrypt E(DS A ) using the key with serial number SN1 in the signature keystore to obtain the signature information of A for contract C. Encrypt DS A ) and send it to B, and at the same time encrypt DS A ) and send it to A. B
[0068] S8: After B receives A's signature information, go to the trusted center to verify the correctness of A's signature information. If it is correct, save the signature information; after A receives B's signature information, go to the trusted center to verify the correctness of B's signature information. If it is correct, save the signature information. The signing of the electronic contract C is completed.
[0069] The trusted center and the signer of the electronic contract obtain a shared key through quantum key distribution. When the shared key between them is about to be used up, the signer of the electronic contract uses the unused shared key to authenticate the identity of each other with the trusted center. After the identity authentication is successful, the trusted center distributes quantum keys to the signer of the electronic contract through the quantum secure channel of the quantum cryptography network. The trusted center and the signer of the electronic contract encrypt the newly distributed quantum keys with the unused keys, use the ciphertext as the new shared key, and partition and sequentially number the new shared key.
[0070] The fair exchange protocol is the basic security protocol that needs to be followed in the process of signing an electronic contract, mainly used to ensure the security and fairness of information exchange and related situations in the network environment. The fair exchange protocol enables the two parties participating in the exchange to exchange information in a fair manner. In this way, either any party can obtain the information of the other party, or neither party can obtain the information of the other party. It can also be said that if the transaction can proceed normally, the protocol ensures that both parties can obtain the information they need; if the protocol is abnormally terminated, the protocol should ensure that both communication parties are in an equal position and neither party has any advantage.
[0071] Generally speaking, the initiator of the contract signing (the party that sends the signature information first) will be in an unfavorable position during the contract signing process. In case the other party receives the signature and does not return its own signature information, it will be disadvantageous to the contract signing initiator. To solve this problem, this patent introduces the hidden information of the initiator's signature. The initiator (offeror) of the contract signing first sends the signature hidden information to the other party (offeree). Only after receiving the correct signature information of the offeree will the offeror send its own signature information to the offeree. If the offeror does not send its own signature information to the offeree after receiving the offeree's signature information, the offeree can use the signature hidden information to obtain the offeror's signature message through a trusted third party (trusted center). To prevent the offeree from directly using the signature hidden message to obtain the offeror's signature through the trusted center, the trusted center must receive the offeree's signature information before obtaining the offeror's signature information through the signature hidden message, send the offeror's signature to the offeree, and at the same time send the offeree's signature information to the offeror. The electronic contract signing process of this embodiment strictly follows the fair exchange protocol. During the signing process, the status of both signing parties is always fair.
[0072] Embodiment 2:
[0073] In this embodiment, an electronic contract signing system against quantum attacks is provided, including:
[0074] An electronic contract signing server, configured to act as a trusted third party during the electronic contract signing process, distribute shared keys to the signers of each client through a quantum cryptography network, perform symmetric key signing on the electronic contract, encrypt the digital signature to obtain signature hidden information, divide the keys of the true random number digital signature key library according to the length used for each digital signature, and perform sequential numbering, and perform verification of the electronic contract signature;
[0075] A number of clients, configured to respectively provide information services to each signer during the contract signing process, and communicate with the electronic contract signing server using the shared key.
[0076] The electronic contract signing server distributes the shared key to the authenticated signers of each client, saves the identity registration information and the shared key of the signer. The client saves the shared key, and divides the shared key according to the length of each use of the shared key together with the shared key in the database of the electronic contract signing server and synchronizes the sequential numbering.
[0077] Each time the client communicates with the electronic contract signing server, different numbered keys are used in sequence;
[0078] Each client and the electronic contract signing server obtain a shared key through quantum key distribution. When the number of shared keys is lower than the set value, the signers of each client use the unused shared keys to authenticate their identities with the contract signing server;
[0079] After successful identity authentication, the contract signing server distributes quantum keys to the signers of each client through the quantum secure channel of the quantum cryptography network. The contract signing server and each client use the unused keys to encrypt the newly distributed quantum keys, take the ciphertext as the new shared key, and divide and sequentially number the new shared key.
[0080] The working method of the above system is the same as the quantum-resistant electronic contract signing method provided in Embodiment 1, and will not be elaborated here.
[0081] Those skilled in the art should understand that the embodiments of the present disclosure can be provided as a method, a system, or a computer program product. Therefore, the present disclosure can take the form of a hardware embodiment, a software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present disclosure can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage and optical storage, etc.) containing computer-usable program code.
[0082] The present disclosure is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present disclosure. It should be understood that each process and / or block in the flowchart and / or block diagram, and the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for implementing the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.
[0083] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device, and the instruction device implements the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.
[0084] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus, so that a series of operation steps are performed on the computer or other programmable apparatus to generate a computer-implemented process, thereby providing instructions for implementing the functions specified in one process or multiple processes and / or blocks Figure 1 one process or multiple processes and / or blocks Figure 1 steps for implementing the functions specified in one block or multiple blocks.
[0085] Those of ordinary skill in the art can understand that all or part of the processes of the methods in the above embodiments can be completed by instructing relevant hardware through a computer program. The program can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above methods. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only memory (ROM), a random access memory (RAM), etc.
[0086] The foregoing is only a preferred embodiment of the present disclosure and is not intended to limit the present disclosure. For those skilled in the art, the present disclosure may have various modifications and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present disclosure shall be included within the protection scope of the present disclosure.
Claims
1. An electronic contract signing method against quantum attacks, characterized in that: It includes the following steps: The trusted center distributes quantum keys as shared keys to each signatory through a quantum cryptography network, saves the identity registration information and shared keys of each signatory in a database, each signatory securely saves the shared key, and divides the shared key according to the length of the shared key used each time and synchronously numbers them together with the shared key in the trusted center database; The trusted center generates first signature information and signature hiding information according to a request generated by the first signatory using the shared key, and sends them to the first signatory; The first signatory sends the signature hiding information to the second signatory. After the second signatory verifies that the signature hiding information is correct with the trusted center, it requests second signature information from the trusted center using the shared key, and the trusted center sends the generated second signature information to the second signatory; The first signatory receives the second signature information sent by the second signatory. After verifying that the second signature information is correct with the trusted center, the first signatory sends the first signature information to the second signatory; After the second signatory verifies that the received first signature information is correct with the trusted center, the electronic contract signing is completed; Among them, each shared key is marked with a used status after being used.
2. The method for signing an electronic contract against quantum attacks according to claim 1, wherein: If the trusted center verifies that the first signature information is incorrect or the second signatory does not receive the first signature information, the second signatory encrypts and sends the electronic contract, the second signature information and the signature hiding information to the trusted center; The trusted center verifies the correctness of the received data, decrypts the signature hiding information, obtains the first signature information of the first signatory, sends the first signature information to the second signatory, and sends the second signature information to the first signatory; The second signatory receives the first signature information, and the first signatory receives the second signature information. They respectively verify the correctness of the received signature information with the trusted center. If both are correct, they each save the received signature information, and the electronic contract signing is completed.
3. The method for signing an electronic contract against quantum attacks according to claim 1, wherein: The first signatory encrypts the electronic contract with the first shared key to obtain an electronic contract ciphertext, calculates a key-related message authentication code with the second shared key, and sends the identity identification code of the trusted center, the number of the first shared key, the number of the second shared password, the identity identification code of the first signatory, the electronic contract ciphertext, and the encrypted message authentication code to the trusted center; Or, the second signatory encrypts the electronic contract with the third shared key to obtain an electronic contract ciphertext, calculates a key-related message authentication code with the fourth shared key, and sends the identity identification code of the trusted center, the number of the third shared key, the number of the fourth shared password, the identity identification code of the second signatory, the electronic contract ciphertext, and the encrypted message authentication code to the trusted center.
4. The method for signing an electronic contract against quantum attacks according to claim 3, wherein: The first signature information is encrypted with the first key to obtain the signature hiding information of the first signature information.
5. The method for signing an electronic contract against quantum attacks according to claim 3, wherein: The second signing direction trust center verifies whether the signature ciphertext in the received signature hidden information is the encrypted ciphertext of the first key pair for the first signature information. After successful verification, it requests the second signature information from the trust center.
6. An electronic contract signing system based on quantum attack resistance, characterized in that: Including: An electronic contract signing server, configured to act as a trusted third party in the electronic contract signing process, distribute quantum keys as shared keys to the signers of each client through a quantum cryptography network, save the identity registration information and shared keys of the signers, perform symmetric key signing on the electronic contract, encrypt the signature information to obtain signature hidden information, divide the keys in the true random number digital signature key library according to the length used for each digital signature, and perform sequential numbering, and verify the electronic contract signature; A number of clients, configured to save the shared keys, divide the shared keys according to the length of the shared keys used each time together with the shared keys in the database of the electronic contract signing server and synchronize the sequential numbering, respectively provide information services for each signer during the contract signing process, and use the shared keys to communicate with the electronic contract signing server; Among them, each shared key is marked with a used status after use.
7. The quantum-resistant electronic contract signing system according to claim 6, characterized in that: Each time the clients communicate with the electronic contract signing server, they use keys with different numbers in sequence; Or, the clients and the electronic contract signing server obtain the shared keys through quantum key distribution. When the number of shared keys is lower than the set value, the signers of each client use the unused shared keys to authenticate each other's identities with the contract signing server; After successful identity authentication, the contract signing server distributes quantum keys to the signers of each client through the quantum secure channel of the quantum cryptography network. The contract signing server and each client encrypt the newly distributed quantum keys with the unused keys, use the ciphertext as the new shared key, and divide and sequentially number the new shared key.
Citation Information
Patent Citations
Method, apparatus and system for digital signature
CN109104271A
Electronic contract signing method and device, computer equipment and storage medium
CN109756485A