A quantum computing-resistant electronic contract signing method and system
Through a random number keystore based on key fob and a symmetric encryption algorithm, quantum computing public keys are generated, which solves the security threat of quantum computers to the existing electronic contract signing system, realizes the unbreakability and fairness of electronic contract signing, and ensures the security and fairness of contract signing.
Patent Information
- Application Number
- CN202011641207.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-12-31
- Publication Date
- 2025-08-22
- Estimated Expiration
- 2040-12-31
AI Technical Summary
When facing quantum computers, the security of an asymmetric public key encryption algorithm such as RSA is threatened and may be cracked by quantum computers in polynomial time, resulting in the security of electronic contracts being compromised.
A random number key store based on key fob is adopted to ensure the incrackability of asymmetric key encryption by generating quantum computing public keys and using symmetric encryption algorithms, and combined with fair exchange protocols, the security and fairness of electronic contract signing are achieved.
It realizes the unbreakability and fairness of electronic contract signing in a quantum computing environment, ensures fair exchange between the two parties during the contract signing process, eliminates the disadvantage of the signing party first, and ensures the safety and integrity of the contract.
Smart Images

Figure CN114692129B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of encryption communication of quantum cryptography networks, and specifically relates to a method and system for signing an electronic contract that is resistant to quantum computing. Background Art
[0002] The statements in this section merely provide background information related to the present invention and do not necessarily constitute prior art.
[0003] Electronic contracts, also known as e-commerce contracts, emerged with the development of computer technology and automated office automation. Essentially, they transmit information via electronic pulses, replacing the traditional practice of using paper as the primary credential with a set of electronic information. Generally speaking, an electronic contract can be defined as an agreement between two or more parties, reached electronically via an electronic information network, to establish, modify, or terminate property-related civil rights and obligations. Simply put, an electronic contract is a contract concluded electronically, primarily an agreement reached online by the parties.
[0004] The core technology of the current electronic contract signing system is PKI technology. The core of PKI technology is to use digital certificates for authentication, stamp the seal on the electronic document through digital signature, and embed the digital signature information of the document in the electronic document, thereby ensuring the authenticity, uniqueness, source confirmation and non-repudiation of the document.
[0005] Quantum computers have enormous potential in password cracking. Most of today's mainstream asymmetric public-key encryption algorithms, such as RSA, are based on two difficult mathematical problems: factoring large integers or computing discrete logarithms over finite fields. The difficulty of cracking these problems depends on the efficiency with which they are solved. On a conventional computer, solving these two mathematical problems takes exponential time, meaning the cracking time increases exponentially with the length of the public key, which is unacceptable in practical applications. Shor's algorithm, tailored for quantum computers, can perform integer factorization or discrete logarithm calculations in polynomial time (i.e., the cracking time increases with the length of the public key at a rate of k, where k is a constant independent of the length of the public key), thus making it possible to crack RSA and discrete logarithm encryption algorithms. Digital signatures based on public and private keys have inputs and outputs that can be known to others. In the presence of a quantum computer, the private key could be derived, allowing electronic signatures to be cracked by a quantum computer and compromising the security of electronic contracts. Summary of the Invention
[0006] In order to solve the above problems, the present invention proposes a quantum computing-resistant electronic contract signing method and system. The present invention realizes the unbreakable nature of asymmetric key encryption based on the random number key library of the key card and has quantum computing-resistant characteristics.
[0007] According to some embodiments, the present invention adopts the following technical solutions:
[0008] A quantum computing-resistant electronic contract signing method comprises the following steps:
[0009] The initiator of the electronic contract signing selects a random number pair, uses an encryption algorithm to calculate the relevant data of the random number pair to form a private key signature, and then sends the local private key signature and quantum computing-resistant public key to the recipient of the electronic contract signing;
[0010] The recipient of the electronic contract signature receives the private key signature and quantum computing-resistant public key of the initiator of the electronic contract signature, sends the received information to a third party to verify the correctness of the private key signature, and receives the verification result;
[0011] If the verification is incorrect, the electronic contract signing recipient terminates the agreement. Otherwise, the electronic contract signing recipient signs with the cost-side private key and sends it together with the quantum computing-resistant public key of the local side to the electronic contract signing initiator.
[0012] The initiator of the electronic contract signing receives the above information and sends it to a third party to verify the correctness of the private key signature of the electronic contract signing recipient. If the signature is incorrect, the signing of the electronic contract is cancelled. Otherwise, the random number pair in the signature is sent to the electronic contract signing recipient for verification. If the random number pair is correct, the agreement ends. Otherwise, the electronic contract signing recipient initiates a dispute resolution request to obtain the correct random number pair.
[0013] In the above process, the third party uses the quantum computing-resistant public key and random number key library of the electronic contract signing initiator or the electronic contract signing recipient to obtain the public key of the corresponding party, and uses the public key to verify the correctness of the corresponding private key signature.
[0014] As an optional implementation, the private key signature is calculated based on the electronic contract signing initiator, the electronic contract signing recipient and the third-party ID, as well as the hash value and random number pair of the electronic contract to be signed.
[0015] As an optional implementation method, the specific process of canceling the signing of an electronic contract includes: the initiator of the electronic contract signing sends the private key signature to a third party and requests cancellation, the third party sends a message to the recipient of the electronic contract signing indicating that the initiator of the electronic contract signing wants to cancel the private key signature, and requests the recipient of the electronic contract signing to feedback a random number pair to the third party, if the recipient of the electronic contract signing receives the random number pair sent by the initiator of the electronic contract signing, the recipient of the electronic contract signing sends the random number pair and its own private key signature to the third party, the third party verifies the random number pair and private key signature of the recipient of the electronic contract signing, and if correct, stores the private key signature to determine the cancellation of the signing of the electronic contract.
[0016] As a further step, the specific process of verifying the random number pair and private key signature includes: if the electronic contract signing recipient receives the random number pair sent by the electronic contract signing initiator, the electronic contract signing recipient sends the random number pair and the private key signature of the local end to a third party, and the third party verifies the correctness of the random number pair. If it is correct, the private key signature of the electronic contract signing recipient is sent to the electronic contract signing initiator. Otherwise, the third party sends a signature to cancel the signing and the third party's quantum computing-resistant public key to the electronic contract signing initiator and the electronic contract signing recipient. The electronic contract signing initiator and the electronic contract signing recipient verify and store the signature to cancel the signing.
[0017] As a further step, the cancellation signature is calculated based on the electronic contract signing initiator, the electronic contract signing recipient and the third-party ID, as well as the electronic contract and the random number pair.
[0018] As an optional implementation method, the specific process of the electronic contract signing recipient initiating a dispute resolution request to obtain the correct random number pair includes: the electronic contract signing recipient sends the private key signatures of both signatories to a third party and requests to cancel the agreement; the third party sends the private key signature of the electronic contract signing recipient to the electronic contract signing initiator and informs it that the electronic contract signing recipient wants to cancel the private key signature, the electronic contract signing initiator sends the random number pair to the third party to verify the correctness of the random number pair, if it is correct, the third party sends the random number pair to the electronic contract signing recipient, otherwise the third party sends the cancellation signature and the third party quantum computing resistant public key to the electronic contract signing initiator and the electronic contract signing recipient, the electronic contract signing initiator and the electronic contract signing recipient verify and store the cancellation signature.
[0019] As an optional implementation method, the initiator of the electronic contract signing and the recipient of the electronic contract signing both register for electronic contract signing with a third party in advance, and send a random number rd, personal information, ID and an undisclosed public key to the third party for identity authentication. After successful verification, the random number is used as a key pointer, and the data at the position pointed to by the key pointer is used as a new key pointer. The data pointed to by the new key pointer is extracted as an encryption key, and the encryption key is used to encrypt the public key of the electronic contract signatory to generate a new public key aqk. The combination of the random number rd and the encrypted public key aqk {rd, aqk} is used as the quantum computing-resistant public key of the electronic contract signatory and the recipient.
[0020] A quantum computing-resistant electronic contract signing system, comprising:
[0021] A first client device, providing services for an initiator of electronic contract signing, is configured to select a random number pair, calculate data related to the random number pair using an encryption algorithm to form a private key signature, send the local private key signature and the quantum-resistant public key, and receive a verification result from a server as well as the peer private key signature and the quantum-resistant public key;
[0022] The second client device provides services for the recipient of the electronic contract signing, is configured to receive the peer private key signature and quantum computing resistant public key, send the received information to the server to verify the correctness of the peer private key signature, receive the verification result, stop the electronic contract signing or generate the local private key signature according to the verification result, and send the local private key signature and quantum computing resistant public key;
[0023] The server interacts with the first client device and the second client device, and is configured to receive the corresponding private key signatures and quantum-resistant public keys sent by the first client device and the second client device, and use the quantum-resistant public key and random number key library of the first client device or the second client device to obtain the corresponding public key, and use the public key to verify the correctness of the corresponding private key signature.
[0024] As an optional implementation, the first client device, the second client device, and the server are all configured with a key card, and the key card is physically connected to the server or the client device.
[0025] Furthermore, the key cards configured for the first client device and the second client device store the public key and private key of the corresponding client device, as well as the public key encryption and decryption algorithm, and have a built-in random number generator.
[0026] Furthermore, the key card configured for the server stores the server public key and private key, a random number key library, a public key encryption and decryption algorithm and a symmetric key encryption algorithm, and has a built-in true random number generator.
[0027] Compared with the prior art, the present invention has the following beneficial effects:
[0028] The present invention eliminates the disadvantageous position of the party that signs the contract first based on the random number pair, thereby ensuring the fairness of the contract signing agreement; and the random number key library based on the key card realizes the unbreakability of asymmetric key encryption and has anti-quantum computing characteristics; during the entire signing process, the fair exchange protocol is strictly followed, thereby ensuring fairness for both parties during the contract signing process.
[0029] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, preferred embodiments are given below and described in detail with reference to the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0030] The accompanying drawings, which constitute a part of the present invention, are used to provide a further understanding of the present invention. The exemplary embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute improper limitations on the present invention.
[0031] Figure 1 It is the system structure diagram;
[0032] Figure 2 This is a schematic diagram of the electronic contract exchange process;
[0033] Figure 3 This is a schematic diagram of the process of canceling an electronic contract;
[0034] Figure 4 Schematic diagram of the dispute resolution process. DETAILED DESCRIPTION
[0035] The present invention will be further described below with reference to the accompanying drawings and embodiments.
[0036] It should be noted that the following detailed descriptions are illustrative and intended to provide further explanation of the present invention. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the art to which the present invention belongs.
[0037] It should be noted that the terms used herein are only for describing specific embodiments and are not intended to limit the exemplary embodiments according to the present invention. As used herein, unless the context clearly indicates otherwise, the singular form is intended to include the plural form. In addition, it should be understood that when the terms "comprise" and / or "include" are used in this specification, they indicate the presence of features, steps, operations, devices, components and / or combinations thereof.
[0038] As mentioned in the background, current electronic contracts are generally implemented based on PKI technology, which authenticates the signer's identity and uses RSA asymmetric keys for non-repudiation signatures. The RSA asymmetric key encryption algorithm is computationally secure. However, given the foreseeable research and development of quantum computers, cryptographic systems based on computational complexity are inherently unsafe. Therefore, current electronic contract signing methods based on asymmetric key technology present security risks.
[0039] This embodiment provides a quantum computing-resistant electronic contract signing method based on a random number key library.
[0040] The details are as follows:
[0041] Establish an electronic contract signing server to register electronic contract signatories, encrypt the public keys of electronic contract signatories to generate quantum computing-resistant public keys, verify the personal signatures of electronic contract signatories, and serve as a trusted third party in the electronic contract signing process.
[0042] The e-contract signing server issues key cards to the e-contract signing server and the e-contract signatory, respectively. Key cards are independent hardware-isolated devices similar to USB keys, SD keys, and host key boards, divided into multiple internal areas. The client key card stores the client's public and private keys, a true random number generator, and public key encryption and decryption algorithms; the server key card stores the server's public and private keys, a random number key library, a true random number generator, and public and symmetric key encryption algorithms.
[0043] The electronic contract signatory with a key card registers for electronic contract signing with the electronic contract signing server, uses the true random number generator in the key card to generate a random number rd, and sends personal information, key card ID, undisclosed public key and random number rd to the electronic contract signing server using a quantum encryption channel.
[0044] In this embodiment, the quantum encryption channel refers to a communication channel that can use quantum keys to encrypt and decrypt securely transmitted communication data, generally symmetric encryption such as AES.
[0045] The electronic contract signing server verifies the personal information of the electronic contract signatory. Upon successful verification, it uses the random number rd as a key pointer to the random number key library. The data at the location pointed by this key pointer is used as a new key pointer. This data is extracted as an encryption key, which is then used to encrypt the electronic contract signatory's public key to generate a new public key aqk. The combination of the random number rd and the encrypted public key aqk {rd, aqk} is used as the quantum-resistant public key. The electronic contract signing server uses a true random number generator to generate random numbers, which are used to generate and store a quantum-resistant public key for its own public key. Of course, because symmetric encryption is quantum-resistant, using symmetric encryption to encrypt the public key also makes the generated encrypted public key quantum-resistant.
[0046] Electronic contract signatory A and electronic contract signatory B agree on electronic contract C, and then sign the electronic contract through the electronic contract signing server. Assuming that electronic contract signatory A is the initiator of the signing of electronic contract C, the signing process includes the electronic contract exchange process, cancellation process and dispute resolution process.
[0047] Specifically, such as Figure 2 As shown, the electronic contract exchange process includes:
[0048] The electronic contract signatory A first selects a random number pair (M, R) and uses the encryption algorithm E TP Encrypt message M to get Z = E R TP(A, B, H(C), M) (A, B, TP, H(C) are the electronic contract signatories A, B, the electronic contract signing server ID, and the hash value of contract C respectively). Then A forms his own signature SIG A (A, B, TP, C, Z)(SIG A () represents A's private key signature), Z is the encrypted information mentioned above, and SIG A (A, B, TP, C, Z) and A’s quantum-resistant public key are sent to B;
[0049] Electronic contract signatory B receives A's signature SIG A (A, B, TP, C, Z), then SIG A (A, B, TP, C, Z) and A's quantum-resistant public key are sent to the electronic contract signing server to verify the correctness of the signature. The electronic contract signing server verifies the correctness of the signature by using A's quantum-resistant public key and the random number key library to obtain A's public key decryption signature, and sends the result and Z to B.
[0050] If it is incorrect, the electronic contract signatory B stops the agreement, otherwise B uses the private key to form his own signature SIG B (A, B, TP, C, Z) is sent to A along with B's quantum-resistant public key. After receiving it, A sends B's signature and quantum-resistant public key to the electronic contract signing server. The electronic contract signing server uses B's quantum-resistant public key and random number key library to obtain B's public key, uses the public key to verify the correctness of the signature, and sends the result to A, the electronic contract signatory.
[0051] If the verification result of the electronic contract signatory B's signature is incorrect, the cancellation process is executed, otherwise the random number pair (M, R) is sent to B; B uses the encryption algorithm E TP Encrypt A, B, and H(C) and compare the result with Z. If they are equal, (M, R) is the correct random number pair and the protocol ends. Otherwise, B can initiate a dispute resolution process to obtain the correct random number pair.
[0052] like Figure 3 As shown in the figure, the specific process of cancellation includes:
[0053] Electronic contract signatory A will SIG A (A, B, TP, C, Z) sends the electronic contract signing server and requests cancellation. The electronic contract signing server sends a message to the electronic contract signatory B: Electronic contract signatory A wants to cancel SIG A (A, B, TP, C, Z), and requires the electronic contract signatory B to send a random number pair (M, R) to it. If B receives the random number pair sent by A, the electronic contract signatory B will send the random number pair (M, R) and SIG B(A, B, TP, C, Z) is sent to the electronic contract signing server, which verifies the correctness of the random number pair (M, R). If it is correct, SIG B (A, B, TP, C, Z) sends a message to the electronic contract signatory A, otherwise the electronic contract signing server sends SIG to B and A. TP ("cancelled", A, B, TP, C, Z) and the server's quantum-resistant public key, electronic contract signatory A and electronic contract signatory B verify and store SIG TP ("cancelled", A, B, TP, C, Z).
[0054] like Figure 4 As shown, dispute resolution includes:
[0055] Electronic contract signatory B will SIG A (A, B, TP, C, Z) and SIG B (A, B, TP, C, Z) are sent to the electronic contract signing server and request to cancel the agreement; the electronic contract signing server sends SIG B (A, B, TP, C, Z) sent to A, and informed the electronic contract signatory A electronic contract signatory B to cancel SIG B (A, B, TP, C, Z), the electronic contract signatory A sends the random number pair (M, R) to the electronic contract signing server, the electronic contract signing server verifies the correctness of (M, R), and if it is correct, it sends (M, R) to the electronic contract signatory B, otherwise it sends SIG to the electronic contract signatory A and the electronic contract signatory B. TP ("cancelled", A, B, TP, C, Z) and the server's quantum-resistant public key, the electronic contract signatories A and B verify and store SIG TP ("cancelled", A, B, TP, C, Z).
[0056] A system that performs the above process, such as Figure 1 As shown, the entire system includes an electronic contract signing server and an electronic contract signatory (the executing agency is a client device).
[0057] The electronic contract signing server is used to register electronic contract signatories, encrypt the public keys of electronic contract signatories to generate quantum computing-resistant public keys, verify the personal signatures of electronic contract signatories, and serve as a trusted third party in the electronic contract signing process.
[0058] Both the electronic contract signing server and the electronic contract signatory are equipped with a key card, which is physically connected to the server or client machine during use. A key card is an independent hardware-isolated device similar to a USB key, SD key, or host key board, and is divided into multiple internal areas. The client key card stores the client's public and private keys, a true random number generator, and public key encryption and decryption algorithms; the server key card stores the server's public and private keys, a random number key library, a true random number generator, and public key encryption and decryption algorithms, as well as symmetric key encryption algorithms.
[0059] An electronic contract signatory with a key fob registers with the electronic contract signing server. The key fob uses a true random number generator (TRNG) to generate a random number rd. The server then sends the signatory's personal information, key fob ID, undisclosed public key, and random number rd to the server. The server verifies the signatory's personal information. Upon successful verification, the server uses the random number rd as a key pointer to the random number keystore. The data pointed to by the key pointer is used as a new key pointer. This data is then extracted as an encryption key. This encryption key is then used to encrypt the signatory's public key to generate a new public key aqk. The combination of random number rd and encrypted public key aqk, {rd, aqk}, is used as the signatory's quantum-resistant public key and sent to the signatory. The server uses the TRNG to generate random numbers, which it uses to generate and store a quantum-resistant public key for its own public key.
[0060] Of course, the electronic contract signing server can frequently or periodically replace the server-side quantum computing-resistant public key.
[0061] SIG A (A, B, TP, C, Z) and the random number pair (M, R) are the commitments of the electronic contract signatory A to the contract C. B (A, B, TP, C, Z) is the commitment of B, the signatory of the electronic contract, to contract C, where Z = E R TP (A, B, H(C), M). If electronic signatory A receives a commitment from electronic signatory B, then electronic signatory B is obliged to perform. Conversely, if electronic signatory B receives a commitment from electronic signatory A, then electronic signatory A is obliged to perform. Fairness in a contract signing agreement is reflected in the fact that either both parties receive a commitment from the other, or neither party receives a commitment from the other.
[0062] This embodiment eliminates the disadvantageous position of the party that signs the contract first based on the hidden information (M, R), and ensures the fairness of the contract signing agreement.
[0063] The random number key library based on the key card realizes the unbreakability of asymmetric key encryption and has anti-quantum computing characteristics. Because symmetric encryption has anti-quantum characteristics, the public key is encrypted using a symmetric key, so that the generated encrypted public key also has anti-quantum characteristics, and strictly follows the fair exchange protocol to ensure fairness for both parties during the contract signing process.
[0064] It will be understood by those skilled in the art that embodiments of the present invention may be provided as methods, systems, or computer program products. Thus, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0065] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowcharts and / or block diagrams, as well as combinations of processes and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowcharts and / or block diagrams. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0066] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0067] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 The steps for the function specified in one or more boxes.
[0068] The foregoing description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. Those skilled in the art will readily appreciate that various modifications and variations of the present invention are possible. Any modifications, equivalent substitutions, or improvements made within the spirit and principles of the present invention are intended to be within the scope of protection of the present invention.
[0069] Although the above describes the specific embodiments of the present invention in conjunction with the accompanying drawings, it is not intended to limit the scope of protection of the present invention. Those skilled in the art should understand that various modifications or variations that can be made by those skilled in the art on the basis of the technical solution of the present invention without any creative work are still within the scope of protection of the present invention.
Claims
1. A quantum computing-resistant electronic contract signing method, characterized by: The following steps are involved: The electronic contract signing server and electronic contract signatory are equipped with key cards, which are physically connected to the server or client machine when in use. The client key card stores the client's public and private keys, true random number generator, and public key encryption and decryption algorithms; the server key card stores the server's public and private keys, random number key library, true random number generator, public key encryption and decryption algorithms, and symmetric key encryption algorithms. The electronic contract signatory with the key card registers for electronic contract signing with the electronic contract signing server, uses the true random number generator in the key card to generate a random number rd, and sends the personal information, key card ID, undisclosed public key and random number rd to the electronic contract signing server; The electronic contract signing server verifies the personal information of the electronic contract signatory. Upon successful verification, it uses the random number rd as a key pointer to the random number key library. The data at the location pointed to by the key pointer is used as a new key pointer. The data pointed to by the new key pointer is extracted as an encryption key. The encryption key is used to encrypt the public key of the electronic contract signatory to generate a new public key aqk. The combination of the random number rd and the encrypted public key aqk {rd, aqk} is used as the quantum computing-resistant public key of the relevant electronic contract signatory, and the quantum computing-resistant public key is sent to the electronic contract signatory. The electronic contract signing server acts as a trusted third party in the electronic contract signing process. It uses a true random number generator to generate random numbers and use them to generate and store its own quantum computing-resistant public key. The initiator of the electronic contract signing selects a random number pair, encrypts the random number pair related data using an encryption algorithm to form a private key signature, and then sends the local private key signature and quantum computing-resistant public key to the recipient of the electronic contract signing; The recipient of the electronic contract signature receives the private key signature and quantum computing-resistant public key of the initiator of the electronic contract signature, sends the received information to a third party to verify the correctness of the private key signature, and receives the verification result; If the verification is incorrect, the electronic contract signing recipient terminates the agreement. Otherwise, the electronic contract signing recipient signs with the cost-side private key and sends it together with the quantum computing-resistant public key of the local side to the electronic contract signing initiator. The initiator of the electronic contract signing receives the above information and sends it to a third party to verify the correctness of the private key signature of the electronic contract signing recipient. If the signature is incorrect, the signing of the electronic contract is cancelled. Otherwise, the random number pair in the signature is sent to the electronic contract signing recipient for verification. If the random number pair is correct, the agreement ends. Otherwise, the electronic contract signing recipient initiates a dispute resolution request to obtain the correct random number pair. In the above process, the third party uses the quantum computing-resistant public key and random number key library of the electronic contract signing initiator or the electronic contract signing recipient to obtain the public key of the corresponding party, and uses the public key to verify the correctness of the corresponding private key signature.
2. The quantum computing-resistant electronic contract signing method according to claim 1, characterized in that: The private key signature is calculated based on the electronic contract signing initiator, the electronic contract signing recipient and the third-party ID, as well as the hash value and random number pair of the electronic contract to be signed.
3. The quantum computing-resistant electronic contract signing method according to claim 1, characterized in that: The specific process of canceling the signing of an electronic contract includes: the initiator of the electronic contract signing sends the private key signature to a third party and requests cancellation, the third party sends a message to the recipient of the electronic contract signing indicating that the initiator of the electronic contract signing wants to cancel the private key signature, and requests the recipient of the electronic contract signing to feedback a random number pair to the third party, if the recipient of the electronic contract signing receives the random number pair sent by the initiator of the electronic contract signing, the recipient of the electronic contract signing sends the random number pair and its own private key signature to the third party, the third party verifies the random number pair and private key signature of the recipient of the electronic contract signing, and if correct, stores the private key signature to confirm the cancellation of the signing of the electronic contract.
4. The quantum computing-resistant electronic contract signing method according to claim 3, characterized in that: The specific process of verifying the random number pair and private key signature includes: if the electronic contract signing recipient receives the random number pair sent by the electronic contract signing initiator, the electronic contract signing recipient sends the random number pair and the private key signature of the local end to a third party, and the third party verifies the correctness of the random number pair. If it is correct, the private key signature of the electronic contract signing recipient is sent to the electronic contract signing initiator. Otherwise, the third party sends a cancellation signature and the third party's quantum computing-resistant public key to the electronic contract signing initiator and the electronic contract signing recipient. The electronic contract signing initiator and the electronic contract signing recipient verify and store the cancellation signature.
5. The quantum computing-resistant electronic contract signing method according to claim 3, characterized in that: The cancellation signature is calculated based on the electronic contract signing initiator, the electronic contract signing recipient and the third-party ID, as well as the electronic contract and the random number pair.
6. The quantum computing-resistant electronic contract signing method according to claim 1, characterized in that: The specific process of the electronic contract signing recipient initiating a dispute resolution request to obtain the correct random number pair includes: the electronic contract signing recipient sends the private key signatures of both signatories to a third party and requests to cancel the agreement; the third party sends the private key signature of the electronic contract signing recipient to the electronic contract signing initiator and informs it that the electronic contract signing recipient wants to cancel the private key signature. The electronic contract signing initiator sends the random number pair to the third party to verify the correctness of the random number pair. If it is correct, the third party sends the random number pair to the electronic contract signing recipient. Otherwise, the third party sends the cancellation signature and the third party's quantum computing-resistant public key to the electronic contract signing initiator and the electronic contract signing recipient. The electronic contract signing initiator and the electronic contract signing recipient verify and store the cancellation signature.
7. The quantum computing-resistant electronic contract signing method according to claim 1, characterized in that: The initiator and recipient of the electronic contract signing both register for electronic contract signing with a third party in advance, and send a random number rd, personal information, ID and an undisclosed public key to the third party for identity authentication. After successful verification, the random number is used as a key pointer, and the data at the location pointed by the key pointer is used as a new key pointer. The data pointed to by the new key pointer is extracted as an encryption key, and the encryption key is used to encrypt the public key of the electronic contract signatory to generate a new public key aqk. The combination of the random number rd and the encrypted public key aqk {rd, aqk} is used as a quantum computing-resistant public key.
8. A quantum computing-resistant electronic contract signing system, characterized by: include: A first client device, providing services for an initiator of electronic contract signing, is configured to select a random number pair, calculate data related to the random number pair using an encryption algorithm to form a private key signature, send the local private key signature and the quantum-resistant public key, and receive a verification result from a server as well as the peer private key signature and the quantum-resistant public key; The second client device provides services for the recipient of the electronic contract signing, is configured to receive the private key signature and quantum-resistant public key of the peer end, send the received information to the server end to verify the correctness of the private key signature, receive the verification result, stop the electronic contract signing or generate the private key signature of the client end according to the verification result, and send the private key signature and quantum-resistant public key of the client end; The server exchanges information with the first client device and the second client device, and is configured to receive corresponding private key signatures and quantum-resistant public keys sent by the first client device and the second client device, obtain a corresponding public key using the quantum-resistant public key of the first client device or the second client device and a random number key library, and verify the correctness of the corresponding private key signature using the public key; The first client device, the second client device, and the server are all configured with a key card, and the key card is physically connected to the server or the client device; the key card configured for the first client device and the second client device stores the public key and private key of the corresponding client device, as well as a public key encryption and decryption algorithm, and has a built-in random number generator; or the key card configured for the server stores the server public key and private key, a random number key library, a public key encryption and decryption algorithm, and a symmetric key encryption algorithm, and has a built-in true random number generator; The electronic contract signatory with the key card registers for electronic contract signing with the electronic contract signing server, uses the true random number generator in the key card to generate a random number rd, and sends the personal information, key card ID, undisclosed public key and random number rd to the electronic contract signing server; The electronic contract signing server verifies the personal information of the electronic contract signatory. After successful verification, it uses the random number rd as a key pointer to the random number key library, and the data at the position pointed to by the key pointer is used as a new key pointer. The data pointed to by the new key pointer is extracted as an encryption key, and the encryption key is used to encrypt the public key of the electronic contract signatory to generate a new public key aqk. The combination of the random number rd and the encrypted public key aqk {rd, aqk} is used as the quantum computing-resistant public key of the relevant electronic contract signatory, and the quantum computing-resistant public key is sent to the electronic contract signatory; the electronic contract signing server acts as a trusted third party in the electronic contract signing process, and uses a true random number generator to generate a random number and use it to generate and store the quantum computing-resistant public key of its own public key.
Citation Information
Patent Citations
Signing method and signing system resistant to quantum computation based on public key pool
CN109600228A
Anti-quantum computation digital signing methods and anti-quantum computation digital signing systems based on a plurality of key pools
CN109687977A