Signature method, method for verifying signature, mobile terminal, and server

Through the combination of Z cryptography algorithm and asymmetric key algorithm, session key and signature factors are generated, which solves the security problem of client private keys, and realizes the security protection of mobile terminal signatures to prevent forgery of signatures.

CN114827996BActive Publication Date: 2025-07-08MASSIVE SECURITY TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202210237537.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-03-11
Publication Date
2025-07-08
Estimated Expiration
2042-03-11

AI Technical Summary

Technical Problem

In the scenarios of mobile Internet and Internet of Things, the security of the private key generated by the client is difficult to guarantee. Attackers can forge their signatures, and the existing technology cannot effectively protect the private key.

Method used

The Z cryptographic algorithm is used to combine the asymmetric key algorithm to generate the session key and signature factor. Through two-way authentication and session key negotiation mechanism, the private key is decomposed into multi-factor signatures to enhance security.

Benefits of technology

Even if the data is eavesdropped, the attacker cannot forge the signature, and the signature hijacking party alone cannot forge the signature, which improves the security of the private key and the protection of the identity key.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114827996B_ABST
    Figure CN114827996B_ABST
Patent Text Reader

Abstract

The present invention provides a signature method, a method for verifying a signature, a mobile terminal, and a server. The signature method applied to a signing party includes: obtaining a Z algorithm instance for the signing party, combining preset real-time parameters, and using a preset parameter algorithm to generate a session key; generating a first signature parameter according to the data to be signed and a specified hash value by using a first preset algorithm, and sending the first signature parameter to the signature verification party so that the signature verification party generates a second signature parameter and a first signature factor based on the first signature parameter in combination with a preset asymmetric key algorithm; generating a second signature factor by using a second preset algorithm based on the session key, the second signature parameter, and the first signature factor sent by the signature verification party, taking the first signature factor and the second signature factor as the signature result of the data to be signed, and sending the signature result to the signature verification party so that the signature verification party verifies the signature result. It is beneficial to improve the security of the private key.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of communication technologies, and in particular, to a signature method, a method for verifying a signature, a mobile terminal, and a server. Background Art

[0002] The digital signature technology based on the public key infrastructure (PKI) has been widely applied in the fields of finance and e-commerce. The traditional signature process is usually that the signer generates a public-private key pair under the guarantee of a trusted medium, signs the message with the private key, and sends the message, the public key, and the signature result to the signature verifier. The signature verifier uses the public key to verify the signature. In the traditional application scenario, usually the server is the signer and the client is the signature verifier. Assuming that the server side is relatively secure and the private key will not be leaked, only the public key needs to be protected (prevented from being replaced). For example, a digital certificate is used to ensure that the public key has not been replaced.

[0003] However, the scenario solution applied to traditional applications can no longer meet all requirements. In the new scenarios facing mobile Internet and Internet of Everything, the client needs to generate a signature, and the server verifies the signature. In this scenario, the client uses the private key to sign, and the server uses the public key to verify the signature. As a weak end (such as a smart phone), the client has limited ability to protect the private key. Once the private key is leaked, an attacker can forge a signature, making the entire signature system risky.

[0004] Therefore, a new signature method is needed to improve the security of the private key. Summary of the Invention

[0005] The main object of the present invention is to provide a signature method, a method for verifying a signature, a mobile terminal, and a server to improve the security of the private key.

[0006] In a first aspect, the present invention provides a signature method applied to a signer, including: obtaining a Z algorithm instance for the signer, generating a session key by combining preset real-time parameters and using a preset parameter algorithm; generating a first signature parameter according to the data to be signed and a specified hash value by using a first preset algorithm, and sending the first signature parameter to the signature verifier so that the signature verifier generates a second signature parameter and a first signature factor based on the first signature parameter by combining a preset asymmetric key algorithm; generating a second signature factor by using a second preset algorithm based on the session key, the second signature parameter, and the first signature factor sent by the signature verifier, taking the first signature factor and the second signature factor as the signature result of the data to be signed, and sending the signature result to the signature verifier so that the signature verifier verifies the signature result.

[0007] In one embodiment, according to the signatory identity information and the parameter information of a preset asymmetric key algorithm, a specified hash value is generated by using a third preset algorithm, where the preset asymmetric key algorithm includes an elliptic curve algorithm.

[0008] In one embodiment, the first preset algorithm and the third preset algorithm both include the SM3 algorithm.

[0009] In one embodiment, the number of the second signature parameters is at least two.

[0010] In one embodiment, when the number of the second signature parameters is two; based on the session key, the second signature parameters and the first signature factor sent by the signature verifier, a second signature factor is generated by using a second preset algorithm, including: based on the session key, the two second signature parameters and the first signature factor sent by the signature verifier, the second signature factor is generated by using the following formula: where s represents the second signature factor, d1 represents the first random number generated by the signatory, k1 represents the session key, s1 and s2 both represent the second signature parameters, r represents the first signature factor, |mod| represents the modulo operation, and n represents the order of the base point in the preset asymmetric key algorithm.

[0011] In one embodiment, the method further includes: according to the first random number generated by the signatory, a first preliminary public key is generated by using the preset asymmetric key algorithm, and the first preliminary public key is sent to the signature verifier, so that the signature verifier generates a target public key by using a fourth preset algorithm through combining the first preliminary public key with the second random number generated by the signature verifier.

[0012] In one embodiment, obtaining a Z algorithm instance for the signatory includes: obtaining a Z algorithm instance for the signatory from the terminal of the signatory; or requesting a Z algorithm instance for the signatory from the terminal of the signature verifier.

[0013] In a second aspect, the present invention provides a method for verifying a signature, which is applied to a signature verifier and includes: receiving a first preliminary public key and a signature result generated by using the signature method as described above sent by the signatory; according to the second random number generated by the signature verifier and the first preliminary public key, a target public key is generated by using a fourth preset algorithm, so as to verify the signature result by using the verification method of the preset asymmetric key algorithm according to the target public key.

[0014] In one embodiment, it further includes: obtaining a Z algorithm instance for the signer, combining preset real-time parameters, and using a preset parameter algorithm to generate a session key; based on a preset asymmetric key algorithm, generating a multiple point coordinate according to the session key and a third random number, and then generating a first signature factor according to the multiple point coordinate and a first signature parameter sent by the signer, where the first signature parameter is generated by the signer according to the data to be signed and a specified hash value using a first preset algorithm; generating a second signature parameter according to a second random number and the session key; and sending the second signature parameter and the first signature factor to the signer.

[0015] In a third aspect, the present invention provides a signature method applied to a third party different from the signer and the signature verifier, including: obtaining a Z algorithm instance for the signer, combining preset real-time parameters, and using a preset parameter algorithm to generate a session key; based on a preset asymmetric key algorithm, generating a multiple point coordinate according to the session key and a third random number, and then generating a first signature factor according to the multiple point coordinate and a first signature parameter sent by the signer, where the first signature parameter is generated by the signer according to the data to be signed and a specified hash value using a first preset algorithm; generating a second signature parameter according to a second random number and the session key; and sending the second signature parameter and the first signature factor to the signer.

[0016] In a fourth aspect, the present invention provides a mobile terminal, including: a memory and a processor, where a computer program is stored in the memory, and when the computer program is executed by the processor, it executes the steps of the signature method described above.

[0017] In a fifth aspect, the present invention provides a server, including: a memory and a processor, where a computer program is stored in the memory, and when the computer program is executed by the processor, it executes the steps of the method for verifying a signature described above or the steps of the signature method described above.

[0018] In a sixth aspect, the present invention provides a signature verification system, including the mobile terminal described above and at least one server described above.

[0019] In a seventh aspect, the present invention provides a storage medium storing a computer program, and when the computer program is executed by a processor, it executes the steps of the signature method described above or the steps of the method for verifying a signature described above.

[0020] The technical solution of the present invention can, but is not limited to, strengthen the security protection of the entire signature system based on the scenario of "mobile terminal signature - server signature verification". Even if all the data transmitted during the interaction is eavesdropped, the attacker still cannot forge the signature, and a separate hijacking of the signature party or the signature verification party also cannot forge the signature. At the same time, by combining with the Z cryptographic algorithm, on the one hand, the Z cryptographic algorithm provides a mechanism for deriving random numbers, and on the other hand, through the two-way authentication and session key negotiation mechanism based on the Z cryptographic algorithm, to provide identity key security (algorithm and key integration), and provides enhanced mechanisms such as one-time pad, multi-factor authentication, and two-way authentication. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] The accompanying drawings forming a part of this application are used to provide a further understanding of the present invention. The schematic embodiments and descriptions thereof of the present invention are used to explain the present invention and do not constitute an improper limitation of the present invention. In the drawings:

[0022] Figure 1 is a timing diagram of the signature verification process according to an exemplary embodiment of the present application;

[0023] Figure 2 is a timing diagram of obtaining an instance of the Z algorithm according to an exemplary embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0024] It should be noted that, without conflict, the embodiments in this application and the features in the embodiments can be combined with each other. The present invention will be described in detail below with reference to the drawings and in combination with the embodiments.

[0025] Embodiment 1

[0026] This embodiment provides a specific embodiment of the interaction process of a signature verification method. As Figure 1 shown, taking the mobile terminal as the signature party and the server as the signature verification party as an example for illustration. Of course, the solution of this embodiment is also applicable to the scenario where the server is the signature party and the mobile terminal is the signature verification party, as well as more scenarios.

[0027] In the initialization stage, the signature party generates a first random number d1, and uses the asymmetric encryption algorithm to calculate the first preliminary public key P1 = d1 -1 ·G, and sends the first preliminary public key to the signature verification party. The signature verification party receives the first preliminary public key, generates a second random number d2, and then calculates the target public key P = d2 -1 ·P1 - G, and sends the target public key P to the signature party. Among them, the asymmetric encryption algorithm may include the elliptic curve algorithm, and moreover, the algorithms for calculating the first preliminary public key and the target public key are not limited to this, and those skilled in the art can select according to needs.

[0028] Subsequently, the signer and the verifier can each generate a specified hash value Z using the SM3 algorithm based on the signer's identity information and the parameter information of the elliptic curve algorithm. A Of course, other algorithms that can generate the specified hash value can also be used. The specified hash value generated by the signer is used to generate the first signature parameter subsequently, and the specified hash value generated by the verifier can be used to verify the signature subsequently.

[0029] Meanwhile, the signer can request a Z algorithm instance for the signer from the server, or apply for a Z algorithm instance from the terminal to which the signer belongs, and then send the Z algorithm instance to the verifier. Correspondingly, the verifier can generate a Z algorithm instance for the signer according to the signer's identity information, or receive the Z algorithm instance for the signer sent by the signer.

[0030] Figure 2 It is a timing diagram for obtaining the Z algorithm instance according to an exemplary embodiment of the present application. In Figure 2 , the signer can first send a communication request to the verifier. The communication request can include the signer's identity information and the timestamp T. Subsequently, in response to the communication request, the verifier sends a challenge value to the signer. Based on the challenge value, the signer calculates the result ① according to the algorithm of Z(Z(Z(X)+W)+V) and sends the result ① to the verifier. The verifier also calculates the result ② according to the algorithm of Z(Z(Z(X)+W)+V). When the result ① and ② are the same, it indicates that the authentication is passed. Subsequently, the verifier continues to calculate Z(Z(Z(T)+W)+V) to obtain the result ③ and sends the result ③ to the signer. The signer continues to calculate Z(Z(Z(T)+W)+V) to obtain the result ④. When the result ③ and ④ are the same, it indicates that the authentication is passed. Finally, both parties calculate the session key k1 = Z(Z(Z(Z(X)+W)+V)) simultaneously.

[0031] In the signature stage where the signer signs the data M to be signed, first, according to the data to be signed and the specified hash value Z A , calculate the first signature parameter e = Hash(Z A ||M) according to the SM3 algorithm, and send the first signature parameter e to the verifier. Of course, other algorithms can also be used to calculate the first signature parameter.

[0032] The verifier receives the first signature parameter e and generates a third random number k2. Subsequently, calculate the multiple point coordinates (x1, y1) = k1·k2·G according to k1 and k2, calculate the first signature factor r = (e + x1)|mod|n, and calculate two second signature parameters s1 = d2 -1 ·k1|mod|n and s2 = d2 -1, Finally, send the first signature factor r and the two second signature parameters s1 and s2 to the signer. Among them, the methods for calculating the multiple-point coordinates, the first signature factor, and each second signature parameter are not limited to this, and other feasible algorithms can be used for calculation. The algorithms can be the same or different from each other.

[0033] The signer then calculates the second signature factor s = d1 -1 k1s1 + d1 -1 s2·r - r|mod|n, where s represents the second signature factor, d1 represents the first random number generated by the signer, k1 represents the session key, s1 and s2 both represent the second signature parameters, r represents the first signature factor, |mod| represents the modulo operation, and n represents the order of the base point in the preset asymmetric key algorithm. Among them, the algorithm for calculating the second signature factor is not limited to this, and those skilled in the art can choose according to needs. Send the plaintext data M to be signed and the signature result (r, s) to the verifier so that the verifier can verify the signature result using the target public key.

[0034] The verifier can use the verification process of the SM2 algorithm in related technologies to verify the signature result.

[0035] It should be noted that the verifier participating in the signature and the verifier verifying the signature result can be the same or different. For example, they can be different terminal servers.

[0036] The technical solution of the present invention can, but is not limited to, strengthen the security protection of the entire signature system based on the scenario of "mobile terminal signature - server verification". By decomposing the private key into two key parameters, which are generated by the signer and the verifier respectively, and the real private key never appears in the operations of the signer or the verifier in any complete form, new random numbers are introduced in the signature process to protect the interaction process. At the same time, these random numbers are not required to participate in the verification stage, and the verification process is still the same as that of the standard SM2.

[0037] In terms of security, even if all the data transmitted during the interaction is eavesdropped, the attacker still cannot forge the signature, and hijacking the signer or the verifier alone cannot forge the signature either. At the same time, by combining with the Z cryptographic algorithm, on the one hand, the Z cryptographic algorithm provides a mechanism for deriving random numbers, and on the other hand, through the mutual authentication and session key negotiation mechanism based on the Z cryptographic algorithm, enhanced mechanisms such as one-time password, multi-factor authentication, and mutual authentication are provided to ensure the security of the identity key (algorithm and key integration).

[0038] Example Two

[0039] First, introduce the elliptic curve algorithm in related technologies.

[0040] The elliptic curve algorithm is a public-key encryption algorithm. The difficult problem it relies on is the discrete logarithm problem on the elliptic curve. The elliptic curve cryptography (ECC) was first proposed by Neal Koblit and Victor Miller in 1985. Since then, the security and implementation efficiency of ECC have been widely studied by many mathematicians and cryptographers. The results show that compared with the RSA algorithm, ECC has the characteristics of short key length, fast encryption and decryption speed, low requirements for the computing environment, and low occupancy of communication bandwidth.

[0041] The complexity of the elliptic curve algorithm depends on the irreversibility of finding its multiple points. The operations of points on the elliptic curve are very different from those in the standard coordinate system. The addition of points on the elliptic curve is to connect two points, and the line where they are located intersects the elliptic curve at a third point. Then, find the symmetric point of the third point about the horizontal coordinate axis, which is the coordinate of the sum of the two points. From this, the concept of multiple points can be derived. The double point of a certain point on the elliptic curve is the third point where the tangent line passing through this point intersects the elliptic curve, and then take the symmetric point about the horizontal coordinate axis. The sum of the double point of point P and point P itself is the triple point of point P. By analogy, the coordinates of the K-fold point of point P can be calculated.

[0042] The discrete logarithm problem on the elliptic curve is: Given the coordinates of point P and the coordinates of its K-fold point K·P, it is very difficult to deduce K (the coordinates of each multiple point are relatively discrete and do not have regularity. Therefore, it can only be calculated from point P one by one to find its multiple points and compare the results with K·P). However, the multiplication of points on the elliptic curve (given the coordinates of P and the multiplier K, find K·P) can be quickly obtained according to the Double-and-Add algorithm. This asymmetry in computational difficulty determines the feasibility of the elliptic curve public-key encryption algorithm (the base point P is a negotiated parameter, the multiple K is the private key, and the multiple point K·P is the public key).

[0043] Next, briefly introduce the national cryptographic SM2 signature scheme.

[0044] Before using SM2, both communicating parties need to preset the same elliptic curve parameters, including: parameters a, b to determine the shape of the elliptic curve; large prime number p to determine the finite field Fp; the coordinates (x G , y G ) of the base point G; the order n of the base point G.

[0045] Based on these parameters, both the signer and the verifier need to calculate the hash value Z A , where Z A = H 256(ENTL A ||ID A ||a||b||x G ||y G ||x A ||y A )

[0046] The national cryptographic SM2 signature scheme consists of three parts: key generation, signature generation, and signature verification.

[0047] (1) Key generation

[0048] 1. The signer generates a random number d A , d A ∈ [1, n - 1];

[0049] 2. Calculate P = d A ·G, and make P(x A , y A ) public as the public key, and save d A as the private key.

[0050] (2) Signature generation

[0051] 1. The signer selects a random number k ∈ [1, n - 1] and calculates k·G = (x1, y1);

[0052] 2. Let the message to be signed be M, and the signer calculates e = Hash(Z A ||M);

[0053] 3. Calculate r = (e + x1) |mod| n. If r = 0 or r + k = n, then return to step 1 to regenerate k;

[0054] 4. Calculate s = ((1 + d A ) -1 ·(k - r·d A )) |mod| n. If s = 0, then return to step 1 to regenerate k;

[0055] (r, s) is the signature result;

[0056] (3) The verifier performs signature verification

[0057] 1. Receive the message M and the signature (r, s);

[0058] 2. Check whether r, s ∈ [1, n - 1] is satisfied. If so, continue; otherwise, the signature verification fails;

[0059] 3. Check whether r + s = n is satisfied. If so, the signature verification fails; otherwise, continue;

[0060] 4. Calculate e′ = Hash(Z A||M);

[0061] 5. Calculate (x'1, y'1) = s·G + (r + s)·P;

[0062] 6. Calculate r' = (e' + x'1) |mod| n;

[0063] 7. Check if r = r' is satisfied. If so, the signature verification is successful; otherwise, it fails.

[0064] Finally, introduce the technical solution of the present invention.

[0065] This signature scheme is based on the national cryptographic SM2 signature algorithm architecture. Among them, the names of the elliptic curve parameters used are consistent with those provided in the SM2 official document. This scheme can be generally divided into two parts: the main signature part and the data protection part based on the Z algorithm.

[0066] The main signature part can be divided into three parts: the signature initialization (generating the public key) part, the signature generation part, and the signature verification part.

[0067] (1) Signature initialization

[0068] The purpose of signature initialization is for both communication parties to obtain the public key through negotiation, and neither of them can calculate the public key alone. The specific steps are as follows:

[0069] 1. The client generates a random number d1;

[0070] 2. The client obtains through elliptic curve operations and sends P1 to the server;

[0071] 3. The server generates a random number d2;

[0072] 4. The server performs elliptic curve operations based on d2 and P1 to obtain the target public key and sends P to the client;

[0073] (2) Signature generation

[0074] Before generating the signature, the client and the server first calculate the hash value Z A , Z A = H 256 (ENTL A ||ID A ||a||b||x G ||y G ||x A ||y A ), where the parameters a, b, x G , y G , x A , y AThe parameters of the standard SM2 instance can be referred to, ID A is the user identification, ENTL A is the identification length, and H256() is the national secret SM3 hashing algorithm.

[0075] The generation of the signature in this solution still requires the interaction between the two communication parties. Let the message to be signed be M, and the specific signature steps are as follows (reference can be made to Figure 1 ):

[0076] 1. The client and the server jointly generate the session key k1 based on the two-way authentication and session key negotiation mechanism of the Z cryptographic algorithm;

[0077] The client saves the random number d1 and the public key P locally and directly calls them from the local for signature when needed. However, such direct saving is obviously insecure. Therefore, this solution uses a security mechanism based on the Z algorithm to protect the collaborative mechanism based on SM2.

[0078] The Z cryptographic algorithm is mainly designed to solve the problems of identity authentication and session key negotiation for the public under the condition of mobile Internet. The Z block cipher algorithm is a personalized block cipher algorithm. Here, its encryption or decryption function can be selected as a one-way cipher function. Similar to public key cryptography, it only authenticates the user's identity and completes the session key negotiation. The specific two-way authentication and key negotiation process is as follows:

[0079] Step 1: The user initiates a communication request and sends the user ID and the current time T to the server;

[0080] Step 2: The server responds and sends the challenge value X to the user;

[0081] Step 3: The user calculates Z(Z(Z(X)+W)+V) and sends it to the server, where W is the user's simple password and V is the user's client hardware serial number;

[0082] Step 4: The server calculates Z(Z(Z(X)+W)+V) and compares it with the value sent by the user in Step 3. If they are the same, the authentication passes; otherwise, the authentication fails;

[0083] Step 5: The server calculates Z(Z(Z(T)+W)+V) and sends it to the user;

[0084] Step 6: The user calculates Z(Z(Z(T)+W)+V) and compares it with the value sent by the server in Step 5. If they are the same, the authentication of the server is completed; otherwise, the authentication fails;

[0085] Step 7: Based on the successful authentication of both parties, the user and the server respectively calculate k1 = Z(Z(Z(Z(X)+W)+V)), which serves as the session key for subsequent connection data encryption or as a synchronization parameter (64 bits in total. If 128 bits are required, another set of challenge values can be sent, and both parties perform similar calculations).

[0086] 2. The client calculates e = Hash(Z A ||M), where Hash() is the national cryptography SM3 hashing algorithm. The client sends e as the first signature parameter to the server;

[0087] 3. The server obtains Q = k1·G through elliptic curve operations, generates a random number k2, calculates (x1,y1) = k2·Q; calculates r = (e + x1) |mod| n. If r = 0, regenerate k2; calculate Calculate Send (r, s1, s2) as the second signature parameter to the client;

[0088] 4. The client calculates If s = 0 or s = n - r, return to Step 1;

[0089] 5. Signature is completed. The client outputs the plaintext M and the signature result (r, s).

[0090] (3) Signature verification

[0091] The signature verification part of the server is basically the same as the signature verification process of national cryptography SM2. The specific steps are as follows:

[0092] 1. Receive the message M and the signature (r, s);

[0093] 2. Check whether r, s ∈ [1, n - 1]. If so, continue; otherwise, the signature verification fails;

[0094] 3. Check whether r + s = n. If so, the signature verification fails; otherwise, continue;

[0095] 4. Calculate e′ = Hash(Z A ||M);

[0096] 5. Calculate (x′1,y′1) = s·G+(r + s)·P;

[0097] 6. Calculate r′ = (e′ + x′1) |mod| n;

[0098] 7. Check whether r = r′. If so, the signature verification is successful; otherwise, the signature verification fails.

[0099] This solution adopts a collaborative computing method to ensure the security of private key signature calculation under the condition of a weak terminal (without a hardware security medium). At the same time, by combining with the Z cryptographic algorithm, on the one hand, the two-way authentication based on the Z cryptographic algorithm effectively improves the trusted computing security of the terminal. On the other hand, through the session key negotiation mechanism of Z, the security of sensitive parameters required for collaborative signature calculation is effectively guaranteed. Therefore, the overall solution greatly improves the security of collaborative signature under pure software conditions, and effectively improves the convenience, compliance, and omnipresence of cryptographic calculation for general-purpose terminals.

[0100] Embodiment III

[0101] This embodiment provides a mobile terminal, including: a memory and a processor. A computer program is stored in the memory. When the computer program is executed by the processor, the steps of the signature method described above are executed.

[0102] In one embodiment, the mobile device may include one or more processors (CPUs), an input / output interface, a network interface, and a memory.

[0103] The memory may include non-permanent memory in a computer-readable medium, random access memory (RAM), and / or non-volatile memory in the form of, for example, read-only memory (ROM) or flash memory (FLASH RAM). The memory is an example of a computer-readable medium.

[0104] Embodiment IV

[0105] This embodiment provides a server, including: a memory and a processor. A computer program is stored in the memory. When the computer program is executed by the processor, the steps of the method for verifying a signature described above or the steps of the signature method described above are executed.

[0106] In one embodiment, the server may include one or more processors (CPUs), an input / output interface, a network interface, and a memory.

[0107] The memory may include non-permanent memory in a computer-readable medium, random access memory (RAM), and / or non-volatile memory in the form of, for example, read-only memory (ROM) or flash memory (FLASH RAM). The memory is an example of a computer-readable medium.

[0108] Embodiment V

[0109] This embodiment provides a signature verification system, including the mobile terminal described above and at least one server described above. When the number of included servers is more than two, the server executing the signature method and the server executing the method for verifying a signature may be different servers.

[0110] Embodiment Six

[0111] This embodiment provides a storage medium storing a computer program, which when executed by a processor, performs the steps of the signature method described above or the steps of the method for verifying a signature described above.

[0112] The computer program can be in any combination of one or more storage media. The storage medium can be a readable signal medium or a readable storage medium.

[0113] The readable storage medium can, for example, include an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of the readable storage medium (a non-exhaustive list) can include: an electrical connection with one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.

[0114] The readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, which carries the readable computer program. Such a propagated data signal can take various forms, for example, it can include an electromagnetic signal, an optical signal, or any suitable combination of the above. The readable signal medium can also be any storage medium other than the readable storage medium, which can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device.

[0115] The computer program contained on the storage medium can be transmitted by any suitable medium, for example, it can include wireless, wired, optical fiber, RF, etc., or any suitable combination of the above.

[0116] The computer program for performing the operations of the present invention can be written in any combination of one or more programming languages. The programming languages can include object-oriented programming languages - such as Java, C++, etc., and can also include conventional procedural programming languages - such as the "C" language or similar programming languages. The computer program can be executed entirely on the user's computing device, partially on the user's device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device can be connected to the user's computing device through any type of network (for example, it can include a local area network or a wide area network), or it can be connected to an external computing device (for example, by using an Internet service provider to connect through the Internet).

[0117] It should be noted that the terms used herein are only for describing specific embodiments and are not intended to limit the exemplary embodiments according to the present application. When the terms "comprising" and / or "including" are used in this specification, they indicate the presence of features, steps, operations, devices, components, and / or combinations thereof.

[0118] It should be noted that the terms "first", "second", etc. in the specification, claims, and drawings of the present application are used to distinguish similar objects and are not used to describe a specific order or sequence. It should be understood that such terms can be interchanged under appropriate circumstances.

[0119] It should be understood that the exemplary embodiments in this specification can be implemented in many different forms and should not be construed as being limited only to the embodiments set forth herein. Additionally or alternatively, certain steps may be omitted, multiple steps may be combined into one step for execution, and / or one step may be decomposed into multiple steps for execution. These embodiments are provided to make the disclosure of the present application thorough and complete and to fully convey the concept of these exemplary embodiments to those of ordinary skill in the art, and should not be construed as a limitation of the present invention.

[0120] Although the spirit and principles of the present invention have been described with reference to several specific embodiments, it should be understood that the present invention is not limited to the specific embodiments disclosed, and the division of each aspect does not mean that the features in these aspects cannot be combined for benefit. This division is only for the convenience of expression. The present invention is intended to cover various modifications and equivalent arrangements included within the spirit and scope of the appended claims.

Claims

1. A signature method, characterized in that, Applied to the signatory, including: Obtain a Z algorithm instance for the signatory, which is generated from the identity information of the signatory, combine with preset elliptic curve parameters, and use the Z cryptographic algorithm to generate a session key; According to the data to be signed and the specified hash value, use the first preset algorithm to generate a first signature parameter, and send the first signature parameter to the verifier, so that the verifier calculates a first signature factor based on the first signature parameter combined with the preset asymmetric key algorithm, and generates a second signature parameter based on the first signature factor, the session key, and the preset asymmetric key algorithm; Based on the session key, the second signature parameter and the first signature factor sent by the verifier, use the second preset algorithm to generate a second signature factor, use the first signature factor and the second signature factor as the signature result of the data to be signed, and send the signature result to the verifier, so that the verifier verifies the signature result.

2. The signature method according to claim 1, wherein According to the signatory's identity information and the parameter information of the preset asymmetric key algorithm, use the third preset algorithm to generate a specified hash value, where the preset asymmetric key algorithm includes an elliptic curve algorithm.

3. The signature method according to claim 2, wherein The first preset algorithm and the third preset algorithm respectively include the SM3 algorithm.

4. The signature method according to claim 1, wherein The number of the second signature parameters is at least two.

5. The signature method according to claim 1 or 4, characterized in that, When the number of the second signature parameters is two; Based on the session key, the second signature parameter and the first signature factor sent by the verifier, use the second preset algorithm to generate a second signature factor, including: Based on the session key, the two second signature parameters and the first signature factor sent by the verifier, use the following formula to generate a second signature factor: where s represents the second signature factor, d1 represents the first random number generated by the signatory, k1 represents the session key, s1 and s2 both represent the second signature parameters, r represents the first signature factor, |mod| represents the modulo operation, and n represents the order of the base point in the preset asymmetric key algorithm.

6. The signature method according to claim 1, characterized in that, The method further includes: According to the first random number generated by the signatory, use the preset asymmetric key algorithm to generate a first preliminary public key, and send the first preliminary public key to the verifier, so that the verifier uses the fourth preset algorithm to generate a target public key by combining the first preliminary public key with the second random number generated by the verifier.

7. The signature method according to claim 1, wherein Obtain a Z algorithm instance for the signatory, including: Obtain a Z algorithm instance for the signatory from the terminal where the signatory is located; or Request a Z algorithm instance for the signatory from the terminal where the verifier is located.

8. A method for verifying a signature, characterized in that, Applied to the verifier, including: Receive the first preliminary public key and the signature result sent by the signatory generated by using the signature method according to any one of claims 1 to 7; According to the second random number generated by the verifier and the first preliminary public key, use the fourth preset algorithm to generate a target public key, so as to verify the signature result according to the verification method of the preset asymmetric key algorithm by using the target public key.

9. The method for verifying a signature according to claim 8, wherein, Further includes: Obtain a Z algorithm instance for the signatory, combine with preset real-time parameters, and use the preset parameter algorithm to generate a session key; Based on a preset asymmetric key algorithm, generate double point coordinates according to the session key and a third random number, and then generate a first signature factor according to the double point coordinates and a first signature parameter sent by the signer, where the first signature parameter is generated by the signer according to the data to be signed and a specified hash value using a first preset algorithm; Generate a second signature parameter according to a second random number and the session key; Send the second signature parameter and the first signature factor to the signer.

10. A signature method, characterized in that, Applied to a third party different from the signer and the signature verifier, including: Obtain a Z algorithm instance for the signer, which is generated from the identity information of the signer. Combine the preset elliptic curve parameters and use the Z cryptographic algorithm to generate a session key; Based on a preset asymmetric key algorithm, generate double point coordinates according to the session key and a third random number, and then generate a first signature factor according to the double point coordinates and a first signature parameter sent by the signer, where the first signature parameter is generated by the signer according to the data to be signed and a specified hash value using a first preset algorithm; Generate a second signature parameter according to a second random number and the session key; Send the second signature parameter and the first signature factor to the signer.

11. A mobile terminal, characterized in that, Including: A memory and a processor, where a computer program is stored in the memory. When the computer program is executed by the processor, the steps of the signature method according to any one of claims 1 to 7 are executed.

12. A server, characterized in that, Including: A memory and a processor, where a computer program is stored in the memory. When the computer program is executed by the processor, the steps of the method for verifying a signature according to claim 8 or 9 or the steps of the signature method according to claim 10 are executed.

13. A signature verification system, characterized in that, Including the mobile terminal according to claim 11 and at least one server according to claim 12.

14. A storage medium stores a computer program, characterized in that, When the computer program is executed by the processor, the steps of the signature method according to any one of claims 1 to 7 or the steps of the method for verifying a signature according to claim 8 or 9 or the steps of the signature method according to claim 10 are executed.

Citation Information

Patent Citations

  • Private key generation method, signature method and signature verification method

    CN116545614A