Data storage device capable of digital signature, digital signature system, and signature method
By using non-copyable functions in the data storage device to generate a unique private key and using asymmetric encryption algorithm for digital signatures, the problem of private keys being easily deleted or lost is solved, and the security of data transmission is improved.
Patent Information
- Application Number
- CN202110149638.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-02-03
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2041-02-03
AI Technical Summary
In the prior art, private keys protected by asymmetric encryption algorithms are easily deleted or lost, resulting in the inability to decrypt encrypted data. At the same time, backing up the private key to improve security will increase the risk of stolen and reduce the security of data transmission.
By introducing non-replicable functions in the data storage device, a unique private key is generated, and asymmetric encryption algorithm is used to convert the private key into a public key for digital signature. The digital signature system includes a controller, flash memory and data transmission interface, and connects electronic devices through the data transmission interface to realize hashing operations and digital signatures of specific data.
It improves the security of private keys, avoids the situation of mistaken deletion or loss, and reduces the risk of private keys being stolen, and enhances the security of data transmission.
Smart Images

Figure CN114861231B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a data storage device that can digitally sign data generated by performing a specific operation on an electronic device. Background Art
[0002] With the progress of technology and the popularity of the Internet, digital information floods our lives. Since digital information is easily spread and copied, in order to improve the security and reliability of digital information, data is generally encrypted during transmission.
[0003] Encryption algorithms are divided into two types: symmetric encryption algorithms and asymmetric encryption algorithms. Among them, for symmetric encryption algorithms, the encryption and decryption of data use the same key. When transmitting encrypted data, the key must also be transmitted so that the data recipient can decrypt the encrypted data using the received key. However, during the process of transmitting the key, the key may also be intercepted by hackers, so that the data content can also be easily known and tampered with by hackers. Therefore, protecting digital information using symmetric encryption algorithms is relatively insecure.
[0004] In addition, asymmetric encryption algorithms can generate a pair of asymmetric keys, for example: a public key and a private key. The public key is a key that can be made public to others, while the private key is a key that the user keeps for himself and cannot be made public. Use the public key to encrypt data and the private key to decrypt the encrypted data; or use the private key to encrypt data and the public key to decrypt the encrypted data. Using asymmetric encryption algorithms to protect digital information, since the trouble of transmitting the key is eliminated, even if the encrypted data is intercepted by hackers midway, the hackers cannot easily decrypt or tamper with the encrypted data content. Therefore, protecting digital information using asymmetric encryption algorithms is relatively secure.
[0005] Furthermore, asymmetric encryption algorithms are usually stored in a data storage device of a computer device in a software form or built into a security chip of a computer device in a firmware form. A processor or security chip of the computer device randomly generates a private key and its corresponding public key through the asymmetric encryption algorithm. The private key and the public key are respectively a string of random passwords, and the private key is usually stored in the data storage device. If the private key stored in the data storage device is accidentally deleted or lost, the subsequent encrypted data cannot be decrypted. Therefore, in order to avoid the private key being accidentally deleted or lost, the private key can also be backed up in multiple storage devices. However, this approach will increase the chance of the private key being stolen, thereby reducing the security during data transmission. Summary of the Invention
[0006] The object of the present invention is to provide a digital signature system, which includes an electronic device and a data storage device. The electronic device is a device that can perform a specific operation to generate specific data, and the data storage device is a device that can perform digital signature. The electronic device or the data storage device can perform a hashing operation on the specific data to obtain a hashed data. The data storage device performs a digital signature operation on the hashed data, so that the hashed data corresponding to the specific data generated by the electronic device can be protected by digital signature security.
[0007] Another object of the present invention is to provide a digital signature system. The data storage device includes a controller, a plurality of flash memories, and a data transmission interface. The data storage device is connected to the electronic device through the data transmission interface. When performing the digital signature operation, the data storage device reads an uncopyable function and generates a private key according to the uncopyable function, converts the private key into a corresponding public key by using an asymmetric encryption algorithm, encrypts the hashed data corresponding to the specific data generated by the electronic device by using the private key to generate a digital signature, and transmits the public key and the digital signature to the electronic device through the data transmission interface to complete the digital signature operation.
[0008] Another object of the present invention is to provide a digital signature system. After receiving the public key and the digital signature from the data storage device, the electronic device transmits the public key to a notary agency for registration to bind the data storage device to the public key. The electronic device uploads the specific data and the digital signature to a cloud or a data verification unit. When receiving the specific data and the digital signature, the cloud or the data verification unit will execute a data verification program. In the data verification program, the cloud or the data verification unit obtains the public key bound to the data storage device from the notary agency, and decrypts the digital signature by using the public key to obtain a first hashed data. The cloud or the data verification unit performs a hashing operation on the specific data to generate a second hashed data. Then, the cloud or the data verification unit compares the second hashed data with the first hashed data. If the second hashed data is equal to the first hashed data, the specific data is an unaltered data; otherwise, if the second hashed data is not equal to the first hashed data, the specific data is an altered data. The cloud or the data verification unit verifies whether the specific data is provided by a trustworthy electronic device by executing the data verification program.
[0009] To achieve the above object, the present invention provides a data storage device capable of digital signature, comprising: a controller including a firmware having a private key; a plurality of flash memories; and a data transmission interface, wherein the controller is connected to the flash memories and the data transmission interface, and the data storage device is connected to an electronic device through the data transmission interface; wherein, the electronic device performs a specific operation to generate a specific data, and a first hash data is generated by calculating the specific data using a hash algorithm; wherein, the data storage device receives the first hash data from the electronic device through the data transmission interface, the firmware of the controller encrypts the first hash data using the private key to generate a digital signature, and the data storage device transmits the digital signature to the electronic device through the data transmission interface.
[0010] In an embodiment of the present invention, the firmware reads a non-replicable function to generate a private key according to the non-replicable function.
[0011] In an embodiment of the present invention, the firmware of the controller converts the private key into a corresponding public key using an asymmetric encryption algorithm, and the data storage device transmits the public key to the electronic device through the data transmission interface.
[0012] The present invention further provides a data storage device capable of digital signature, comprising: a controller including a firmware having a private key; a plurality of flash memories; and a data transmission interface, wherein the controller is connected to the flash memories and the data transmission interface, and the data storage device is connected to an electronic device through the data transmission interface; wherein, the electronic device performs a specific operation to generate a specific data; wherein, the data storage device receives the specific data from the electronic device through the data transmission interface, the firmware of the controller calculates the specific data using a hash algorithm to generate a first hash data, encrypts the first hash data using the private key to generate a digital signature, and the data storage device transmits the digital signature to the electronic device through the data transmission interface.
[0013] In an embodiment of the present invention, the firmware reads a non-replicable function to generate a private key according to the non-replicable function.
[0014] The present invention further provides a digital signature system, comprising: an electronic device that performs a specific operation to generate a specific data, and calculates the specific data using a hash algorithm to generate a first hash data; and a data storage device, comprising: a controller including a firmware having a private key; a plurality of flash memories; and a data transmission interface, wherein the controller is connected to the flash memories and the data transmission interface, and the data storage device is connected to the electronic device through the data transmission interface; wherein, the electronic device transmits the first hash data to the data storage device; wherein, the data storage device receives the first hash data from the electronic device through the data transmission interface, the firmware of the controller encrypts the first hash data using the private key to generate a digital signature, and the data storage device transmits the digital signature to the electronic device through the data transmission interface.
[0015] In an embodiment of the present invention, the electronic device is a device with networking capabilities. The electronic device is networked to a blockchain, and the electronic device transmits specific data and a digital signature to the blockchain to upload the specific data and the digital signature onto the blockchain.
[0016] In an embodiment of the present invention, the electronic device is a device with networking capabilities. The electronic device transmits a public key to a notary institution for registration to bind the public key to the data storage device.
[0017] In an embodiment of the present invention, the digital signature system includes a cloud or a data verification unit. The electronic device is networked to the cloud or the data verification unit, and the electronic device transmits specific data and a digital signature to the cloud or the data verification unit. After receiving the specific data and the digital signature, the cloud or the data verification unit obtains the public key from the notary institution, decrypts the digital signature using the public key to obtain the first hash data, performs a hash calculation on the specific data to generate a second hash data, and compares the second hash data with the first hash data to verify the authenticity of the specific data.
[0018] The present invention further provides a digital signature system, including: an electronic device that performs a specific operation to generate specific data; and a data storage device, including: a controller including a firmware having a private key; a plurality of flash memories; and a data transmission interface, where the controller is connected to the flash memories and the data transmission interface, and the data storage device is connected to the electronic device through the data transmission interface; wherein the electronic device transmits the specific data to the data storage device; wherein the data storage device receives the specific data from the electronic device through the data transmission interface, the firmware of the controller calculates the specific data using a hash algorithm to generate a first hash data, encrypts the first hash data using the private key to generate a digital signature, and the data storage device transmits the digital signature to the electronic device through the data transmission interface.
[0019] The present invention further provides a digital signature method applied to a digital signature system including an electronic device and a data storage device. The electronic device performs a specific operation to generate specific data and calculates the specific data using a hash algorithm to generate a first hash data. The data storage device includes a controller, a plurality of flash memories, and a data transmission interface. The controller includes a firmware, and the firmware performing the digital signature method includes: generating a private key; receiving the first hash data from the electronic device through the data transmission interface; encrypting the first hash data using the private key to generate a digital signature; and transmitting the digital signature to the electronic device.
[0020] The present invention further provides a digital signature method. The digital signature method is applied to a digital signature system, which includes an electronic device and a data storage device. The electronic device performs a specific operation to generate specific data. The data storage device includes a controller, multiple flash memories, and a data transmission interface. The controller includes a firmware, and the firmware performing the digital signature method includes: generating a private key; receiving the specific data from the electronic device through the data transmission interface; calculating the specific data using a hash algorithm to generate a first hash data; encrypting the first hash data using the private key to generate a digital signature; and transmitting the digital signature to the electronic device. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] Figure 1 It is a schematic diagram of the architecture of the digital signature system of the present invention.
[0022] Figure 2 It is a flowchart of an embodiment of the digital signature method of the present invention.
[0023] Figure 3 It is a flowchart of another embodiment of the digital signature method of the present invention.
[0024] DESCRIPTION OF REFERENCE NUMERALS: 100 - digital signature system; 10 - electronic device; 11 - processor; 12 - specific data; 13 - special application chip; 131 - embedded system; 14 - first hash data; 15 - network communication component; 16 - second hash data; 17 - data uploading program; 200 - blockchain; 20 - data storage device; 21 - controller; 211 - firmware; 212 - digital signature operation program; 22 - volatile memory; 221 - non - replicable function; 23 - flash memory; 24 - digital seal; 25 - data transmission interface; 271 - private key; 272 - public key; 300 - notary agency; 301 - private key; 302 - public key; 31 - electronic certificate; 400 - cloud; 500 - data verification unit. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0025] Please refer to Figure 1 which is a schematic diagram of the architecture of the digital signature system of the present invention. As Figure 1As shown, the digital signature system 100 includes an electronic device 10 and a data storage device 20. The electronic device 10 of the present invention is a device capable of performing specific operations, such as: a computer host, a communication device, or an Internet of Things device. The electronic device 10 includes a processor 11 or an Application Specific Integrated Circuit (ASIC) 13. The electronic device 10 generates a specific data 12 by performing a specific operation in a software manner through the processor 11, or generates the specific data 12 by performing a specific operation in a hardware manner through the special application chip 13. The data storage device 20 is a device capable of digital signature, which can perform a digital signature operation on the specific data 12 generated by the electronic device 10 or the specific data 12 after a hash calculation, so that the specific data 12 generated by the electronic device 10 or the specific data 12 after the hash calculation can be protected by digital signature. In addition, the electronic device 10 further includes a network communication component 15, and the electronic device 10 uses the network communication component 15 to connect to the network.
[0026] The data storage device 20 of the present invention may also be a Solid State Disk. The data storage device 20 is an external device independent of the electronic device 10, or may alternatively be disposed inside an electronic device 10 as a storage medium of the electronic device 10. The data storage device 20 includes a controller 21, a plurality of flash memories 23, and a data transmission interface 25. The controller 21 is respectively connected to the flash memory 23 and the data transmission interface 25. The data transmission interface 25 is an interface conforming to SATA, PCIe, USB, or other data standard specifications. The data storage device 20 is plugged into a connector of the electronic device 10 through the data transmission interface 25, such as a SATA, PCIe, or USB base. The data storage device 20 and the electronic device 10 transmit data through the data transmission interface 25.
[0027] The controller 21 includes a firmware 211. The firmware 211 is set with a digital signature operation program 212. The user can also control the firmware 211 of the controller 21 to execute the digital signature operation program 212 in a software manner (such as an application program) or a hardware manner (such as a physical control button).
[0028] The firmware 211 has a private key 271. The private key 271 is generated according to an unclonable function 221. In an embodiment of the present invention, the controller 21 includes a volatile memory (such as SRAM) 22, and the unclonable function 221 is the initial state of the volatile memory 22 when it is powered on. The firmware 211 reads the initial state of the volatile memory 22 when it is powered on to generate the private key 271 according to the initial state of the volatile memory 22 when it is powered on. In another embodiment of the present invention, the unclonable function 221 is a biometric feature captured by a biometric capture module, such as a fingerprint, a vein pattern, a face, or an iris. The biometric capture module (not shown) is disposed in the data storage device 20 or is an external device of a data storage device 20. The firmware 211 reads the biometric feature through the biometric capture module to generate the private key 271 according to the biometric feature. Since the unclonable function of the physical feature (such as the initial state of the volatile memory 22 when it is powered on) 221 or the unclonable function of the biometric feature (such as a fingerprint, a vein pattern, a face, or an iris) 221 is unique, the data storage device 20 can use the unclonable function 221 of the physical feature or the biometric feature to generate the same private key 271 at any operating time, so that there is no need to store the private key 271. Without storing the private key 271, the risk of the private key 271 being copied and leaked can be reduced to improve the security of the digital signature.
[0029] In another embodiment of the present invention, the controller 21 further includes a key storage area (not shown). The key storage area can also be a read-only memory (ROM). The private key 271 is burned in the key storage area in an encryption manner. For example, the private key 271 is encrypted by AES, DES, or other encryption algorithms and the encrypted private key 271 is burned in the key storage area. Then, the firmware 211 decrypts the private key 271 retrieved from the key storage area through the encryption algorithm. Then, the private key 271 is stored in the read-only memory in an encrypted manner, which can avoid the risks of being tampered with and leaked.
[0030] After obtaining the private key 271, the firmware 21 further converts the private key 271 into a corresponding public key 272 by using an asymmetric encryption algorithm. The asymmetric encryption algorithm is an elliptic curve algorithm or an RSA encryption algorithm. The data storage device 20 transmits the public key 272 to the electronic device 10 through the data transmission interface 25. In an embodiment of the present invention, after receiving the public key 272, the electronic device 10 can further transmit the public key 272 to a notary agency (such as a Certificate Authority, CA) 300 for registration to bind the public key 272 with the data storage device 20.
[0031] Continuing from the above, after the electronic device 10 finishes executing a specific operation, specific data 12 will be generated. The specific data 12 will be subjected to a hashing operation by the electronic device 10 or the data storage device 20 to obtain a first hash data 14 corresponding to the specific data 12. In an embodiment of the present invention, if the hashing operation of the specific data 12 is executed by the electronic device 10, the electronic device 10 will execute the hashing operation of the specific data 12 through the processor 11 or the special application chip 13 to obtain the first hash data 14, and transmit the first hash data 14 to the data storage device 20. Alternatively, in another embodiment of the present invention, if the hashing operation of the specific data 12 is executed by the data storage device 20, the electronic device 10 will transmit the specific data 12 to the data storage device 20, and the data storage device 20 will execute the hashing operation of the specific data 12 through the firmware 211 of the controller 21 to obtain the first hash data 14. After the firmware 211 obtains the first hash data 14 corresponding to the specific data 12, it encrypts the first hash data 14 using the private key 271 to generate a digital signature 24, and transmits the digital signature 24 to the electronic device 10 through the data transmission interface 25 to complete the digital signature process.
[0032] After receiving the digital signature 24, the user of the electronic device 10 uploads the specific data 12 and the digital signature 24 to a cloud 400, or hands the specific data 12 and the digital signature 24 to a data verification unit 500. When the cloud 400 or the data verification unit 500 receives the specific data 12 and the digital signature 24, in order to verify the authenticity of the specific data 12, a data verification program can be executed.
[0033] In the data verification program, the cloud 400 or the data verification unit 500 obtains the public key 272 bound to the data storage device 20 from the notary agency 300, and decrypts the digital signature 24 using the public key 272 to obtain the first hash data 14. The cloud 400 or the data verification unit 500 performs a hashing operation on the specific data 12 again to generate a second hash data 16. Then, the cloud 400 or the data verification unit 500 compares the second hash data 16 with the first hash data 14. If the second hash data 16 is equal to the first hash data 14, the specific data 12 is an unaltered data; conversely, if the second hash data 16 is not equal to the first hash data 14, the specific data 12 is an altered data. Here, the cloud 400 or the data verification unit 500 verifies whether the specific data 12 is provided by a trustworthy electronic device 10 by executing the data verification program. In the present invention, the cloud 400 can also be a network server, a remote computer, or a remote communication device, and the data verification unit 500 is a unit equipped with a data operation device (such as a computer device).
[0034] In another embodiment of the present invention, in order to improve the credibility of the public key 272, the electronic device 10 may also submit an application for an electronic certificate to the notary institution 300 for the public key 272. The notary institution 300 encrypts the public key 272 of the electronic device 10 using a private key 301 of the notary institution to bind an electronic certificate 31, and returns the electronic certificate 31 to the electronic device 10. Thereafter, the electronic device 10 uploads the electronic certificate 31, the digital signature 24, and the specific data 12 to the cloud 400 or delivers them to the data verification unit 500. After receiving the electronic certificate 31, the digital signature 24, and the specific data 12, the cloud 400 or the data verification unit 500 will execute a data verification program. In the data verification program, the cloud 400 or the data verification unit 500 obtains a public key 302 of the notary institution 300 from the notary institution 300. The cloud 400 or the data verification unit 500 decrypts the electronic certificate 31 using the public key 302 of the notary institution 300 to obtain the public key 272 of the electronic device 10. Subsequently, the cloud 400 or the data verification unit 500 decrypts the digital signature 24 using the public key 272 of the electronic device 10 to obtain the first hash data 14. The cloud 400 or the data verification unit 500 performs a hash calculation on the specific data 12 again to generate the second hash data 16; then, the cloud 400 or the data verification unit 500 compares the second hash data 16 with the first hash data 14. If the second hash data 16 is equal to the first hash data 14, the specific data 12 is an unaltered data; otherwise, if the second hash data 16 is not equal to the first hash data 14, the specific data 12 is an altered data.
[0035] For example, in an application embodiment of the present invention, the electronic device 10 is a device capable of producing electronic certificates (such as graduation certificates, skill certification certificates, patent certificates, etc.). The electronic device 10 executes an operation of producing an electronic certificate through an electronic certificate production software to generate specific data 12 related to the electronic certificate. The processor 11 of the electronic device 10 or the firmware 211 of the data storage device 20 calculates the specific data 12 through a hashing algorithm to obtain the first hash data 14 corresponding to the specific data 12. Then, the firmware 211 of the data storage device 20 encrypts the first hash data 14 using the private key 271 to generate a digital signature 24. The data storage device 20 transmits the digital signature 24 to the electronic device 10 through the data transmission interface 25. Then, the electronic device 10 transmits the specific data 12 related to the electronic certificate and the digital signature 24 to the data verification unit 500, such as the human resources department of an enterprise. When receiving the specific data 12 and the digital signature 24, the data verification unit 500 obtains the public key 272 bound to the electronic device 10 from the notary agency 300, and decrypts the digital signature 24 using the public key 272 to obtain the first hash data 14. In addition, the data verification unit 500 performs a hashing operation on the specific data 12 again to generate a second hash data 16. Then, the data verification unit 500 compares the second hash data 16 with the first hash data 14. If the second hash data 16 is equal to the first hash data 14, then the specific data 12 related to the electronic certificate is an unaltered and trustworthy data; conversely, if the second hash data 16 is not equal to the first hash data 14, then the specific data 12 related to the electronic certificate is a forged data.
[0036] In another application embodiment of the present invention, the electronic device 10 is a device capable of performing network transactions (such as shopping transactions or securities transactions). The electronic device 10 performs an operation of a network transaction through a network transaction application program to generate specific data 12 related to the network transaction. The processor 11 of the electronic device 10 or the firmware 211 of the data storage device 20 calculates the specific data 12 through a hashing algorithm to obtain the first hash data 14 corresponding to the specific data 12. Then, the firmware 211 of the data storage device 20 encrypts the first hash data 14 using the private key 271 to generate a digital signature 24. The data storage device 20 transmits the digital signature 24 to the electronic device 10 through the data transmission interface 25. Then, the electronic device 10 transmits the specific data 12 related to the network transaction and the digital signature 24 to the cloud 400, such as a network transaction center. When receiving the specific data 12 and the digital signature 24, the cloud 400 obtains the public key 272 bound to the electronic device 10 from the notary agency 300, and decrypts the digital signature 24 using the public key 272 to obtain the first hash data 14. In addition, the cloud 400 performs a hashing calculation on the specific data 12 again to generate a second hash data 16. Then, the cloud 400 compares the second hash data 16 with the first hash data 14. If the second hash data 16 is equal to the first hash data 14, the specific data 12 of the network transaction is an unaltered data, and the cloud 400 executes a network transaction process according to the specific data 12; otherwise, if the second hash data 16 is not equal to the first hash data 14, the specific data 12 of the network transaction is an altered data, and the cloud 400 prohibits the execution of the network transaction process.
[0037] Of course, in the above application embodiment, when the electronic device 10 transmits the public key 272 to the notary agency 300, it can further submit an application for the electronic certificate 31 to the notary agency 300 to improve the credibility of the public key 272. Furthermore, the digital signature system 100 of the present invention can be applied not only to the electronic signature of electronic certificates or relevant data of network transactions, but also to other uses that require data protection. Here, they will not be listed one by one.
[0038] Furthermore, in another embodiment of the present invention, the electronic device 10 can also directly transmit the public key 272 to the cloud 400 or the data verification unit 500. Then, the cloud 400 or the data verification unit 500 directly decrypts the digital signature 24 using the public key 272 delivered by the electronic device 10 to obtain the first hash data 14.
[0039] In addition, the electronic device 10 is network-connected to a blockchain 200 through the network communication component 15. The electronic device 10 further includes a data uploading program 17. The data uploading program 17 is selectively built in the processor 11 or the application-specific chip 13 in the form of a firmware and directly executed by the microprocessor 13 or the controller 111. Alternatively, the application-specific chip 13 includes an embedded system 131, and the data uploading program 17 is installed in the embedded system 131 of the application-specific chip 13 in the form of a software and executed by the embedded system 131. The electronic device transmits the specific data 12 and / or the digital signature 24 to the blockchain 200 to upload the specific data 12 and / or the digital signature 24 onto the blockchain 200. Then, due to the characteristics of the blockchain that data cannot be tampered with or forged, the specific data 12 and / or the digital signature 24 can be protected in the blockchain 200 to enhance the security of the application of the specific data 12 and / or the digital signature 24.
[0040] Please refer to Figure 2 , which is a flowchart of an embodiment of the digital signature method of the present invention, and also refer to Figure 1 . First, in step 601, the firmware 211 of the controller 21 of the data storage device 20 reads a non-replicable function 221 to generate a private key 271 according to the non-replicable function 221, and converts the private key 271 into a corresponding public key 272 by using an asymmetric encryption algorithm. In step S603, the electronic device 10 receives the public key 272 from the data storage device 20. In step S605, the processor 11 or the application-specific chip 13 of the electronic device 10 performs a specific operation to generate a specific data 12, calculates the specific data 12 by using a hash algorithm to obtain a first hash data 14, and transmits the first hash data 14 to the data storage device 20. In step 607, after receiving the first hash data 14, the data storage device 20 encrypts the first hash data 14 by using the private key 271 to generate a digital signature 24, and transmits the digital signature 24 to the electronic device 10 through the data transmission interface 25 to complete the digital signature process. Furthermore, in an embodiment of the present invention, after step S603 in which the electronic device 10 receives the public key 272 from the data storage device 20, step S604 is executed to further transmit the public key 272 to the notary institution 300 for registration to bind the public key 272 with the data storage device 20.
[0041] Next, in step 609, the electronic device 10 uploads the specific data 12 and the digital signature 24 to a cloud 400 or a data verification unit 500, and the cloud 400 or the data verification unit 500 can execute a data verification program 70. In the data verification program 70, in step 701, the cloud 400 or the data verification unit 500 obtains the public key 272 bound to the data storage device 20 from the electronic device 10 or the notary institution 300, and decrypts the digital signature 24 using the public key 272 to obtain the first hash data 14. In step 703, the cloud 400 or the data verification unit 500 performs a hash calculation on the specific data 12 to generate a second hash data 16. In step 705, the cloud 400 or the data verification unit 500 compares the second hash data 16 with the first hash data 14. If the second hash data 16 is equal to the first hash data 14, in step 707, the cloud 400 or the data verification unit 500 determines that the specific data 12 is an unaltered data; otherwise, in step 709, if the second hash data 16 is not equal to the first hash data 14, the cloud 400 or the data verification unit 500 determines that the specific data 12 is an altered data.
[0042] Please refer to Figure 3 , which is a flowchart of another embodiment of the digital signature method of the present invention, and also refer to Figure 1 . First, in step 601, the firmware 211 of the controller 21 of the data storage device 20 reads a non-replicable function 221 to generate a private key 271 according to the non-replicable function 221, and converts the private key 271 into a corresponding public key 272 using an asymmetric encryption algorithm. In step S603, the electronic device 10 receives the public key 272 from the data storage device 20. In step S606, the processor 11 or the special application chip 13 of the electronic device 10 performs a specific operation to generate a specific data 12. The data storage device 20 receives the specific data 12 from the electronic device 10, and calculates the specific data 12 using a hash algorithm to obtain a first hash data 14. In step 607, after the data storage device 20 obtains the first hash data 14, it encrypts the first hash data 14 using the private key 271 to generate a digital signature 24, and transmits the digital signature 24 to the electronic device 10 through the data transmission interface 25 to complete the digital signature process. Furthermore, in an embodiment of the present invention, after step S603 in which the electronic device 10 receives the public key 272 from the data storage device 20, step S604 is executed to transmit the public key 272 to the notary institution 300 for registration to bind the public key 272 to the data storage device 20.
[0043] Continuing with step 609, the electronic device 10 uploads the specific data 12 and the digital signature 24 to a cloud 400 or a data verification unit 500. The cloud 400 or the data verification unit 500 can execute a data verification program 70. In the data verification program 70, in step 701, the cloud 400 or the data verification unit 500 obtains the public key 272 bound to the data storage device 20 from the electronic device 10 or the notary institution 300, and uses the public key 272 to decrypt the digital signature 24 to obtain the first hash data 14. In step 703, the cloud 400 or the data verification unit 500 performs a hash calculation on the specific data 12 to generate a second hash data 16. In step 705, the cloud 400 or the data verification unit 500 compares the second hash data 16 with the first hash data 14. If the second hash data 16 is equal to the first hash data 14, in step 707, the cloud 400 or the data verification unit 500 determines that the specific data 12 is an unaltered data; conversely, in step 709, if the second hash data 16 is not equal to the first hash data 14, the cloud 400 or the data verification unit 500 determines that the specific data 12 is an altered data.
[0044] The above is only a preferred embodiment of the present invention and is not used to limit the scope of implementation of the present invention. That is, all equivalent changes and modifications made according to the shape, structure, features and spirit described in the claims of the present invention should be included in the claims of the present invention.
Claims
1. A digitally signable data storage device, characterized in that, it comprises: a controller including a firmware having a private key; a plurality of flash memories; and a data transmission interface, the controller being connected to the flash memories and the data transmission interface, and the data storage device being connected to an electronic device through the data transmission interface; wherein, the electronic device performs a specific operation to generate a specific data, and a first hash data is generated by calculating the specific data using a hash algorithm; wherein, the data storage device receives the first hash data from the electronic device through the data transmission interface, and the firmware of the controller encrypts the first hash data using the private key to generate a digital signature, and the data storage device transmits the digital signature to the electronic device through the data transmission interface; wherein, the firmware of the controller converts the private key into a corresponding public key using an asymmetric encryption algorithm, and the data storage device transmits the public key to the electronic device through the data transmission interface; wherein, the electronic device is a device with networking function, and the electronic device transmits the public key to a notary agency for registration to bind the public key with the data storage device.
2. The data storage device according to claim 1, characterized in that, the firmware reads a non-replicable function to generate the private key according to the non-replicable function.
3. A digitally signable data storage device, characterized in that, it comprises: a controller including a firmware having a private key; a plurality of flash memories; and a data transmission interface, the controller being connected to the flash memories and the data transmission interface, and the data storage device being connected to an electronic device through the data transmission interface; wherein, the electronic device performs a specific operation to generate a specific data; wherein, the data storage device receives the specific data from the electronic device through the data transmission interface, and the firmware of the controller calculates the specific data using a hash algorithm to generate a first hash data, encrypts the first hash data using the private key to generate a digital signature, and the data storage device transmits the digital signature to the electronic device through the data transmission interface; wherein, the firmware of the controller converts the private key into a corresponding public key using an asymmetric encryption algorithm, and the data storage device transmits the public key to the electronic device through the data transmission interface; wherein, the electronic device is a device with networking function, and the electronic device transmits the public key to a notary agency for registration to bind the public key with the data storage device.
4. The data storage device according to claim 3, characterized in that, the firmware reads a non-replicable function to generate the private key according to the non-replicable function.
5. A digital signature system, characterized in that, it comprises: an electronic device that performs a specific operation to generate a specific data, and calculates the specific data using a hash algorithm to generate a first hash data; and a data storage device, comprising: A controller, including a firmware, the firmware having a private key; A plurality of flash memories; and A data transmission interface, the controller being connected to the flash memories and the data transmission interface, the data storage device being connected to the electronic device through the data transmission interface; wherein, the electronic device transmits the first hash data to the data storage device; wherein, the data storage device receives the first hash data from the electronic device through the data transmission interface, and the firmware of the controller encrypts the first hash data using the private key to generate a digital signature, and the data storage device transmits the digital signature to the electronic device through the data transmission interface; Wherein, the firmware of the controller of the data storage device converts the private key into a corresponding public key using an asymmetric encryption algorithm, and transmits the public key to the electronic device; Wherein, the electronic device is a device with networking function, and the electronic device transmits the public key to a notary agency for registration to bind the public key with the data storage device together.
6. The digital signature system according to claim 5, Characterized in that, The electronic device is a device with networking function, the electronic device is network-connected to a blockchain, and the electronic device transmits the specific data and the digital signature to the blockchain to chain the specific data and the digital signature on the blockchain.
7. The digital signature system according to claim 5, Characterized in that, The firmware reads a non-replicable function to generate the private key according to the non-replicable function.
8. The digital signature system according to claim 5, Characterized in that, The digital signature system includes a cloud or a data verification unit, the electronic device is network-connected to the cloud or the data verification unit, and the electronic device transmits the specific data and the digital signature to the cloud or the data verification unit; after receiving the specific data and the digital signature, the cloud or the data verification unit obtains the public key from the notary agency, decrypts the digital signature using the public key to obtain the first hash data, performs a hash calculation on the specific data to generate a second hash data, and compares the second hash data with the first hash data to verify the authenticity of the specific data.
9. A digital signature system, Characterized in that, Including: An electronic device that performs a specific operation to generate specific data; And A data storage device, including: A controller, including a firmware, the firmware having a private key; A plurality of flash memories; and A data transmission interface, the controller is connected to the flash memory and the data transmission interface, and the data storage device is connected to the electronic device through the data transmission interface; wherein, the electronic device transmits the specific data to the data storage device; wherein, the data storage device receives the specific data from the electronic device through the data transmission interface, and the firmware of the controller calculates the specific data using a hash algorithm to generate a first hash data, encrypts the first hash data using the private key to generate a digital signature, and the data storage device transmits the digital signature to the electronic device through the data transmission interface; wherein, the firmware of the controller of the data storage device converts the private key into a corresponding public key using an asymmetric encryption algorithm and transmits the public key to the electronic device; wherein, the electronic device is a device with networking function, and the electronic device transmits the public key to a notary institution for registration to bind the public key with the data storage device.
10. The digital signature system according to claim 9, characterized in that, the electronic device is a device with networking function, the electronic device is network-connected to a blockchain, and the electronic device transmits the specific data and the digital signature to the blockchain to chain the specific data and the digital signature on the blockchain.
11. The digital signature system according to claim 9, characterized in that, the firmware reads a non-replicable function to generate the private key according to the non-replicable function.
12. A digital signature method, characterized in that, the digital signature method is applied to a digital signature system, the digital signature system includes an electronic device and a data storage device, the electronic device performs a specific operation to generate a specific data and calculates the specific data using a hash algorithm to generate a first hash data, the data storage device includes a controller, a plurality of flash memories and a data transmission interface, the controller includes a firmware, and the firmware executes the digital signature method including the following steps: Generate a private key; Receive the first hash data from the electronic device through the data transmission interface; Encrypt the first hash data using the private key to generate a digital signature; and Transmit the digital signature to the electronic device; wherein, the firmware executing the digital signature method further includes: Converting the private key into a corresponding public key using an asymmetric encryption algorithm; and Transmitting the public key to the electronic device; wherein, the electronic device transmits the public key to a notary institution for registration to bind the public key with the data storage device, the digital signature system further includes a cloud or a data verification unit, the electronic device is network-connected to the cloud or the data verification unit, and the cloud or the data verification unit executes a data verification program, and the data verification program includes: Receiving the specific data and the digital signature from the electronic device; Obtaining the public key bound to the data storage device from the notary institution; Decrypt the digital signature using the public key to obtain the first hash data; Perform a hashing operation on the specific data to generate a second hash data; and Compare the second hash data with the first hash data to verify the authenticity of the specific data.
13. The digital signature method according to claim 12, wherein, the step of the firmware generating the private key includes: reading a non-replicable function; and generating the private key according to the non-replicable function.
14. A digital signature method, wherein, the digital signature method is applied to a digital signature system, the digital signature system includes an electronic device and a data storage device, the electronic device performs a specific operation to generate a specific data, the data storage device includes a controller, a plurality of flash memories and a data transmission interface, the controller includes a firmware, and the steps for the firmware to execute the digital signature method include: generating a private key; receiving the specific data from the electronic device through the data transmission interface; calculating the specific data using a hashing algorithm to generate a first hash data; encrypting the first hash data using the private key to generate a digital signature; and transmitting the digital signature to the electronic device; wherein, the steps for the firmware to execute the digital signature method further include: converting the private key into a corresponding public key using an asymmetric encryption algorithm; and transmitting the public key to the electronic device; wherein, the electronic device transmits the public key to a notary agency for registration to bind the public key with the data storage device, the digital signature system further includes a cloud or a data verification unit, the electronic device is network-connected to the cloud or the data verification unit, and the cloud or the data verification unit executes a data verification program, and the data verification program includes: receiving the specific data and the digital signature from the electronic device; obtaining the public key bound to the data storage device from the notary agency; decrypting the digital signature using the public key to obtain the first hash data; performing a hashing operation on the specific data to generate a second hash data; and comparing the second hash data with the first hash data to verify the authenticity of the specific data.
15. The digital signature method according to claim 14, wherein, the step of the firmware generating the private key includes: reading a non-replicable function; and generating the private key according to the non-replicable function.
Citation Information
Patent Citations
Key generation method and device based on PUF and private key storage method
CN109995507A
Block chain private key generation method and device
CN110601853A
Contract signing and verification system based on blockchain
TWM582272U
Cited By
Distributed physical infrastructure data uplink anti-counterfeiting method and system
CN122339691A
Distributed physical infrastructure data chaining anti-counterfeiting method and system
CN122339691B