A Big Data Integrity Protection Method Based on Domestic IBC Cryptography

By building an orderly signature chain and using SM9 encryption system, the problems of big data integrity verification and problem traceability in the cloud computing environment are solved, and the integrity verification and traceability in the big data flow process are realized.

CN115412261BActive Publication Date: 2025-06-17TAIYUAN PENGYUE ELECTRONIC TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211060579.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-31
Publication Date
2025-06-17
Estimated Expiration
2042-08-31

AI Technical Summary

Technical Problem

In the cloud computing environment, the lack of big data integrity verification and problem traceability mechanisms lead to the inability to discover the integrity problems of big data and trace back to which participant the problem came from.

Method used

Using a method based on domestic IBC passwords, the orderly signature chain is constructed, and the SM9 encryption system is initialized. The user obtains the signature key, establishes an orderly signature and signature verification process, verifys the orderly chain signature of multiple users, builds an orderly signature chain, and analyzes the correctness of chain signatures.

Benefits of technology

It realizes the integrity verification and problem traceability of big data during the circulation process, ensuring the integrity and security of the data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115412261B_ABST
    Figure CN115412261B_ABST
Patent Text Reader

Abstract

The present invention belongs to the technical field of big data integrity protection methods, and specifically relates to a big data integrity protection method based on domestic IBC cryptography, including the following steps: initializing the SM9 encryption system; the user obtaining a signature secret key; setting the preconditions for constructing an ordered signature chain; establishing an ordered signature and a signature verification process; verifying the multi-user ordered chain signature; constructing an ordered signature chain; and analyzing the correctness of the chain signature. The present invention establishes a participant and data flow model in the entire life cycle of big data on the cloud. Based on the SM9 standard calculation process, for the data flow process in the big data application scenario on the cloud, an ordered chain signature scheme and a corresponding chain signature verification scheme are designed, the relevant calculation steps in the signature and signature verification processes are improved, and a mechanism capable of effectively verifying the integrity of big data during the transfer process and a traceability mechanism for integrity problems are established.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of big data integrity protection methods, and particularly relates to a big data integrity protection method based on domestic IBC cryptography. Background Art

[0002] In the cloud computing environment, the convenience and openness of cloud services can form a security system centered on business applications, such as identity authentication, unified user management, and digital signatures, to verify the legitimacy of the terminal identity and solve the security problems faced by data secure transmission and access control management in the cloud environment. The life cycle of big data generally includes big data generation, big data distribution / sharing, big data storage, big data processing, and big data owner (protocol generation). Other big data life cycle participants can also be divided according to the actual scenario. In the big data life cycle, the above participants may pose a hazard to the integrity of big data and pass incomplete data to the next participant. Without corresponding integrity verification and problem tracing mechanisms, the integrity problems of big data cannot be discovered and traced back to which participant the problem comes from. Summary of the Invention

[0003] Aiming at the above technical problem that without corresponding integrity verification and problem tracing mechanisms, the integrity problems of big data cannot be discovered, the present invention provides a big data integrity protection method based on domestic IBC cryptography. The participation order of big data participants has a fixed time sequence. Signatures are made in an orderly manner according to this order. By constructing the associated signature and signature verification processes of upper and lower level users, an orderly signature chain is constructed, and the big data integrity verification and problem tracing mechanisms are realized by this signature chain.

[0004] In order to solve the above technical problems, the technical solution adopted by the present invention is as follows:

[0005] A big data integrity protection method based on domestic IBC cryptography, comprising the following steps:

[0006] S1. Initialize the SM9 encryption system;

[0007] S2. The user obtains the signature secret key;

[0008] S3. Set the preconditions for constructing an orderly signature chain;

[0009] S4. Establish an orderly signature and signature verification process;

[0010] S5. Verify the multi-user orderly chain signature;

[0011] S6. Construct an orderly signature chain;

[0012] S7. Analyze the correctness of the chain signature.

[0013] The method for initializing the SM9 encryption system in S1 is as follows: The key generation center KGC first generates a random number k S ∈[1, N - 1] as the signature master private key, and calculates the element P in G2 pub-s =[kS]P2 as the signature master public key, where G2 represents an additive cyclic group of prime order N, obtaining the signature master key pair (k S , P pub-s ). KGC securely stores k S , where k S represents the signature master private key, and publicly discloses P pub-s . KGC selects and publicly discloses the signature private key generation function identifier hid represented by one byte.

[0014] The method for a user to obtain a signature key in S2 is as follows: The identifier of user A is ID A . To generate the signature private key d SA of user A, the key generation center KGC first calculates t1 = H1(ID N ||hid, N) + k A on the finite field F S . If t1 = 0, where hid represents the signature key generation function identifier represented by one byte, then the signature master private key needs to be regenerated, and then the signature master public key P pub-s is calculated and publicly disclosed, and the signature private keys of existing users are updated; otherwise, calculate t2 = k S ·t1 -1 , and finally calculate the signature private key d SA of user A = [t2]P1.

[0015] The method for setting the preconditions for constructing an ordered signature chain in S3 is as follows:

[0016] Trusted signature initiating user: Assume that the first - level user is trusted, that is, it will not damage data integrity, and the large data it passes to the lower - level user is complete, that is, the first - level user is the trusted initiating user;

[0017] Trusted signature center: Set up a trusted signature center to store the signatures of users at all levels that have been verified; during the signature process, user U i obtains the signature of the upper - level user U i-1 from the signature center and performs associated signatures; during signature verification, user U i+1 obtains the signature of U i-1 from the signature center and performs chained signature verification.

[0018] The method for establishing an ordered signature and a signature verification process in S4 is as follows: Define the ordered set of participants in this order as U = {U i}(i = 1, 2, 3, 4, 5), let the message to be signed be the bit string M. To obtain the digital signature of message M, the user U as the signer i performs the following operations:

[0019] S4.1. Calculate the element g = e(P1, P T ) in the group G pub-s , where G T represents a multiplicative cyclic group of prime order N;

[0020] S4.2. Generate a random number r ∈ [1, N - 1]; where N represents the order of the cyclic groups G1, G2, and G T , and N is a prime number greater than 2 191 ;

[0021] S4.3. Calculate the element ω = g T in the group G T , and convert ω to a bit string, where g T represents the T - th power of the element g in the multiplicative group G T ;

[0022] S4.4. There are two cases. If the current signer is the signature initiator U1, then calculate h i = H2(M||ω, N); otherwise, start constructing an ordered signature chain, incorporate the signature of the superior user into the current - level signature calculation, establish the association of two - level signatures to form a chained signature, and perform the following calculation process: h i = H2(M||h i-1 ||S i-1 ||ω, N)(i = 2, 3, 4, 5);

[0023] S4.5. Calculate the integer l = (r - h) mod N. If l = 0, then return to S4.2;

[0024] S4.6. Calculate the element S i = [l]d i in the group G1, where G1 represents an additive cyclic group of prime order N;

[0025] S4.7. Convert both h i and S i to byte strings to form the digital signature (h i , S i ) of message M, where M represents the message to be signed; (h i , S i ) represents the signature sent by the i - th participant;

[0026] S4.8. User U iPut one's own signature into the trusted signature library, and all big data users can read the signatures in the signature library but cannot perform deletion or modification operations.

[0027] The method for verifying the multi-user ordered chain signature in S5 is as follows:

[0028] S5.1. Convert the data type of h i ' to an integer, and check whether h i ' ∈ [1, N - 1] holds. If it does not hold, the verification fails;

[0029] S5.2. Convert the data type of S i ' to a point on the elliptic curve, and check whether S i ' ∈ G1 holds. If it does not hold, the verification fails; (h i ', S i ) represents the signature received by the (i + 1)-th participant;

[0030] S5.3. Calculate the element (h T , S x )g = e(P1, P x ) in the group G pub-s ; P1 represents the generator of the group G1;

[0031] S5.4. Calculate the element t = g T ' in the group G h ;

[0032] S5.5. Calculate h1 = H1(ID i ||hid, N); H1 and H2 represent cryptographic functions derived from cryptographic hash functions;

[0033] S5.6. Calculate the element P = [h1]P2 + P pub-s in the group G2;

[0034] S5.7. Calculate the element u = e(S T ', P) in the group G i ;

[0035] S5.8. Calculate the element ω' = u · t in the group G T , and convert the data type of ω' to a bit string;

[0036] S5.9. There are two cases. If i = 1, calculate the integer h″ i = H2(M'||ω', N); otherwise, calculate the integer h″ i = H2(M'||h i-1 ||S i-1 ||ω', N), and check whether h″ i = hi Whether it holds. If it holds, the verification passes; otherwise, the verification fails. The M' represents the message to be verified.

[0037] Since U i+1 Perform the signature verification of U i When performing the signature verification of U, the known conditions are the public keys IDx and signatures of all superior users U x (x = 1, 2,..., i). Therefore, the user U i+1 Can verify the signature of U i-1 To implement the chain verification mechanism. Therefore, in the chain verification process, S5.9 evolves into the following process:

[0038] If i = 1, directly verify the signature of U i Calculate h″1 = H2(M'||ω', N), and then continue with the subsequent verification steps;

[0039] If i > 1, then do not directly verify the signature of U i Instead, use the data M″ received from U i To verify the signature of U i-1 When i - 1 = 1, h″ i-1 = H2(M″||h1||S1||ω′', N), otherwise, perform the calculation according to the signature verification steps to obtain h″ i-1 = H2(M″||h i-2 ||S i-2 ||ω', N);

[0040] If the user U i Tampered with the data M″, since M″≠M′, so h″ i-1 ≠h = i-1 ;

[0041] Calculate h′ i = H2(M″||h″ i-1 ||S i-1 ||ω', N), it is certain that h′ i ≠h i , and the signature of U i Cannot pass.

[0042] The method for constructing an ordered signature chain in S6 is as follows: According to the signature calculation process, if the signature verification of U2 for U1 passes, then the signature (h1, S1) of U1 is credible. Therefore, (h1, S1) serves as the basis for the credibility of the signature chain;

[0043] Since the first-level signature (h1, S1) is credible, when verifying the second-level signature (h2, S2), directly use (h1, S1) saved in the trusted signature center;

[0044] For the signature (hx , S x The verification of )(x = 3, 4, 5) involves the participation of a superior signature in the calculation process. The superior signature does not use the signature saved by the superior user in the signature center, but is obtained by calculating according to the verification calculation process:

[0045] h″ x-1 = H2(M″ || h x-2 || S x-2 || ω', N) This makes the signature after a user at level x tampers with the data unable to pass the verification;

[0046] In the above way, with the first-level signature as the trusted basis, an ordered signature chain is established.

[0047] The method for analyzing the correctness of the chained signature in S7 is as follows: Let M″ = M′ || h i-1 || S i-1 , regard M″ as the data to be signed, substitute it into the signature and verification process of SM9, then the signature and verification process here completely conform to the calculation process of the SM9 standard; Therefore, the signature and verification process of user U i-1 combined with the signature of U i has correctness.

[0048] Compared with the prior art, the beneficial effects of the present invention are:

[0049] The present invention establishes a model of participants and data flow in the entire life cycle of big data on the cloud. Based on the calculation process of the SM9 standard, for the data flow process in the big data application scenario on the cloud, an ordered chained signature scheme and a corresponding chained signature verification scheme are designed, the relevant calculation steps in the signature and signature verification processes are improved, and a mechanism for effectively verifying the integrity of big data during the flow process and a traceability mechanism for integrity problems are established. BRIEF DESCRIPTION OF THE DRAWINGS

[0050] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only exemplary, and for those of ordinary skill in the art, without creative efforts, other implementation drawings can also be obtained based on the provided drawings.

[0051] The structures, ratios, sizes, etc. illustrated in this specification are only used to match the content disclosed in the specification for those skilled in this technology to understand and read, and are not used to limit the implementation conditions of the present invention. Therefore, they do not have substantial technical significance. Any modification of the structure, change of the proportional relationship, or adjustment of the size, without affecting the effects that the present invention can produce and the purposes that can be achieved, should still fall within the scope covered by the technical content disclosed in the present invention.

[0052] Figure 1 It is the flowchart of the steps of the present invention. Specific implementation manners

[0053] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. These descriptions are only for further explaining the features and advantages of the present invention, rather than limiting the claims of the present invention; based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the scope protected by the present application.

[0054] The following will further describe in detail the specific implementation manners of the present invention in conjunction with the accompanying drawings and embodiments. The following embodiments are used to illustrate the present invention, but are not used to limit the scope of the present invention.

[0055] In GM / T 0044.2-2016 SM9 Identity-Based Cryptography Algorithm - Part 2: Digital Signature Algorithm, it stipulates the implementation of the identity-based digital signature algorithm using elliptic curves.

[0056] In this standard, it is stipulated that the Key Generate Center (KGC) is a trusted institution responsible for selecting system parameters, generating the signature master key, and generating the user signature private key.

[0057] I. Initialization of the SM9 Encryption System

[0058] In the starting stage of the SM9 cryptographic system, the cryptographic system parameters and the master key pair are first generated.

[0059] The KGC first generates a random number k S ∈ [1, N - 1] as the signature master private key, and calculates the element P in G2 pub-s =[k S P2 as the signature master public key, obtaining the signature master key pair (k S , P pub-s ). The KGC securely stores k S , and publishes P pub-s. The KGC selects and discloses the signature private key generation function identifier hid represented by one byte.

[0060] II. User obtains the signature secret key

[0061] The identifier of user A is ID A , to generate the signature private key d of user A SA , the KGC first calculates t1 = H1(ID N ||hid, N) + k A on the finite field F S . If t1 = 0, the signature master private key needs to be regenerated, and then the signature master public key P pub-s is calculated and disclosed, and the signature private keys of existing users are updated; otherwise, calculate t2 = k S ·t1 -1 , and finally calculate the signature private key d of user A SA = [t2]P1.

[0062] III. Prerequisites for constructing an ordered signature chain

[0063] Trusted signature initiating user: Assume that the first-level user (i.e., the data producer) is trusted, that is, it will not damage the data integrity, and the big data it passes to the lower-level users is complete. That is, the first-level user is the trusted initiating user.

[0064] Trusted signature center: Set up a trusted signature center to save the signatures of users at all levels that have been verified. During the signature process, user U i obtains the signature of the upper-level user U i-1 from the signature center and performs associated signatures; during signature verification, user U i+1 obtains the signature of Ui-1 from the signature center and performs chained signature verification.

[0065] Under the above premise, establish an ordered signature and signature verification process.

[0066] IV. Multi-user ordered chained signature process

[0067] According to the definition of multi-party participants in the big data life cycle and the transfer process of big data in the life cycle, perform an ordered multi-party digital signature on the big data. The order of the ordered multi-party signature is: big data producer, data sharing coordination agency, big data cloud storage provider, big data processing module provider, and big data owner. Define the ordered set of participants as U = {U i} (i = 1, 2, 3, 4, 5).

[0068] Let the message to be signed be the bit string M. To obtain the digital signature of the message M, as the signer, user U i performs the following operations:

[0069] Step 1: Calculate G T The element g = e(P1, P pub-s ) in it;

[0070] Step 2: Generate a random number r ∈ [1, N - 1];

[0071] Step 3: Calculate the element ω = g T in the group G T , and convert ω into a bit string;

[0072] Step 4: There are two cases. If the current signer is the signature initiator U1, then calculate

[0073] h i = H2(M || ω, N);

[0074] Otherwise, start building an ordered signature chain, incorporate the signature of the superior user into the current signature calculation, establish the association of two - level signatures, and form a chained signature. Execute the following calculation process:

[0075] h i = H2(M || h i-1 || S i-1 || ω, N) (i = 2, 3, 4, 5);

[0076] Step 5: Calculate the integer l = (r - h) mod N. If l = 0, then return to Step 2;

[0077] Step 6: Calculate the element S i = [l]d i ;

[0078] Step 7: Convert both h i and S i into byte strings to form the digital signature (h i , S i ) of the message M.

[0079] Step 8: User U i puts his own signature into the trusted signature library. All big - data users can read the signatures in this signature library, but cannot perform deletion or modification operations.

[0080] V. Multi - user Ordered Chained Signature Verification Process

[0081] To verify the received message M' and its digital signature (h i ', S i '), as the verifier, user U i+1 performs the following operation steps.

[0082] Step 1: Convert h i'Convert the data type to an integer and check h i '∈[1,N - 1] holds. If not, the verification fails;

[0083] Step 2: Convert the data type of S i ' to a point on the elliptic curve and check if S i '∈G1 holds. If not, the verification fails.

[0084] Step 3: Calculate the element g = e(P1, P T in group G of (h x , S x ); pub-s )

[0085] Step 4: Calculate the element t = g T in group G h ';

[0086] Step 5: Calculate h1 = H1(ID i ||hid, N);

[0087] Step 6: Calculate the element P = [h1]P2 + P pub-s in group G2;

[0088] Step 7: Calculate the element u = e(S T ', P) in group G i ;

[0089] Step 8: Calculate the element ω' = u·t in group G T and convert the data type of ω' to a bit string;

[0090] Step 9: In two cases, if i = 1, calculate the integer h″ i = H2(M'||ω', N); otherwise, calculate the integer h″ i = H2(M'||h i-1 ||S i-1 ||ω', N)

[0091] Check if h″ i = h i ' holds. If so, the verification passes; otherwise, the verification fails.

[0092] The above signature calculation process is the verification process in the general single - user mode. In the multi - user environment of the big data platform, the above signature verification has deficiencies and cannot achieve effective verification of ordered multi - signatures and traceability of data integrity issues.

[0093] After the above signature verification calculation process, if the signature verification passes, it proves that the data is from user U isigned and the data has not been tampered with by a third party, but it cannot be proven that the data has not been tampered with by user U i tampered with, because if user U i tampered with the data and then signed it, and then passed the signature and the tampered data to user U i+1 , user U i 's signature can still pass the verification after U i+1 executes this verification process.

[0094] Corresponding to the above multi-user ordered signature process, to verify whether the data has been tampered with when passing through user U i and to trace the source of the data integrity problem, the following ordered signature chain verification process needs to be executed:

[0095] Since when performing the signature verification of U i+1 , the known conditions are the public key IDs and signatures of all superior users U i (x = 1, 2,... i), so user U x can verify the signature of U i+1 and implement a chain verification mechanism. Therefore, in the chain verification process, step nine evolves into the following process. i-1

[0096] Step nine: If i = 1, directly verify the signature of U i , calculate h″1 = H2(M'||ω', N), and then continue with the subsequent verification steps.

[0097] If i > 1, then do not directly verify the signature of U i , but use the data M″ received from U i to verify the signature of U i-1 . When i - 1 = 1,

[0098] h″ i-1 = H2(M″||h1||S1||ω', N),

[0099] Otherwise, perform the calculation according to the signature verification steps to get h″ i-1 = H2(M″||h i-2 ||S i-2 ||ω', N).

[0100] If user U i tampered with the data M″, since M″≠M′, so h″ i-1 ≠h′ i-1 . Calculate

[0101] h′ i = H2(M″||h″ i-1 ||S i-1 ||ω', N), and it is certain that h′​i ≠h i ,U i The signature cannot pass.

[0102] Therefore, the above chain signature verification process can verify the tampering of user U i on M'. Similarly, if intermediate users U2, U3, U4 tamper with the data, it can be verified during the chain signature verification process, and it can be determined which user tampered with the data.

[0103] VI. Construction of Ordered Signature Chain

[0104] Since it is assumed that the data M of data producer U1 is trustworthy and there is no signature of the superior user participating in the calculation, there will be no forged signature either. Therefore, according to the signature calculation process, if the signature verification of U1 by U2 passes, then the signature (h1, S1) of U1 is trustworthy. Therefore, (h1, S1) serves as the basis for the trustworthiness of the signature chain.

[0105] Since the first-level signature (h1, S1) is trustworthy, the verification of the second-level signature (h2, S2) directly uses (h1, S1) saved in the trusted signature center.

[0106] For the verification of the signature (h x , S x )(x = 3, 4, 5), the calculation process involves the participation of the superior signature, and the superior signature does not use the signature saved by the superior user in the signature center, but is calculated according to the verification calculation process:

[0107] h″ x-1 = H2(M″||h x-2 ||S x-2 ||ω', N) This makes the signature after the x-level user tampers with the data unable to pass the verification.

[0108] In the above way, with the first-level signature as the trusted basis, an ordered signature chain is established.

[0109] Establishing this ordered signature chain serves the purpose of preventing data tampering and forged signatures.

[0110] VII. Correctness Analysis of Chain Signature

[0111] Let M″ = M′||h i-1 ||S i-1 , regard M″ as the data to be signed, and substitute it into the signature and verification process of SM9. Then the signature and verification process here completely conforms to the calculation process of the SM9 standard. Therefore, the signature and verification process of user U i-1 combined with the signature of U i has correctness.

[0112] The above only describes in detail the preferred embodiments of the present invention. However, the present invention is not limited to the above embodiments. Within the scope of knowledge possessed by those of ordinary skill in the art, various changes can be made without departing from the gist of the present invention, and all such changes should be included within the scope of protection of the present invention.

Claims

1. A method for protecting the integrity of big data based on domestic IBC cryptography, characterized in that: It includes the following steps: S1. Initialize the SM9 encryption system; S2. The user obtains the signature key; S3. Set the preconditions for constructing an ordered signature chain; S4. Establish an ordered signature and signature verification process; define the ordered set of participants as U = {U i}(i = 1, 2, 3, 4, 5) in this order. Let the message to be signed be the bit string M. To obtain the digital signature of message M, the user U i as the signer performs the following operations: S4.

1. Calculate the group G T The element g = e(P1, P pub-s ) in it, where G T represents a multiplicative cyclic group of prime order N, P1 represents the generator of the group G1, and P pub-s represents the signature public key; S4.

2. Generate a random number r ∈ [1, N - 1]; where N represents the order of the cyclic groups G1, G2, and G T and N is a prime number greater than 2 191 , and r represents a random number within [1, N - 1]; S4.

3. Calculate the group G T for the element ω = g T in it, and convert ω into a bit string, where g T represents the T-th power of the element g in the multiplicative group G T ; S4.

4. In two cases, if the current signer is the signature initiator U1, then calculate h i = H2(M||ω, N); otherwise, start constructing an ordered signature chain, incorporate the signature of the superior user into the current signature calculation, establish the association of two-level signatures to form a chained signature, and execute the following calculation process: h i = H2(M||h i-1 ||S i-1 ||ω, N) (i = 2, 3, 4, 5); S4.

5. Calculate the integer l = (r - h i ) mod N. If l = 0, then return to S4.2; S4.

6. Calculate the element S in group G1 i = [l]d i , where the d i represents the signature private key of participant U i , and G1 represents an additive cyclic group of prime order N; S4.

7. Convert h i and S i both into byte strings to form the digital signature of message M (h i , S i ); the (h i , S i ) represents the signature sent by the i-th participant; the M is the message to be signed; S4.8, User U i Put their own signature into the trusted signature library. All big data users can read the signatures in this library, but cannot perform deletion or modification operations; S5. Verify the multi-user ordered chain signature; S5.

1. Convert the data type of h i ' to an integer, and check whether h i ' ∈ [1, N - 1] holds. If not, the verification fails; S5.

2. Convert the data type of S i ' into a point on the elliptic curve, and check whether S i ' ∈ G1 holds. If it does not hold, the verification fails; the (h i ', S i ) represents the signature received by the (i + 1)-th participant; S5.3, Calculate the group G T The elements (h x , S x ) g = e(P1, P pub-s ); S5.4, Calculate the group G T The element t = g in h' ; S5.

5. Calculate h1 = H1(ID i ||hid,N); where H1 and H2 represent cryptographic functions derived from cryptographic hash functions; S5.

6. Calculate the element P = [h1]P2 + P in the group G2 pub-s ; S5.

7. Calculate the element u = e(S T ', P) in the group G i ; S5.8, Calculate the element ω' = u · t in group G and convert the data type of ω' into a bit string; T ​ S5.

9. In two cases, if i = 1, calculate the integer h″ i = H2(M'||ω', N); otherwise, calculate the integer h″ i = H2(M'||h i-1 ||S i-1 ||ω', N), and check whether h″ i = h i ' holds. If it holds, the verification passes; otherwise, the verification fails. The M' represents the message to be verified; Since U i+1 Perform the U i When performing signature verification of U, the known conditions are the public key IDx and signatures of all superior users U x (x = 1, 2,... i), so the user U i+1 Can verify the signature of U i-1 To implement a chain verification mechanism; therefore, during the chain verification process, S5.9 evolves into the following process: If i = 1, directly verify the signature of U i , calculate h″1 = H2(M'||ω', N), and then continue with the subsequent verification steps; If i > 1, then directly verify U i signature, but use the data M″ received from U i to verify the signature of U i-1 When i - 1 = 1, h″ i-1 = H2(M″||h1||S1||ω', N), otherwise, perform calculations according to the signature verification steps to obtain h″ i-1 = H2(M″||h i-2 ||S i-2 ||ω', N); If user U i tampered with data M″, since M″≠M′, so h″ i-1 ≠h′ i-1 ; Calculate h′ i = H2(M″||h″ i-1 ||S i-1 ||ω',N), necessarily h′ i ≠h i ,U i The signature cannot pass; S6. Construct an ordered signature chain; S7. Analyze the correctness of the chain signature.

2. The method for protecting the integrity of big data based on domestic IBC cryptography according to claim 1, characterized in that: The method for initializing the SM9 encryption system in S1 is as follows: The key generation center KGC first generates a random number k S ∈ [1, N - 1] as the signature master private key, and calculates the element P in G2 pub-s =[k S P2 as the signature master public key, where G2 represents an additive cyclic group of order prime number N; N represents the order of cyclic groups G1, G2, and G T and is a prime number greater than 2 191 ; P2 is the generator of group G2. Obtain the signature master key pair (k S , P pub-s ), and the KGC securely stores k S , where k S represents the signature master private key, and P pub-s is made public. The KGC selects and makes public the signature private key generation function identifier hid represented by one byte.

3. The method for protecting the integrity of big data based on domestic IBC cryptography according to claim 2, characterized in that: The method for the user to obtain the signature key in S2 is as follows: The identifier of user A is ID A , to generate the signature private key of user A The key generation center KGC first calculates t1 = H1(ID N ||hid, N)+k A on the finite field F S . If t1 = 0, where hid represents the signature key generation function identifier represented by one byte, then the signature master private key needs to be regenerated, and then the signature master public key P pub-s is calculated and publicly disclosed, and the signature private keys of existing users are updated; otherwise, calculate t2 = k S ·t1 -1 . Finally, calculate the signature private key of user A Where: H1 and H2 are cryptographic functions derived from cryptographic hash functions respectively.

4. The method for protecting the integrity of big data based on domestic IBC cryptography according to claim 1, characterized in that:The method for setting the preconditions for constructing an ordered signature chain in S3 is as follows: Trusted signature initiating user: Assume that the first-level user is trusted, that is, it will not damage data integrity, and the large data it passes to the lower-level user is complete, that is, the first-level user is used as the trusted initiating user; Trusted Signature Center: Set up a trusted signature center to store the signatures of users at all levels that have been verified; during the signature process, user U i obtains the signature of the superior user U i-1 from the signature center and conducts associated signatures; during signature verification, user U i+1 obtains the signature of U i-1 from the signature center and conducts chained signature verification.

5. A method for protecting the integrity of big data based on domestic IBC cipher according to claim 1, characterized in that: The method for constructing an ordered signature chain in S6 is as follows: According to the signature calculation process, if the signature of U2 on U1 is verified successfully, then the signature (h1, S1) of U1 is trusted. Therefore, (h1, S1) serves as the basis for the trust of the signature chain; Since the first-level signature (h1, S1) is trusted, the verification of the second-level signature (h2, S2) directly uses (h1, S1) saved in the trusted signature center; For the verification of signature (h x , S x )(x = 3, 4, 5), the calculation process involves the participation of the superior signature. The superior signature does not use the signature saved by the superior user in the signature center, but is obtained by calculating according to the verification calculation process: h″ x-1 = H2(M″||h x-2 ||S x-2 ||ω',N) so that the signature after the x-level user tampers with the data cannot pass the verification; In the above way, an ordered signature chain is established with the first-level signature as the trusted basis.

6. A method for protecting the integrity of big data based on domestic IBC cipher according to claim 5, characterized in that: The method for analyzing the correctness of the chain signature in S7 is as follows: Let M″ = M′||h i-1 ||S i-1 , regard M″ as the data to be signed, substitute it into the signature and verification processes of SM9, then the signature and verification processes here fully conform to the calculation processes of the SM9 standard; therefore, the signature and verification processes of user U i-1 combined with the signature of U i have correctness.

Citation Information

Patent Citations

  • Safe and efficient SM9 ring signature generation and verification method

    CN110880977A

  • Auditable privacy protection authentication method based on national SM9 cryptographic algorithm

    CN113612615A