A method and system for issuing digital assets
Through the generation of three-party quantum digital signatures and one-time CA certificates, the problem of insecure of the public and private key cryptography system during the issuance of digital assets is solved, and quantum-safe digital asset issuance is achieved.
Patent Information
- Application Number
- CN202310262386.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-03-17
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2043-03-17
AI Technical Summary
The existing public-private key cryptography system is no longer secure when facing quantum computers, resulting in a security threat to digital assets during issuance.
The method of three-party quantum digital signature is adopted to conduct quantum digital signatures of signature files between applicants, CA certification centers and digital asset issuance centers, generate a one-time CA certificate, and ensure that the summary of the digital asset is not tampered with during the issuance process through message authentication codes.
It improves the security level of the digital asset issuance process, ensures the value of digital assets in the issuance process and the rights and interests of digital asset owners, and solves the threat of quantum computers to traditional cryptography.
Smart Images

Figure CN116192409B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of quantum information security, and particularly to a method and system for issuing digital assets. Background Art
[0002] In the current market environment, users often possess some valuable things, and digital assets are one of them. Digital assets refer to non-monetary assets that are owned or controlled by an enterprise or an individual, exist in the form of electronic data, and are held for sale or in the production process in daily activities. Due to the nature of assets, digital assets have a certain value. In order to realize the monetization of such digital assets, digital asset owners will seek professional issuing institutions to put the owned digital assets into the market through the issuance method, thereby realizing monetization.
[0003] However, different from physical assets, due to the electronic characteristics of digital assets, the marginal cost of copying them is almost zero and they can be copied almost infinitely. In this way, if digital assets are leaked or stolen during the issuance process, the value of digital assets will be reduced, seriously damaging the rights and interests of digital asset owners.
[0004] Currently, digital certificates, digital signatures, etc. are commonly used in the market to ensure the security of the digital asset issuance process. However, with the progress of computing power and algorithms, especially the progress of quantum computing technology, traditional CA certificates, digital signatures, etc. based on the public-private key cryptosystem have become insecure. This means that in the face of quantum computers, network communications using traditional cryptography, such as the digital asset issuance process, will face serious security threats.
[0005] To solve the above security threats, there is an urgent need for a cryptographic means that meets information-theoretic security or quantum security to solve the security problem of the digital asset issuance process. Summary of the Invention
[0006] Object of the Invention: The object of the present invention is to provide a method and system for issuing digital assets. This method can be applied in the digital asset issuance process, solves the security threat problem suffered by the existing public-private key cryptosystem, and ensures that the security level of this issuance process can be improved to the quantum security level.
[0007] Technical Solution: The present invention provides a method for issuing digital assets, and this method includes the following steps:
[0008] (1) The applicant sends a request req to obtain digital asset M to the digital asset issuance center and generates a signature file sign. A three-party quantum digital signature is performed on the signature file sign among the CA certification center, the digital asset issuance center, and the applicant. Among them, the applicant is the signing party, and the CA certification center and the digital asset issuance center are the signature verification parties;
[0009] (2) The digital asset issuance center extracts the corresponding digital asset M according to the received request req and generates a one-time CA certificate otCA' with the CA certification center;
[0010] (3) The digital asset issuance center generates a digital asset digest M' and sends the digital asset digest M' to the applicant in the manner of a message authentication code;
[0011] (4) The applicant sends the received digital asset digest M' to the CA certification center for review and sends the review result to the digital asset issuance center;
[0012] (5) After receiving the applicant's review result, in response to the review result being passed, the digital asset issuance center registers the digitally issued asset M as issued in the digital asset database.
[0013] Further, the digital asset M is stored by the digital asset owner in the digital asset issuance center.
[0014] The present invention also proposes a digital asset issuance system, which includes: a digital asset issuance center, an applicant, and a CA certification center; among them, the digital asset issuance center, the applicant, and the CA certification center are connected pairwise for performing the issuance process of the digital asset M.
[0015] Further, the digital asset issuance system further includes a digital asset owner who owns the digital asset M, and the digital asset owner is connected to the digital asset issuance center for storing the digital asset M in the digital asset issuance center.
[0016] The beneficial effects of the present invention: By proposing a digital asset issuance method and system according to the present invention, the digital asset owner can issue the digital assets he owns in a quantum-safe manner, solving the security threats posed by the progress of computing power and algorithms to the issuance process, and improving the issuance process to the quantum-safe level, thus ensuring the value of digital assets during the issuance process and protecting the rights and interests of digital asset owners. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] Figure 1 It is a schematic diagram of a digital asset issuance system of the present invention;
[0018] Figure 2 Schematic diagram of another digital asset issuance system of the present invention;
[0019] Figure 3 Process schematic diagram of the digital asset issuance method of the present invention. Detailed implementation manners
[0020] The present invention will be further described below with reference to the accompanying drawings and embodiments.
[0021] The present invention provides a digital asset issuance method and system, and this method can be applied to the digital asset issuance scenarios introduced in the background art. The technical solution of the present invention will be specifically described below.
[0022] As Figure 1 shown, in some embodiments, the issuance system in the present invention may include a digital asset issuance center, an applicant, and a CA certification center. The digital asset issuance center, the applicant, and the CA certification center are connected pairwise and are used to execute the digital asset issuance process. Among them, the applicant can be an enterprise, institution, or individual with a demand for the issued digital asset. As Figure 2 shown, in some other embodiments, the issuance system in the present invention may further include a digital asset owner. The digital asset owner is connected to the digital asset issuance center and is used to store the owned digital assets in the digital asset issuance center. All the participating parties in the system are connected to the quantum security network. With the help of the quantum security network, any two parties can generate a session key according to the requirements of the communication task, that is, the quantum random number shared by both parties according to the communication requirements, which is used for cryptographic tasks such as quantum-secure encryption and decryption, message authentication, and digital signature, thereby enhancing the cryptography in the digital asset issuance to the quantum security level.
[0023] As Figure 2 shown, the present invention provides a digital asset issuance method, including the following steps.
[0024] 1. The applicant sends a request req to obtain digital asset M to the digital asset issuance center and generates a signature file sign. A three-party quantum digital signature is performed on the signature file sign among the CA certification center, the digital asset issuance center, and the applicant, where the applicant is the signing party and the CA certification center and the digital asset issuance center are the signature verification parties. When both the CA certification center and the digital asset issuance center pass the signature verification, it indicates that the applicant's identity is legal, and the next step is entered; otherwise, if the signature verification fails, this issuance process ends.
[0025] Among them, the process of generating the signature file sign includes:
[0026] (1) The digital asset issuance center applies for its public CA certificate from the CA certification center and privacy CA certificates The applicant applies for its public CA certificate from the CA certification center and privacy CA certificates Subsequently, the applicant and the CA certification center generate a one-time CA certificate otCA;
[0027] In the present invention, the digital asset issuance center and the applicant apply for and store their respective public CA certificates and privacy CA certificates from the CA certification center. The CA certification center can be the CA certification center in the "Digital Certificate Generation, Identity Authentication Method, and Quantum CA Certification Center and System" with the application number 2022101851462. Using the method in this patent, the public CA certificates and privacy CA certificates are distributed to the digital asset issuance center and the applicant respectively. The public CA certificate is generated based on the provided real identity information. As an example, it can include the name or unit name (and its domain name, if it is a network service operator), the certificate number (which needs to be unique throughout the network), the certificate issuing authority and its domain name or IP address, the certificate validity period, and other information that can be shown to the public; the privacy CA certificate consists of the public CA certificate, the timestamp timestamp2 for generating the CA certificate, and the quantum random number QRN. The privacy of the privacy CA certificate is guaranteed by the privacy of the quantum random number QRN.
[0028] After the application is completed, the CA certification center stores the public CA certificates and privacy CA certificates of the digital asset issuance center and the applicant.
[0029] Among them, the specific process for the applicant and the CA certification center to generate the one-time CA certificate otCA is as follows:
[0030] 1) The applicant obtains a set of n-bit random numbers s from the local 1 , and the n-bit random numbers s 1 are used to generate an nth-degree irreducible polynomial p(x), and then the n-bit string composed of the coefficients of each term except the highest term in the irreducible polynomial is denoted as str1;
[0031] Among them, the specific process for the n-bit random numbers s 1 to generate the nth-degree irreducible polynomial p(x) is as follows:
[0032] a) First, the applicant successively uses each bit of the n-bit random numbers s 1 to correspond to the coefficients of each term except the highest term in the polynomial, generating an nth-degree polynomial in the GF(2) field, and the coefficient of the highest term is 1; for example, if the random numbers are n bits (a n-1 , a n-2 , …, a 1 , a 0 ), then the generated polynomial is p(x) = x n + a n-1x n-1 +…+a 1 x + a 0 ; Preferably, only when a 0 = 1, the generated polynomial may be an irreducible polynomial. Therefore, to reduce the computational complexity in verifying the irreducible polynomial later, the random number can be judged first: if the last digit of the random number is 0, then set the last digit of the random number to 1; or if the last digit of the random number is 0, then regenerate the random number until the last digit of the generated random number is 1; this can reduce the computational complexity in verifying the irreducible polynomial later, and finally make a 0 = 1, and the generated polynomial is p(x) = x n + a n-1 x n-1 +…+ a 1 x + 1;
[0033] b) Then, verify whether this polynomial is an irreducible polynomial. If the verification result is "no", the applicant regenerates another set of random numbers, and uses the regenerated set of random numbers as the new random number to return to step a) to regenerate the polynomial and verify; if the verification result is "yes", then stop the verification, and the applicant obtains the irreducible polynomial p(x).
[0034] There are multiple methods to verify the irreducible polynomial here. Preferably, we use the two methods mentioned in the present invention:
[0035] Method A: Verify in turn whether holds, where means taking the integer part of . If the verification passes for all i, then p(x) is an nth-order irreducible polynomial over GF(2); where gcd(f(x), g(x)) represents the greatest common divisor of f(x) and g(x) over GF(2), and f(x) and g(x) refer to two arbitrary polynomials.
[0036] Method B: Verify whether the conditions (1) (2) hold simultaneously, where means has the same remainder as x mod p(x), d is any prime factor of n, gcd(f(x), g(x)) represents the greatest common divisor of f(x) and g(x) over GF(2), and f(x) and g(x) refer to two arbitrary polynomials. When both of these verification conditions are satisfied, then p(x) is an nth-order irreducible polynomial over GF(2).
[0037] Generally, take n = 2 k , so in condition (2), only d = 2 needs to be taken. Optionally, take n = 27 = 128. Since this method only needs to verify these two conditions, we use the Fast modular composition (FMC) algorithm to quickly obtain and Use Replace in condition (2) and perform calculations. By reducing the order, we can obtain the calculation result faster.
[0038] 2) The applicant and the CA certification center share three groups of quantum keys s 2 , u, and v, where the lengths of s 2 , u, and v are all n; the applicant selects an n - degree irreducible polynomial p(x) and the shared key s 2 as the input random number to obtain a hash function based on a linear feedback shift register Then use this hash function to calculate the hash value of the applicant's private CA certificate , denoted as Subsequently, encrypt using the shared key u. The encryption is performed using the XOR operation to obtain which is the one - time CA certificate otCA. The applicant stores this one - time CA certificate otCA;
[0039] This invention involves hash value calculations in many places. To avoid hash collision problems caused by choosing other hash functions, the hash value calculations of this invention are performed using a hash function based on a linear shift register, preferably the Toeplitz hash function based on a linear shift register. This hash function is generated by an n - degree irreducible polynomial over the GF(2) field and quantum random numbers.
[0040] 3) The applicant encrypts the string str1 using the shared key v. The encryption is performed using the XOR operation to obtain v⊕str1, and then sends the encrypted result v⊕str1 to the CA certification center;
[0041] 4) After receiving it, the CA certification center decrypts the encrypted result using the shared key v to obtain the same string str1 as the applicant. The CA certification center successively uses the coefficients of each term of str1 corresponding to each term except the highest - order term in the polynomial to generate an n - degree irreducible polynomial p(x) with the highest - order coefficient of 1 over the GF(2) field. Then it selects this irreducible polynomial p(x) and the shared key string s 2 as the input random number to generate the same hash function based on a linear feedback shift register as the applicant Use the hash function to calculate the hash value of the applicant's private CA certificate reserved in the CA certification center, denoted as Subsequently, the CA certification center encrypts using the shared key u The encryption is performed using the exclusive OR operation to obtain which is the one-time CA certificate otCA. The CA certification center stores this one-time CA certificate otCA
[0042] The CA certification center can set the certificate validity period for the one-time CA certificate otCA issued this time. If the validity period is exceeded, the one-time CA certificate will be invalidated
[0043] (2) The applicant uses the one-time CA certificate otCA and the public CA certificate and the request req to generate the signature file sign, that is
[0044]
[0045] The process of performing a three-party quantum digital signature on the signature file sign among the CA certification center, the digital asset issuance center, and the applicant includes
[0046] S1. The applicant obtains a random number from the local to generate an irreducible polynomial l(x), and then records the string composed of the coefficients of each term except the highest term in the irreducible polynomial l(x) as str2; the method of generating the irreducible polynomial l(x) is the same as the above method of generating the irreducible polynomial, and will not be repeated here
[0047] S2. The applicant and the CA certification center perform key negotiation to obtain the shared keys w 1 , x 1 and y 1 , where the lengths of w 1 , x 1 and y 1 are all n; the applicant and the digital asset issuance center perform key negotiation to obtain the shared keys w 2 , x 2 and y 2 , where the lengths of w 2 , x 2 and y 2 are all n; the applicant performs the exclusive OR operation on the possessed keys w 1 , x 1 , y 1 , w 2 , x 2 and y 2 to obtain the keys w 3 , x 3 and y 3 , as follows
[0048] w 3 = w 1 ⊕ w 2
[0049] x 3 = x 1 ⊕ x 2
[0050] y 3 = y 1 ⊕ y 2 ;
[0051] S3. The applicant selects an irreducible polynomial l(x) and the key x as the input random number 3 Generate a hash function Use the hash function Perform a hash operation on the signature file sign to obtain a hash value Subsequently, the applicant uses the key w 3 and the key y 3 respectively encrypt the hash value and the string str2 to obtain a signed message:
[0052]
[0053] The applicant transmits the signed message to the digital asset issuance center;
[0054] S4. After receiving the signed message, the digital asset issuance center sends the signed message and the keys w 2 , x 2 and y 2 it owns together to the CA certification center. The CA certification center sends the keys w 1 , x 1 and y 1 it owns together to the digital asset issuance center. The information exchange between the two parties is carried out through an authenticated channel to prevent tampering. At this time, both the CA certification center and the digital asset issuance center have the keys w 1 , x 1 , y 1 , w 2 , x 2 , y 2 and the signed message;
[0055] S5. The digital asset issuance center performs an exclusive OR operation on the keys w 1 , x 1 , y 1 , w 2 , x 2 and y 2 it owns to obtain the keys w 3 ′, x 3 ′ and y 3 ′, where:
[0056] w3 ' = w 1 ⊕ w 2
[0057] x 3 ' = x 1 ⊕ x 2
[0058] y 3 ' = y 1 ⊕ y 2 ;
[0059] The digital asset issuance center uses the key w' 3 to decrypt the in the signed message and obtains Then it uses the key y 3 ' to decrypt str2 ⊕ y in the signed message 3 and obtains the string str2. Then the digital asset issuance center uses the coefficients of each term of the polynomial except the highest term corresponding to each bit of the string str2 to generate an irreducible polynomial l'(x) with the highest term coefficient of 1, selects the irreducible polynomial l'(x) and the key x 3 ' as the input random number to generate a hash function Uses the hash function to perform a hash operation on sign in the signed message and obtains a hash value Compares the calculated hash value with the obtained by decryption. If they are equal, the signature verification passes; otherwise, the signature verification fails;
[0060] S6. The CA certification center performs an exclusive OR operation on the keys w 1 , x 1 , y 1 , w 2 , x 2 and y 2 and obtains the keys w 3 '', x 3 '' and y 3 '', where:
[0061] w 3 '' = w 1 ⊕ w 2
[0062] x 3 '' = x 1 ⊕ x 2
[0063] y 3 '' = y 1 ⊕ y 2 ;
[0064] The CA certification center uses the key w 3 ″ to decrypt in the signed message, and obtains Then use the key y 3 ″ to decrypt str2⊕y in the signed message 3 to obtain the string str2′. Then, the CA certification center uses the coefficients of each term of the polynomial except the highest term corresponding to each bit of the string str2′ to generate an irreducible polynomial l″(x) with the highest term coefficient of 1, and selects this irreducible polynomial l″(x) and the key x as the input random number 3 ″ to generate a hash function Use the hash function to perform a hash operation on sign in the signed message to obtain a hash value Compare the calculated hash value with the decrypted to see if they are equal. If they are equal, the comparison passes; otherwise, the comparison fails;
[0065] At the same time, the CA certification center compares otCA in sign in the signed message with the one-time CA certificate otCA generated by the CA certification center. If they are equal, the comparison passes; otherwise, the comparison fails;
[0066] The CA certification center passes the signature verification only when both comparisons pass; otherwise, the signature verification fails;
[0067] S7. When both the digital asset issuance center and the CA certification center pass the signature verification, it indicates that the applicant's identity is legal, and proceed to the next step; otherwise, the signature verification fails, indicating that the applicant's identity is illegal and cannot obtain the digital asset M, and end this issuance process.
[0068] 2. The digital asset issuance center extracts the corresponding digital asset M according to the received request req, assigns a business number SN for this issuance process, and generates a one-time CA certificate otCA′ with the CA certification center. The digital asset issuance center sends the business number SN to the CA certification center, and the CA certification center saves the business number and establishes a corresponding relationship between the business number SN and the stored one-time CA certificate otCA′. Among them, the digital asset issuance center can extract the digital asset M from its own digital asset database. The digital asset issuance center can set up an issuance business table, which can include the mapping relationship between the business number SN and the one-time CA certificate otCA′ saved by the digital asset issuance center, as well as certificate information such as the validity period of the one-time CA certificate otCA′.
[0069] Among them, the specific process of the digital asset issuance center and the CA certification center generating the one-time CA certificate otCA′ is as follows:
[0070] A1: The digital asset issuance center obtains and selects a group of n-bit random numbers k locally 1 , the n-bit random number k 1 is used to generate an nth-degree irreducible polynomial q(x), and the n-bit string formed by the coefficients of each term except the highest term in the irreducible polynomial is denoted as str3;
[0071] A2: The digital asset issuance center shares three groups of quantum keys k 2 , i, and j with the CA certification center, where the lengths of k 2 , i, and j are all n; the digital asset issuance center selects the nth-degree irreducible polynomial q(x) and the shared key k 2 as the input random number to obtain a hash function based on a linear feedback shift register Then use this hash function to calculate the hash value of the privacy CA certificate of the digital asset issuance center , denoted as Subsequently, encrypt using the shared key i. The encryption uses the exclusive OR operation to obtain which is the one-time CA certificate otCA′. The digital asset issuance center stores this one-time CA certificate otCA′;
[0072] A3: The digital asset issuance center encrypts the string str3 using the shared key j. The encryption uses the exclusive OR operation to obtain j⊕str3, and then sends the encrypted result j⊕str3 to the CA certification center;
[0073] A4: After receiving it, the CA certification center decrypts the encrypted result using the shared key j to obtain the same string str3 as the digital asset issuance center. The CA certification center successively uses each bit of the string str3 as the coefficient of each term except the highest term in the corresponding polynomial to generate an nth-degree irreducible polynomial q(x) with the highest-order coefficient of 1 in the GF(2) field. Then, select this irreducible polynomial q(x) and the shared key string k 2 as the input random number to generate the same hash function based on a linear feedback shift register as the digital asset issuance center Use the hash function to calculate the hash value of the privacy CA certificate of the digital asset issuance center retained in the CA certification center , denoted as Subsequently, the CA certification center encrypts using the shared key i. The encryption uses the exclusive OR operation to obtain which is the one-time CA certificate otCA′. The CA certification center stores this one-time CA certificate otCA′.
[0074] 3. The digital asset issuance center generates a digital asset digest M', and sends the digital asset digest M' to the applicant in the manner of a message authentication code. This digital asset digest M' serves as the response message of the request req.
[0075] Among them, the digital asset digest M' = (digital asset M, business number SN, otCA', timestamp1).
[0076] Among them, the timestamp timestamp1 is the time when the digital asset digest M' is generated, and the time corresponding to the timestamp timestamp1 can be recorded in the aforementioned issuance business table.
[0077] The process by which the digital asset issuance center sends the digital asset digest M' to the applicant in the manner of a message authentication code includes:
[0078] B1: The digital asset issuance center and the applicant share a string of n-bit random numbers z 1 , so as to perform the preset generation of the irreducible polynomial f(x);
[0079] B2: The digital asset issuance center and the applicant share two groups of quantum keys z 2 and t. The digital asset issuance center uses its own shared key z 2 as the input random number and the preset irreducible polynomial f(x) to generate a hash function based on a linear feedback shift register Then, the digital asset digest M' is input into the hash function to generate the first message authentication code, denoted as
[0080] B3: The digital asset issuance center encrypts the digital asset digest M' using the shared key t; the digital asset issuance center sends the encrypted digital asset digest M' and the first message authentication code to the applicant together;
[0081] B4: The applicant decrypts the encrypted digital asset digest M' using its own shared key t to obtain the decrypted digital asset digest M'; then, the applicant uses its own shared key z 2 as the input random number and the preset irreducible polynomial f(x) to generate a hash function based on a linear feedback shift register Then, the decrypted digital asset digest M' is input into the hash function to generate the second message authentication code, denoted as
[0082] B5: The applicant verifies the received first message authentication code and the calculated second message authentication code Whether they are consistent; if they are consistent, the authentication passes; otherwise, the authentication fails and the applicant needs to return for re - authentication.
[0083] 4. The applicant sends the received digital asset digest M’ to the CA certification center for review, and sends the review result to the digital asset issuance center. For example, the applicant can send the business number SN in the digital asset digest M’ to the CA certification center for review. The specific process includes:
[0084] The applicant obtains the business number SN in the digital asset digest M’, sends the business number SN to the CA certification center. The CA certification center retrieves according to the business number SN. If the corresponding one - time CA certificate otCA′ is retrieved, the review passes, and the CA certification center feeds back the result of passing the review to the applicant; if not retrieved, the review fails, and the CA certification center feeds back that the digital asset issued this time is abnormal.
[0085] After retrieving the one - time CA certificate otCA′ corresponding to the business number SN, the CA certification center can also conduct a timeliness review on the retrieved certificate to determine whether the one - time CA certificate otCA′ has exceeded the validity period. If the one - time CA certificate otCA′ has exceeded the validity period, the review fails, and the CA certification center also feeds back that the digital asset issued this time is abnormal.
[0086] 5. After receiving the applicant's review result, in response to the review result being passed, the digital asset issuance center registers the digital asset M issued this time as issued in the digital asset database, which means that the digital asset M is successfully issued.
[0087] Before performing the above steps 1 - 5, the digital asset M issued by the digital asset issuance center can be stored by the digital asset owner in the digital asset issuance center. Correspondingly, the digital asset issuance center can have a digital asset database to store the digital asset M. Through the method of the present invention, the digital asset owner can issue the digital assets he owns in a quantum - secure manner, solve the security threats caused by the progress of computing power and algorithms to the issuance process, and raise the issuance process to the level of quantum security, thus ensuring the value of digital assets in the issuance process and protecting the rights and interests of digital asset owners.
Claims
1. A method for issuing digital assets, characterized in that, the method comprises the following steps: (1) The applicant sends a request req to obtain digital asset M to the digital asset issuing center and generates a signature file sign. A three-party quantum digital signature is performed on the signature file sign among the CA certification center, the digital asset issuing center, and the applicant. Among them, the applicant is the signing party, and the CA certification center and the digital asset issuing center are the signature verification parties; (2) The digital asset issuing center extracts the corresponding digital asset M according to the received request req and generates a one-time CA certificate otCA' with the CA certification center; (3) The digital asset issuing center generates a digital asset digest M', and sends the digital asset digest M' to the applicant in the manner of a message authentication code; (4) The applicant sends the received digital asset digest M' to the CA certification center for review and sends the review result to the digital asset issuing center; (5) After receiving the applicant's review result, in response to the review result being passed, the digital asset issuing center registers the digitally issued asset M as issued in the digital asset database; The process of generating the signature file sign includes: 1) The digital asset issuance center applies for its public CA certificate from the CA certification center and the privacy CA certificate The applicant applies for its public CA certificate from the CA certification center and the privacy CA certificate Subsequently, the applicant and the CA certification center generate a one-time CA certificate otCA; 2) The applicant uses a one-time CA certificate otCA and a public CA certificate and the request req to generate a signature file sign, that is Among them, the process of sending the digital asset digest M' to the applicant in the manner of a message authentication code includes: B1: The digital asset issuance center shares an n-bit random number z with the applicant to perform the preset generation of the irreducible polynomial f(x); 1 , thereby performing the preset generation of the irreducible polynomial f(x). B2: Sharing two groups of quantum keys z between the digital asset issuance center and the applicant 2 and t, the digital asset issuance center uses its shared key z 2 as the input random number and the irreducible polynomial f(x) generated in advance to generate a hash function based on a linear feedback shift register Then, the digital asset digest M’ is input into the hash function to generate the first message authentication code, denoted as B3: The digital asset issuing center encrypts the digital asset digest M' using the shared key t; the digital asset issuing center sends the encrypted digital asset digest M' and the first message authentication code to the applicant together; B4: The applicant uses its own shared key t to decrypt the encrypted digital asset digest M' to obtain the decrypted digital asset digest M'; then, the applicant uses its own shared key z 2 As the input random number and the irreducible polynomial f(x) generated in advance are used together to generate a hash function based on a linear feedback shift register Then, the decrypted digital asset digest M' is input into the hash function To generate a second message authentication code, denoted as B5: The applicant verifies the received first message authentication code and the calculated second message authentication code to check if they are consistent; if they are consistent, the authentication passes; otherwise, the authentication fails and re - authentication is required.
2. A method for issuing digital assets according to claim 1, characterized in that, the process of the applicant and the CA certification center generating a one-time CA certificate otCA includes: a) The applicant obtains and selects a set of n-bit random numbers s locally 1 , the n-bit random numbers s 1 are used to generate an irreducible polynomial p(x) of degree n, and the n-bit string composed of the coefficients of each term except the highest term in the irreducible polynomial is denoted as str1; b) Three groups of quantum keys s 2 , u, and v are shared between the applicant and the CA certification center, where the lengths of s 2 , u, and v are all n; the applicant selects an irreducible polynomial p(x) of degree n and the shared key s as the input random number 2 to obtain a hash function based on a linear feedback shift register Then use this hash function to calculate the hash value of the applicant's privacy CA certificate , denoted as Subsequently, encrypt with the shared key u The encryption is performed using the exclusive-or operation to obtain which is the one-time CA certificate otCA, and the applicant stores this one-time CA certificate otCA; c) The applicant encrypts the string str1 using the shared key v, and the encryption is performed by XOR operation to obtain Then the encrypted result is sent to the CA certification center; d) After receiving it, the CA certification center decrypts the encrypted result using the shared key v to obtain the same string str1 as the applicant. The CA certification center successively uses each bit of the string str1 as the coefficients of each term except the highest term in the polynomial to generate an nth-order irreducible polynomial p(x) with the highest-order coefficient of 1 in the GF(2) field. Then, the irreducible polynomial p(x) and the shared key string s as the input random number are selected. 2 Generate a hash function based on a linear feedback shift register that is the same as the applicant's. Use the hash function Calculate the privacy CA certificate of the applicant retained in the CA certification center. The hash value of is denoted as Subsequently, the CA certification center encrypts using the shared key u. The encryption is performed using an exclusive OR operation to obtain which is the one-time CA certificate otCA. The CA certification center stores the one-time CA certificate otCA.
3. A method for issuing digital assets according to claim 1, characterized in that, the process of the three-party quantum digital signature of the signature file sign among the CA certification center, the digital asset issuing center, and the applicant includes: S1. The applicant obtains a random number locally to generate an irreducible polynomial l(x), and then records the string composed of the coefficients of each term except the highest term in the irreducible polynomial l(x) as str2; S2. The applicant and the CA certification center conduct key negotiation to obtain the shared keys w 1 , x 1 and y 1 , where the lengths of w 1 , x 1 and y 1 are all n; the applicant and the digital asset issuing center conduct key negotiation to obtain the shared keys w 2 , x 2 and y 2 , where the lengths of w 2 , x 2 and y 2 are all n; the applicant performs XOR operations on the possessed keys w 1 , x 1 , y 1 , w 2 , x 2 and y 2 to obtain the keys w 3 , x 3 and y 3 as follows: S3. The applicant selects an irreducible polynomial l(x) and a key x as the input random number 3 Generate a hash function Use the hash function Perform a hash operation on the signature file sign to obtain a hash value Subsequently, the applicant uses the key w 3 and the key y 3 to encrypt the hash value and the string str2 respectively to obtain a signed message: The applicant transmits the signature message to the digital asset issuing center; S4. After receiving the signed message, the digital asset issuance center sends the signed message and the keys w 2 , x 2 , and y 2 to the CA certification center together. The CA certification center sends the keys w 1 , x 1 , and y 1 to the digital asset issuance center together. The information exchange between the two parties is carried out through an authenticated channel to prevent tampering. At this time, both the CA certification center and the digital asset issuance center have the keys w 1 , x 1 , y 1 , w 2 , x 2 , y 2 , and the signed message; S5. The digital asset issuance center performs exclusive OR operations on the keys w 1 , x 1 , y 1 , w 2 , x 2 and y 2 to obtain the keys w′ 3 , x 3 ′ and y 3 ′, where: The digital asset issuance center uses the secret key w′ 3 to decrypt the in the signed message, obtaining Then, use the secret key y 3 ′ to decrypt the in the signed message, obtaining the string str2. Then, the digital asset issuance center uses the coefficients of each term of the polynomial except the highest term corresponding to each digit of the string str2 to generate an irreducible polynomial l′(x) with the highest term coefficient of 1. Select the irreducible polynomial l′(x) and the secret key x 3 ′ as the input random number to generate a hash function Use the hash function to perform a hash operation on sign in the signed message, obtaining a hash value Compare the calculated hash value with the obtained by decryption. If they are equal, the signature verification passes; otherwise, the signature verification fails. S6. The CA certification center performs an exclusive OR operation on the keys w 1 , x 1 , y 1 , w 2 , x 2 and y 2 to obtain the key w 3 ″, x 3 ″ and y 3 ″, where: The CA certification center uses the key w 3 ″ decrypts the in the signed message to obtain Then, using the key y 3 ″ decrypts the in the signed message to obtain the string str2'. Next, the CA certification center uses the coefficients of each term of the polynomial except the highest term corresponding to each bit of the string str2' to generate an irreducible polynomial l″(x) with the highest term coefficient of 1, and selects this irreducible polynomial l″(x) and the key x as the input random number 3 ″ to generate a hash function Use the hash function to perform a hash operation on sign in the signed message to obtain a hash value Compare the calculated hash value with the obtained by decryption. If they are equal, the comparison passes; otherwise, the comparison fails; At the same time, the CA certification center compares the otCA in sign in the signature message with the one-time CA certificate otCA generated by the CA certification center. If they are equal, the comparison passes; otherwise, the comparison fails; Only when both the hash value and the one-time CA certificate pass the comparison, the CA certification center determines that the signature verification passes; otherwise, the signature verification fails; S7. When both the digital asset issuing center and the CA certification center pass the signature verification, proceed to the next step; otherwise, the signature verification fails and this issuance process ends.
4. A method for issuing digital assets according to claim 1, characterized in that, the process of the digital asset issuing center and the CA certification center generating a one-time CA certificate otCA' includes: A1: The digital asset issuance center obtains and selects a group of n-bit random numbers k locally 1 , the n-bit random number k 1 is used to generate an irreducible polynomial q(x) of degree n, and the n-bit string composed of the coefficients of each term except the highest term in the irreducible polynomial is denoted as str3; A2: Three groups of quantum keys k 2 , i, and j are shared between the digital asset issuance center and the CA certification center, where the lengths of k 2 , i, and j are all n; the digital asset issuance center selects an nth-degree irreducible polynomial q(x) and the shared key k 2 as the input random number to obtain a hash function based on a linear feedback shift register Then use this hash function to calculate the hash value of the privacy CA certificate of the digital asset issuance center , denoted as Subsequently, encrypt using the shared key i. The encryption is performed using the XOR operation to obtain which is the one-time CA certificate otCA′. The digital asset issuance center stores this one-time CA certificate otCA′; A3: The digital asset issuance center encrypts the string str3 using the shared key j. The encryption is performed using the exclusive OR operation to obtain Then, the encrypted result is sent to the CA certification center; After receiving it, the user of the CA certification center decrypts the encryption result using the shared key j to obtain the same string str3 as that of the digital asset issuance center. The CA certification center successively uses each bit of the string str3 as the coefficient of each term except the highest term in the polynomial to generate an nth-degree irreducible polynomial q(x) with the highest-order coefficient of 1 in the GF(2) field. Then, the irreducible polynomial q(x) and the shared key string k used as the input random number are selected. 2 Generate a hash function based on a linear feedback shift register that is the same as that of the digital asset issuance center. Use the hash function. Calculate the privacy CA certificate of the digital asset issuance center retained in the CA certification center. The hash value of which is denoted as Subsequently, the CA certification center encrypts using the shared key i. The encryption is performed using the exclusive OR operation to obtain Which is the one-time CA certificate otCA′. The CA certification center stores the one-time CA certificate otCA′.
5. A method for issuing digital assets according to claim 1, characterized in that, the step (2) further includes: The digital asset issuance center assigns a business number SN and sends the business number SN to the CA certification center; The CA certification center stores the business number SN and establishes a corresponding relationship between the business number SN and the stored one-time CA certificate otCA'.
6. A digital asset issuance method according to claim 5, wherein, The process by which the digital asset issuance center generates a digital asset digest M' includes: The digital asset issuance center generates a digital asset digest M’ = (digital asset M, business number SN, otCA′, timestamp timestamp1).
7. A digital asset issuance method according to claim 6, wherein, The step (4) further includes: The applicant sends the business number SN in the received digital asset digest M' to the CA certification center for review. The review process includes: The applicant obtains the business number in the digital asset digest M' and sends the business number to the CA certification center. The CA certification center retrieves according to the business number in the secure storage module of the CA certification center. If the corresponding one-time CA certificate otCA' is retrieved, the review is passed, and the CA certification center feeds back the result of passing the review to the applicant; if not retrieved, the review fails, and the CA certification center feeds back that the digital asset issued this time is abnormal to the applicant.
8. A digital asset issuance method according to claim 1, wherein, The digital asset M is stored by the digital asset owner in the digital asset issuance center.
9. A digital asset issuance system, wherein, The system includes: a digital asset issuance center, an applicant, and a CA certification center; Among them, the digital asset issuance center, the applicant, and the CA certification center are connected pairwise and are used to execute the digital asset issuance method according to any one of claims 1-7.
10. A digital asset issuance system according to claim 9, wherein, The system further includes a digital asset owner who owns the digital asset M. The digital asset owner is connected to the digital asset issuance center and is used to store the digital asset M in the digital asset issuance center.
Citation Information
Patent Citations
To-be-authenticated digital asset processing system
CN112241513A
Digital asset right confirmation and source tracing method based on Hash algorithm
CN114362971A