A method, device and equipment for processing collaborative digital signature data
Through the collaborative digital signature data processing method, the security risks of usernames and passwords in network transmission and cross-platform login adaptation are solved, the security and convenience of identity verification are achieved, and mobile login is supported.
Patent Information
- Application Number
- CN202411047418.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-01
- Publication Date
- 2025-06-06
- Estimated Expiration
- 2044-08-01
AI Technical Summary
In the prior art, user names and passwords have security risks in network transmission. USBKey login has a large amount of workload and does not support mobile terminals on different operating system platforms. There is a problem that users need to install additional APPs and use environment restrictions on mobile APPs.
Through the processing method of collaborative digital signature data, the server receives the signature data sent by the user, generates and sends the signature horizontal coordinate data and vertical coordinate intermediate value data. The user generates the signature vertical coordinate data and digital certificates based on these data. The server finally generates the signature result data for logging in to different platforms.
It realizes identity authentication in user network behavior, avoids the security risks of username and password in network transmission, simplifies cross-platform login adaptation, supports mobile login, and reduces user environment restrictions.
Smart Images

Figure CN118573381B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of computer information processing, and in particular to a method, device and equipment for processing collaborative digital signature data. Background Art
[0002] The current B / S (Browser / Server) architecture web system login mainly includes the following four methods: username, password, verification code login method, username, password, SMS verification code login method, USBKey, digital certificate login, mobile APP (application) scan code login method.
[0003] For the login method of username, password, and verification code, in this solution, the username, password, and verification code are transmitted in plain text on the network, which poses a great security risk. Although in some business systems, passwords are encrypted using MD5 and salt to increase the complexity of passwords, the security problem of network transmission is not fundamentally solved. For the login method of username, password, and SMS verification code, this solution adds SMS verification code verification compared to the previous solution, which increases the complexity of username and password cracking, but still does not solve the security problem of account and password in network transmission. For the login method of usbKey and digital certificate, the driver of usbKey in this solution is closely related to the user's computer operating system and CPU architecture. Different driver programs are required under different operating system platforms such as Windows, UOS, Kylin, Mac, and mobile terminals, and the platform adaptation workload is very large; at the same time, since mobile devices cannot directly use usbKey at present, this solution does not support mobile terminals. For the mobile phone APP scan code login method, in this solution, users need to install an additional APP. In a specific usage environment, users are not allowed to carry mobile devices such as mobile phones, so users cannot log in to the business system by scanning the code, which has limitations in use. Summary of the invention
[0004] The present invention provides a method, device and equipment for processing collaborative digital signature data, which solves the problem of identity authentication in user network behavior.
[0005] In order to solve the above technical problems, the technical solution of the present invention is as follows:
[0006] An embodiment of the present invention provides a method for processing collaborative digital signature data, which is applied to a server. The method includes:
[0007] Receive signature data sent by the user;
[0008] Generate signature abscissa data and signature ordinate intermediate value data according to the signature data, and send the signature abscissa data and the signature ordinate intermediate value data to the user terminal;
[0009] Receiving the signature ordinate data and the digital certificate sent by the user terminal according to the signature abscissa data and the signature ordinate intermediate value data;
[0010] The signature result data is generated according to the signature abscissa data, the signature ordinate data and the digital certificate.
[0011] Optionally, generating signature abscissa data and signature ordinate intermediate value data according to the signature data includes:
[0012] Generate a first key according to the user identification data in the signature data, wherein the first key includes a first public key and a first random number;
[0013] Generate a second random number according to the first public key;
[0014] The signature abscissa data and the signature ordinate intermediate value data are generated according to the second random number and the summary data in the signature data.
[0015] Optionally, generating signature abscissa data and signature ordinate intermediate value data according to the second random number and summary data in the signature data includes:
[0016] according to
[0017] ( x 1 , y 1 )=[ k 2 ] G + Q 1
[0018] r =( e + x 1 ) mod n
[0019] s 2 =[ d 2 -1 ⋅( r + k 2 )] mod n
[0020] Generate abscissa data and signature ordinate intermediate value data;
[0021] in, x 1 , y 1 are the coordinates of the elliptic curve point, k 2 is the second random number, G For the preset elliptic curve n Step base point, Q 1 is the signature data, r is the horizontal axis data, e For summary data, s 2 is the middle value data of the signature ordinate, d 2 is the first random number, n Is the order.
[0022] Optionally, signature result data is generated according to the signature abscissa data, the signature ordinate data and the digital certificate:
[0023] Determine whether the signature ordinate data is equal to 0, and whether the signature ordinate data is equal to the difference between the order and the signature abscissa data; if the judgment result is no, perform format conversion and encapsulation processing on the signature abscissa data, the signature ordinate data and the digital certificate to generate signature result data; otherwise, re-acquire the signature abscissa data and the signature ordinate data for verification again.
[0024] An embodiment of the present invention provides a method for processing collaborative digital signature data, which is applied to a user terminal. The method includes:
[0025] Generate signature data and send the signature data to the server;
[0026] Receiving the signature horizontal coordinate data and the signature vertical coordinate intermediate value data generated and sent by the server according to the signature data;
[0027] Generate signature ordinate data according to the signature abscissa data and the signature ordinate intermediate value data, and send the signature ordinate data and the digital certificate to the server;
[0028] The signature result data generated and sent by the receiving server is based on the signature horizontal coordinate data, the signature vertical coordinate data and the digital certificate.
[0029] Optionally, generating signature data includes:
[0030] generating a third random number;
[0031] according to Q 1 =[ k 1 ] P 2 , generate signature data;
[0032] in, Q 1 is the signature data, k 1 is the third random number, P 2 is the first public key.
[0033] Optionally, generating signature ordinate data according to the signature abscissa data and the signature ordinate intermediate value data includes:
[0034] according to s =[ d 1 -1 ⋅( k 1 + s 2 )- r ] mod n Generate signature ordinate data;
[0035] in, s is the signature ordinate data, d 1 is the user's private key data, s 2 is the middle value data of the signature ordinate, s 2 =[ d 2 -1 ⋅( r + k 2 )] mod n , d 2 is the first random number, k 2 is the second random number, n Is the order.
[0036] An embodiment of the present invention provides a collaborative digital signature data processing device, which is applied to a server, and the device includes:
[0037] A first transceiver module, used to receive signature data sent by a user terminal;
[0038] A first processing module, configured to generate signature abscissa data and signature ordinate intermediate value data according to the signature data, and send the signature abscissa data and the signature ordinate intermediate value data to the user terminal;
[0039] The first transceiver module is further used to receive the signature ordinate data and the digital certificate sent by the user terminal according to the signature abscissa data and the signature ordinate intermediate value data;
[0040] The first processing module is further used to generate signature result data according to the signature horizontal coordinate data, the signature vertical coordinate data and the digital certificate.
[0041] The embodiment of the present invention provides a collaborative digital signature data processing device, which is applied to a user end, and the device includes:
[0042] A second processing module is used to generate signature data and send the signature data to the server;
[0043] A second transceiver module is used to receive signature abscissa data and signature ordinate intermediate value data generated and sent by the server according to the signature data;
[0044] The second processing module is further used to generate signature ordinate data according to the signature abscissa data and the signature ordinate intermediate value data, and send the signature ordinate data and the digital certificate to the server;
[0045] The second transceiver module is also used to receive signature result data sent by the server, which is generated and sent according to the signature horizontal coordinate data, the signature vertical coordinate data and the digital certificate.
[0046] An embodiment of the present invention provides a computing device, including: a processor and a memory storing a computer program, wherein the computer program executes the above method when executed by the processor.
[0047] The technical solution of the present invention includes at least the following effects:
[0048] The above-mentioned scheme of the present invention receives signature data sent by the user end; generates signature horizontal coordinate data and signature vertical coordinate intermediate value data based on the signature data, and sends the signature horizontal coordinate data and the signature vertical coordinate intermediate value data to the user end; receives the signature vertical coordinate data and the digital certificate sent by the user end based on the signature horizontal coordinate data and the signature vertical coordinate intermediate value data; generates signature result data based on the signature horizontal coordinate data, the signature vertical coordinate data and the digital certificate, which is suitable for identity authentication work when logging into different platforms, and realizes long-term storage of certificates in the browser. BRIEF DESCRIPTION OF THE DRAWINGS
[0049] Figure 1 It is a flow chart of the server side of the collaborative digital signature data processing method provided by an embodiment of the present invention;
[0050] Figure 2 It is a flowchart of the user end of the collaborative digital signature data processing method provided by an embodiment of the present invention;
[0051] Figure 3 It is a system block diagram of a method for processing collaborative digital signature data provided by an embodiment of the present invention;
[0052] Figure 4 It is a flowchart of calculating a collaborative public key in a collaborative digital signature data processing method provided by an embodiment of the present invention;
[0053] Figure 5 It is a collaborative signature flow chart of a collaborative digital signature data processing method provided by an embodiment of the present invention;
[0054] Figure 6 It is a digital certificate application flow chart of a method for processing collaborative digital signature data provided by an embodiment of the present invention;
[0055] Figure 7 It is a key backup flow chart of a collaborative digital signature data processing method provided by an embodiment of the present invention;
[0056] Figure 8 It is a key recovery flow chart of a method for processing collaborative digital signature data provided by an embodiment of the present invention;
[0057] Fig. 9 It is a structural diagram of a server side of a collaborative digital signature data processing device provided by an embodiment of the present invention;
[0058] Fig.10 It is a structural diagram of a user end of a collaborative digital signature data processing device provided by an embodiment of the present invention;
[0059] Fig.11 It is a schematic diagram of the structure of a computing device provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0060] The exemplary embodiments of the present invention will be described in more detail below with reference to the accompanying drawings. Although the exemplary embodiments of the present invention are shown in the accompanying drawings, it should be understood that the present invention can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided in order to enable a more thorough understanding of the present invention and to enable the scope of the present invention to be fully communicated to those skilled in the art.
[0061] like Figure 1 As shown, an embodiment of the present invention proposes a collaborative digital signature data processing method, which is applied to a server and includes:
[0062] Step 11, receiving the signature data sent by the user terminal;
[0063] Step 12, generating signature abscissa data and signature ordinate intermediate value data according to the signature data, and sending the signature abscissa data and the signature ordinate intermediate value data to the user terminal;
[0064] Step 13, receiving the signature ordinate data and the digital certificate sent by the user terminal according to the signature abscissa data and the signature ordinate intermediate value data;
[0065] Step 14: Generate signature result data according to the signature horizontal coordinate data, the signature vertical coordinate data and the digital certificate.
[0066] In this example, the server is a collaborative signature server, which is a server system that can use public and private keys to encrypt, sign and verify data to ensure that the data is not tampered with or stolen during transmission; the user end refers to a client application or device that interacts with the collaborative signature server, which can be various forms of software or hardware, including but not limited to desktop applications, mobile applications, Web Browser plug-ins, IoT devices, etc.; the user end generates data to be signed and sends a signature request to the collaborative signature server. The collaborative signature server generates signature horizontal coordinate data and signature vertical coordinate intermediate value data based on the signature data, and sends the signature horizontal coordinate data and the signature vertical coordinate intermediate value data to the user end, wherein the signature horizontal coordinate data refers to the position information of the handwriting in the horizontal direction (i.e., the X-axis direction) during the signing process in the digital signature or handwritten signature recognition system; the signature vertical coordinate intermediate value data refers to an intermediate statistic of the vertical coordinate values of all sampling points of the handwriting in the vertical direction (i.e., the Y-axis direction) in the context of signature recognition or signature verification (usually in the handwritten signature process). This intermediate value can help analyze certain features of the signature, such as the vertical position and height change of the signature; the user end generates the signature vertical coordinate data based on the signature horizontal coordinate data and the signature vertical coordinate intermediate value data, and sends the signature vertical coordinate data and the digital certificate to the collaborative signature server, wherein the user end calls JSSDK (JavaScript Software Development Kit, JavaScript software development kit) generates a digital certificate request file and sends the digital certificate request file to the collaborative signature server. After receiving the digital certificate request file, the collaborative signature server sends the digital certificate request file to the third-party digital certificate server to apply for a digital certificate. After the certificate application is successful, the collaborative signature server returns the digital certificate information returned by the third-party digital certificate server to JSSDK; the collaborative signature server generates signature result data according to the signature horizontal coordinate data, the signature vertical coordinate data and the digital certificate, and uses the signature result data as the user's credentials for logging into the web system.
[0067] This embodiment solves the identity problem in user network behavior; based on the design method of JSSDK, it eliminates the additional system adaptation work when users log in to the web system using different platforms such as Windows, Linux, Mac, etc., and realizes the browser's support for dynamic library calls and the browser's long-term storage of private keys or certificates.
[0068] In an optional embodiment, the embodiment of the present invention provides that step 12 may include:
[0069] Step 121, generating a first key according to the user identification data in the signature data, wherein the first key includes a first public key and a first random number;
[0070] Step 122, generating a second random number according to the first public key;
[0071] Step 123: Generate signature horizontal coordinate data and signature vertical coordinate intermediate value data according to the second random number and the summary data in the signature data.
[0072] In this example, the signature data includes user identification data and summary data. After receiving the signature data, the collaborative signature server queries the first key corresponding to the user according to the user identification data, that is, the collaborative key ( d 2 , P 2 ),in, d 2 is the first random number, P 2 is the first public key; the collaborative signature server uses the first public key P 2 , generate the second random number k 2 According to the second random number k 2 And the summary data in the signature data, generate the signature horizontal coordinate data r and signature ordinate intermediate value data s 2 ,in, r =( e + x 1 ) mod n , s 2 =[ d 2 -1 ⋅( r + k 2 )] mod n , ( x 1 , y 1 )=[ k 2 ] G + Q 1 , x 1 , y 1 is the coordinate of the preset elliptic curve point, GFor the preset elliptic curve n Step base point, Q 1 is the preset elliptic curve point, r is the horizontal axis data, e For summary data, s 2 is the middle value data of the signature ordinate, n Is the order.
[0073] In an optional embodiment, the embodiment of the present invention provides that step 14 may include:
[0074] Step 141, determine whether the signature ordinate data is equal to 0, and whether the signature ordinate data is equal to the difference between the order and the signature abscissa data; if the judgment result is no, the signature abscissa data, the signature ordinate data and the digital certificate are format converted and packaged to generate signature result data; otherwise, the signature abscissa data and the signature ordinate data are re-obtained for verification again.
[0075] In this example, the verification of two key data in the signature process, namely, the signature horizontal coordinate data and the signature vertical coordinate data, is involved. First, it is determined whether the signature vertical coordinate data is equal to 0, and whether the signature vertical coordinate data is equal to the difference between the order and the signature horizontal coordinate data; if the judgment result is no, the signature horizontal coordinate data, the signature vertical coordinate data and the digital certificate are format converted and encapsulated to generate signature result data, and the signature result data is used as the user's credential for logging into the web system; wherein, the signature result data is an output generated in the digital signature process, which is used to verify the integrity and authenticity of digital information or files, and usually contains the following information: signature value, which is the ciphertext obtained by encrypting the hash value with the private key, which is the core part of the signature result data and is used for comparison in the subsequent verification process; algorithm identifier, which indicates the hash function and encryption algorithm used to generate the signature; timestamp, certificate serial number, signer identifier, etc. It should be noted that the signature result data itself does not contain the original data signed; it only provides a means to verify the integrity and authenticity of the original data. Therefore, when verifying the signature, both the signature result data and the original data must be available.
[0076] like Figure 2 As shown, an embodiment of the present invention proposes a method for processing collaborative digital signature data, which is applied to a user end and includes:
[0077] Step 21, generate signature data and send the signature data to the server;
[0078] Step 22, receiving the signature horizontal coordinate data and the signature vertical coordinate intermediate value data generated and sent by the server according to the signature data;
[0079] Step 23, generating signature ordinate data according to the signature abscissa data and the signature ordinate intermediate value data, and sending the signature ordinate data and the digital certificate to the server;
[0080] Step 24, receiving the signature result data generated and sent by the server based on the signature horizontal coordinate data, the signature vertical coordinate data and the digital certificate.
[0081] In this example, the user terminal generates and sends signature data to the collaborative signature server. The collaborative signature server generates and sends signature horizontal coordinate data to the user terminal based on the received signature data. r and signature ordinate intermediate value data s 2 , the user receives the signature horizontal coordinate data r and signature ordinate intermediate value data s 2 After that, the signature vertical coordinate data is generated, and the signature vertical coordinate data and the digital certificate are sent to the collaborative signature server. The collaborative signature server generates the signature result data according to the signature horizontal coordinate data, the signature vertical coordinate data and the digital certificate and sends it to the user end. The user end uses the signature result data as the user's credentials for logging into the web system.
[0082] In an optional embodiment, the embodiment of the present invention provides that step 21 may include:
[0083] Step 211, generating a third random number;
[0084] Step 212, according to Q 1 =[ k 1 ] P 2 , generate signature data;
[0085] in, Q 1 is the signature data, k 1 is the third random number, P 2 is the first public key.
[0086] In this example, the client generates and sends signature data to the collaborative signature server. The client calls JSSDK (JavaScript Software Development Kit) and passes the random number to be signed to JSSDK. JSSDK calculates the summary data. e , generate the third random number k 1 , calculate the elliptic curve point Q 1 , generate signature data.
[0087] In an optional embodiment, the embodiment of the present invention provides that step 23 may include:
[0088] Step 231, according to s =[ d 1 -1 ⋅( k 1 + s 2 )- r ] mod n Generate signature ordinate data;
[0089] in, s is the signature ordinate data, d 1 is the user's private key data, s 2 is the middle value data of the signature ordinate, k 1 is the third random number, and n is the order.
[0090] In this example, the user terminal receives the signature horizontal coordinate data and the signature vertical coordinate intermediate value data sent by the collaborative signature server, and s =[ d 1 -1 ⋅( k 1 + s 2 )- r ] mod n Generate signature ordinate data.
[0091] A specific embodiment of the method for controlling the energy efficiency of a water pump unit provided by an embodiment of the present invention is:
[0092] Step 1: The client calls the JSSDK interface to calculate the collaborative public key, such as Figure 2 and Figure 3As shown, the user identification data is sent to the collaborative signature server; after the collaborative signature server receives the user identification data, it generates a collaborative key corresponding to the user end ( d 2 , P 2 ),in d 2 is the first random number, P 2 The collaborative signature server will be the first public key P 2 Sent to the client's JSSDK, which receives the first public key P 2 After that, generate a local user key ( d 1 , P 1 ), and then according to the first public key P 2 and local private key d 1 Calculate the second public key P (i.e. collaborative public key), where the local private key d 1 Encryption with retry times via user PIN;
[0093] Step 2: The client calls JSSDK to generate a digital certificate request file and sends the digital certificate request file to the collaborative signature server. Figure 6 As shown; after receiving the digital certificate request file, the collaborative signature server sends the digital certificate request file to the third-party digital certificate server to apply for a digital certificate. After the certificate application is successful, the collaborative signature server returns the digital certificate information returned by the third-party digital certificate server to JSSDK;
[0094] Step 3: After the client receives the digital certificate, Figure 7 As shown, JSSDK uses the user PIN to encrypt the local private key d 1 , and the encrypted local private key d 1 , collaborative public key P , the digital certificate is sent to the collaborative signature server in a specific format; the local private key stored on the collaborative signature server d 1 Through PIN protection with retry times, the user's private key data is invisible ciphertext data to the collaborative signature server, effectively protecting the security of the local private key.
[0095] Step 4: When the user logs into the business system, Figure 8As shown in the figure, the business system calls JSSDK to sign data. At this time, JSSDK obtains the user key (i.e., local private key) and certificate data from the collaborative signature server through the user ID passed by the business system. After JSSDK receives the user key / certificate data returned by the collaborative signature server, it decrypts the signature private key through the user PIN code.
[0096] Step 5: The business system calls JSSDK and passes the random number to be signed to JSSDK, and JSSDK calculates the summary e , generate random numbers k 1 , calculate the elliptic curve point Q 1 ,like Figure 4 As shown, Q 1 =[ k 1 ] P 2 ;JSSDK will e , Q 1 The collaborative signature server receives the signature request and the user identification data, and then queries the collaborative key corresponding to the user according to the user identification data. d 2 , P 2 ), generate random numbers k 2 , calculate the elliptic curve point Q 2 ( x 1 , y 1 ),in Q 2 =[ k 2 ] G + Q 1 ; Calculate the signature horizontal coordinate data r And the signature vertical coordinate intermediate value data s 2 ,Will r and s 2 Return to JSSDK; JSSDK returns based on the signature server r and s 2 Calculate the signature ordinate data s ,like Figure 5 As shown, in r , s, the digital certificate is converted into pkcs7 format and returned to the business system; the web end of the application system submits the signature data to the business system server, the business system server calls the signature verification server to complete the verification, and uses the verification result as the user's login credential for the web system.
[0097] This embodiment is based on the public key and secret key system, which solves the identity problem in the user's network behavior; based on the design method of JSSDK, it eliminates the additional system adaptation work when users log in to the web system using different platforms such as Windows, Linux, Mac, etc.; the user's private key adopts a PIN code protection mechanism with a retry number, and the PIN code is stored on the user side, which can effectively prevent the private key from being cracked by brute force; the browser supports dynamic library calls and the browser's long-term storage of private keys or certificates.
[0098] like Fig. 9 As shown, the embodiment of the present invention further provides a collaborative digital signature data processing device 90, which is applied to a server, and the device 90 includes:
[0099] The first transceiver module 91 is used to receive signature data sent by the user terminal;
[0100] A first processing module 92 is used to generate signature abscissa data and signature ordinate intermediate value data according to the signature data, and send the signature abscissa data and the signature ordinate intermediate value data to the user terminal;
[0101] The first transceiver module 91 is further used to receive the signature ordinate data and the digital certificate sent by the user terminal according to the signature abscissa data and the signature ordinate intermediate value data;
[0102] The first processing module 92 is further configured to generate signature result data according to the signature horizontal coordinate data, the signature vertical coordinate data and the digital certificate.
[0103] Optionally, the first processing module 92 is specifically used for:
[0104] Generate a first key pair according to the user identification data in the signature data, wherein the first key pair includes a first public key and a first random number;
[0105] Generate a second random number according to the first public key;
[0106] The signature abscissa data and the signature ordinate intermediate value data are generated according to the second random number and the summary data in the signature data.
[0107] Optionally, generating signature abscissa data and signature ordinate intermediate value data according to the second random number and summary data in the signature data includes:
[0108] according to
[0109] ( x 1 , y 1 )=[ k 2 ] G + Q 1
[0110] r =( e + x 1 ) mod n
[0111] s 2 =[ d 2 -1 ⋅( r + k 2 )] mod n
[0112] Generate abscissa data and signature ordinate intermediate value data;
[0113] in, x 1 , y 1 are the coordinates of the elliptic curve point, k 2 is the second random number, G For the preset elliptic curve n Step base point, Q 1 is the signature data, r is the horizontal axis data, e For summary data, s 2 is the middle value data of the signature ordinate, d 2 is the first random number, n Is the order.
[0114] Optionally, the first processing module 92 is further specifically configured to:
[0115] Determine whether the signature ordinate data is equal to 0, and whether the signature ordinate data is equal to the difference between the order and the signature abscissa data; if the judgment result is no, perform format conversion and encapsulation processing on the signature abscissa data, the signature ordinate data and the digital certificate to generate signature result data; otherwise, re-acquire the signature abscissa data and the signature ordinate data for verification again.
[0116] It should be noted that the device is Figure 1 The device corresponding to the method shown, all implementation methods in the above method embodiment are applicable to this embodiment and can achieve the same technical effect.
[0117] like Fig.10 As shown, the embodiment of the present invention further provides a collaborative digital signature data processing device 10, which is applied to a user end, and the device 10 includes:
[0118] The second processing module 101 is used to generate signature data and send the signature data to the server;
[0119] The second transceiver module 102 is used to receive the signature horizontal coordinate data and the signature vertical coordinate intermediate value data generated and sent by the server according to the signature data;
[0120] The second processing module 101 is further used to generate signature ordinate data according to the signature abscissa data and the signature ordinate intermediate value data, and send the signature ordinate data and the digital certificate to the server;
[0121] The second transceiver module 102 is further used to receive signature result data generated and sent by the server according to the signature horizontal coordinate data, the signature vertical coordinate data and the digital certificate.
[0122] Optionally, the second processing module 101 is specifically used for:
[0123] generating a third random number;
[0124] according to Q 1 =[ k 1 ] P 2 , generate signature data;
[0125] in, Q 1 is the signature data, k 1 is the third random number, P 2 is the first public key.
[0126] Optionally, the second processing module 101 is further specifically configured to:
[0127] according to s =[ d 1 -1 ⋅( k 1 + s2 )- r ] mod n Generate signature ordinate data;
[0128] in, s is the signature ordinate data, d 1 is the user's private key data, s 2 is the middle value data of the signature ordinate, s 2 =[ d 2 -1 ⋅( r + k 2 )] mod n , d 2 is the first random number, k 2 is the second random number, n Is the order.
[0129] It should be noted that the device is Figure 2 The device corresponding to the method shown, all implementation methods in the above method embodiment are applicable to this embodiment and can achieve the same technical effect.
[0130] like Fig.11 As shown, the embodiment of the present invention further provides a computing device 110, including a processor 111, a memory 112, and a program or instruction stored in the memory 112 and executable on the processor 111. When the program or instruction is executed by the processor 111, each process of the above-mentioned collaborative digital signature data processing method embodiment is implemented, and the same technical effect can be achieved. To avoid repetition, it will not be repeated here. It should be noted that the computing device in the embodiment of the present invention includes the above-mentioned mobile electronic device and non-mobile electronic device.
[0131] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the present invention.
[0132] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0133] In the embodiments provided by the present invention, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic, for example, the division of units is only a logical function division, and there may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0134] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0135] In addition, each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0136] Stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to perform all or part of the steps of the methods of various embodiments of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, ROM, RAM, disk or optical disk, etc., various media that can store program codes.
[0137] In addition, it should be pointed out that in the apparatus and method of the present invention, it is obvious that each component or each step can be decomposed and / or recombined. These decompositions and / or recombinations should be regarded as equivalent schemes of the present invention. Moreover, the steps of performing the above series of processing can naturally be performed in chronological order according to the order of description, but it is not necessary to perform them in chronological order, and some steps can be performed in parallel or independently of each other. For those of ordinary skill in the art, it is understandable that all or any steps or components of the method and apparatus of the present invention can be implemented in hardware, firmware, software or a combination thereof in any computing device (including processors, storage media, etc.) or a network of computing devices, which can be achieved by those of ordinary skill in the art using their basic programming skills after reading the description of the present invention.
[0138] Therefore, the purpose of the present invention can also be achieved by running a program or a group of programs on any computing device. The computing device can be a well-known general-purpose device. Therefore, the purpose of the present invention can also be achieved by simply providing a program product containing a program code for implementing a method or device. That is to say, such a program product also constitutes the present invention, and a storage medium storing such a program product also constitutes the present invention. Obviously, the storage medium can be any well-known storage medium or any storage medium developed in the future. It should also be pointed out that in the device and method of the present invention, it is obvious that each component or each step can be decomposed and / or recombined. These decompositions and / or recombinations should be regarded as equivalent schemes of the present invention. In addition, the steps of performing the above-mentioned series of processing can naturally be performed in chronological order according to the order of description, but it is not necessary to perform them in chronological order. Some steps can be performed in parallel or independently of each other.
[0139] The above are preferred embodiments of the present invention. It should be pointed out that, for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present invention. These improvements and modifications should also be regarded as within the scope of protection of the present invention.
Claims
1. A method for processing collaborative digital signature data, characterized in that: Applied to a collaborative signature server, the method includes: Receive signature data sent by the user; Generate signature abscissa data and signature ordinate intermediate value data according to the signature data, and send the signature abscissa data and the signature ordinate intermediate value data to the user terminal; Receiving the signature ordinate data and the digital certificate sent by the user terminal according to the signature abscissa data and the signature ordinate intermediate value data; Generate signature result data according to the signature abscissa data, the signature ordinate data and the digital certificate; Among them, the signature ordinate data is based on s =[ d 1 -1 ⋅( k 1+ s 2)- r ] mod n generate; in, s is the signature ordinate data, d 1 is the user's private key data, s 2 is the middle value data of the signature vertical coordinate, s 2=[ d 2 -1 ⋅( r + k 2)] mod n , d 2 is the first random number, k 2 is the second random number, k 1 is the third random number, r is the signature horizontal coordinate data, n is the order; Among them, the signature abscissa data is based on r =( e + x 1) mod n and( x 1, y 1)=[ k 2] G + Q 1Generate; in, x 1. y 1 is the coordinate of the elliptic curve point, G For the preset elliptic curve n Step base point, Q 1 is the signature data, e is summary data; The digital certificate is obtained by the user generating a digital certificate request file and sending the digital certificate request file to the collaborative signature server. After receiving the digital certificate request file, the collaborative signature server sends the digital certificate request file to the third-party digital certificate server for application. Wherein, generating signature result data according to the signature abscissa data, the signature ordinate data and the digital certificate includes: Determine whether the signature ordinate data is equal to 0, and whether the signature ordinate data is equal to the difference between the order and the signature abscissa data; if the determination result is no, perform format conversion and encapsulation processing on the signature abscissa data, the signature ordinate data and the digital certificate to generate signature result data; otherwise, re-acquire the signature abscissa data and the signature ordinate data for verification again; The signature result data includes: signature value, algorithm identifier, timestamp, certificate serial number, and signer identifier. The signature value is the ciphertext obtained by encrypting the hash value with the private key, which is used for comparison in the subsequent verification process; the algorithm identifier is used to generate the hash function and encryption algorithm of the signature.
2. A method for processing collaborative digital signature data, characterized in that: Applied to a user terminal, the method includes: Generate signature data, and send the signature data to the collaborative signature server; Receiving the signature horizontal coordinate data and the signature vertical coordinate intermediate value data generated and sent by the collaborative signature server according to the signature data; Generate signature ordinate data according to the signature abscissa data and the signature ordinate intermediate value data, and send the signature ordinate data and the digital certificate to the collaborative signature server; Receiving signature result data generated and sent by the collaborative signature server according to the signature horizontal coordinate data, the signature vertical coordinate data and the digital certificate; Among them, the signature ordinate data is based on s =[ d 1 -1 ⋅( k 1+ s 2)- r ] mod n generate; in, s is the signature ordinate data, d 1 is the user's private key data, s 2 is the middle value data of the signature vertical coordinate, s 2=[ d 2 -1 ⋅( r + k 2)] mod n , d 2 is the first random number, k 2 is the second random number, k 1 is the third random number, r is the signature horizontal coordinate data, n is the order; Among them, the signature abscissa data is based on r =( e + x 1) mod n and( x 1, y 1)=[ k 2] G + Q 1Generate; in, x 1. y 1 is the coordinate of the elliptic curve point, G For the preset elliptic curve n Step base point, Q 1 is the signature data, e is summary data; The digital certificate is obtained by the user generating a digital certificate request file and sending the digital certificate request file to the collaborative signature server. After receiving the digital certificate request file, the collaborative signature server sends the digital certificate request file to the third-party digital certificate server for application. Wherein, generating signature result data according to the signature abscissa data, the signature ordinate data and the digital certificate includes: Determine whether the signature ordinate data is equal to 0, and whether the signature ordinate data is equal to the difference between the order and the signature abscissa data; if the determination result is no, perform format conversion and encapsulation processing on the signature abscissa data, the signature ordinate data and the digital certificate to generate signature result data; otherwise, re-acquire the signature abscissa data and the signature ordinate data for verification again; The signature result data includes: signature value, algorithm identifier, timestamp, certificate serial number, and signer identifier. The signature value is the ciphertext obtained by encrypting the hash value with the private key, which is used for comparison in the subsequent verification process; the algorithm identifier is used to generate the hash function and encryption algorithm of the signature.
3. The method for processing collaborative digital signature data according to claim 2, characterized in that: The generating of signature data comprises: generating a third random number; according to Q 1=[ k 1] P 2. Generate signature data; in, Q 1 is the signature data, k 1 is the third random number, P 2 is the first public key.
4. A collaborative digital signature data processing device, characterized in that: Applied to a collaborative signature server, the device comprises: A first transceiver module, used to receive signature data sent by a user terminal; A first processing module, configured to generate signature abscissa data and signature ordinate intermediate value data according to the signature data, and send the signature abscissa data and the signature ordinate intermediate value data to the user terminal; The first transceiver module is further used to receive the signature ordinate data and the digital certificate sent by the user terminal according to the signature abscissa data and the signature ordinate intermediate value data; The first processing module is further used to generate signature result data according to the signature horizontal coordinate data, the signature vertical coordinate data and the digital certificate; Among them, the signature ordinate data is based on s =[ d 1 -1 ⋅( k 1+ s 2)- r ] mod n generate; in, s is the signature ordinate data, d 1 is the user's private key data, s 2 is the middle value data of the signature vertical coordinate, s 2=[ d 2 -1 ⋅( r + k 2)] mod n , d 2 is the first random number, k 2 is the second random number, k 1 is the third random number, r is the signature horizontal coordinate data, n is the order; Among them, the signature abscissa data is based on r =( e + x 1) mod n and( x 1, y 1)=[ k 2] G + Q 1Generate; in, x 1. y 1 is the coordinate of the elliptic curve point, G For the preset elliptic curve n Step base point, Q 1 is the signature data, e is summary data; The digital certificate is obtained by the user generating a digital certificate request file and sending the digital certificate request file to the collaborative signature server. After receiving the digital certificate request file, the collaborative signature server sends the digital certificate request file to the third-party digital certificate server for application. Wherein, generating signature result data according to the signature abscissa data, the signature ordinate data and the digital certificate includes: Determine whether the signature ordinate data is equal to 0, and whether the signature ordinate data is equal to the difference between the order and the signature abscissa data; if the determination result is no, perform format conversion and encapsulation processing on the signature abscissa data, the signature ordinate data and the digital certificate to generate signature result data; otherwise, re-acquire the signature abscissa data and the signature ordinate data for verification again; The signature result data includes: signature value, algorithm identifier, timestamp, certificate serial number, and signer identifier. The signature value is the ciphertext obtained by encrypting the hash value with the private key, which is used for comparison in the subsequent verification process; the algorithm identifier is used to generate the hash function and encryption algorithm of the signature.
5. A collaborative digital signature data processing device, characterized in that: Applied to a user terminal, the device comprises: A second processing module is used to generate signature data and send the signature data to the collaborative signature server; The second transceiver module is used to receive the signature horizontal coordinate data and the signature vertical coordinate intermediate value data generated and sent by the collaborative signature server according to the signature data; The second processing module is further used to generate signature ordinate data according to the signature abscissa data and the signature ordinate intermediate value data, and send the signature ordinate data and the digital certificate to the collaborative signature server; The second transceiver module is further used to receive the signature result data generated and sent by the collaborative signature server according to the signature horizontal coordinate data, the signature vertical coordinate data and the digital certificate; Among them, the signature ordinate data is based on s =[ d 1 -1 ⋅( k 1+ s 2)- r ] mod n generate; in, s is the signature ordinate data, d 1 is the user's private key data, s 2 is the middle value data of the signature vertical coordinate, s 2=[ d 2 -1 ⋅( r + k 2)] mod n , d 2 is the first random number, k 2 is the second random number, k 1 is the third random number, r is the signature horizontal coordinate data, n is the order; Among them, the signature abscissa data is based on r =( e + x 1) mod n and( x 1, y 1)=[ k 2] G + Q 1Generate; in, x 1. y 1 is the coordinate of the elliptic curve point, G For the preset elliptic curve n Step base point, Q 1 is the signature data, e is summary data; The digital certificate is obtained by the user generating a digital certificate request file and sending the digital certificate request file to the collaborative signature server. After receiving the digital certificate request file, the collaborative signature server sends the digital certificate request file to the third-party digital certificate server for application. Wherein, generating signature result data according to the signature abscissa data, the signature ordinate data and the digital certificate includes: Determine whether the signature ordinate data is equal to 0, and whether the signature ordinate data is equal to the difference between the order and the signature abscissa data; if the determination result is no, perform format conversion and encapsulation processing on the signature abscissa data, the signature ordinate data and the digital certificate to generate signature result data; otherwise, re-acquire the signature abscissa data and the signature ordinate data for verification again; The signature result data includes: signature value, algorithm identifier, timestamp, certificate serial number, and signer identifier. The signature value is the ciphertext obtained by encrypting the hash value with the private key, which is used for comparison in the subsequent verification process; the algorithm identifier is used to generate the hash function and encryption algorithm of the signature.
6. A computing device, characterized in that include: A processor and a memory storing a computer program, wherein when the computer program is executed by the processor, the method according to claim 1 or any one of claims 2 to 3 is executed.
Citation Information
Patent Citations
Collaborative signature method and collaborative signature system
CN114567448A