Collaborative Signature Method, Apparatus, Device and System
Through the public key encryption of the certificate authorization center and the terminal private key generation of the target user's terminal private key, the problems of private information leakage and private key tampering in the prior art are solved, and the security of collaborative signatures are realized and the interaction process is simplified.
Patent Information
- Application Number
- CN202410307454.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-03-18
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2044-03-18
AI Technical Summary
The existing collaborative signature method fails to effectively protect the signing party's private information, and the interaction process is cumbersome, and there is a risk of private key tampering and information leakage.
The signature request information is encrypted through the public key of the certificate authorization center, and the public key intermediate value and the signature final value are generated. The public key final value and the second signature final value are generated by combining the target user's terminal private key to generate the public key final value and the second signature final value, verify the hash value of the file to be signed, and ensure the security and reliability of information transmission.
Effectively protect user privacy information, prevent hash values from being tampered with, improve the security and reliability of information transmission, and simplify the collaborative signature process.
Smart Images

Figure CN118677619B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technology, and in particular, to a collaborative signature method, apparatus, device, and system. Background Art
[0002] Collaborative signature is a way of signing contracts involving multiple parties. By collaborating among multiple parties to complete the signature, it improves the signing efficiency and increases the transparency and sense of responsibility of all participating parties. Collaborative signature has wide applications in fields such as business, law, and government. The basic principle of collaborative signature is a signing method based on digital technology. Its core is to convert traditional paper signing into electronic signature and enable multiple parties to participate in the signing and approval process through a network platform.
[0003] At present, the collaborative signature methods in related technologies do not well protect the privacy information of the signing parties, and the interaction process between the two collaborating parties is very cumbersome. Summary of the Invention
[0004] Embodiments of this application provide a collaborative signature method, apparatus, device, and system to protect the privacy information of users and ensure the security and reliability of information transmission in the system.
[0005] In a first aspect, embodiments of this application provide a collaborative signature method. The collaborative signature method is applied to a first server, and the method includes:
[0006] Generating signature request information based on a signature request signal sent by a terminal of a target user; wherein, the signature request information includes: the identity information of the target user and the hash value of the target file to be signed;
[0007] Encrypting the signature request information using the public key of a certificate authority to obtain encrypted information;
[0008] Sending the encrypted information to a second server, so that the second server generates a public key intermediate value based on the private key of the second server, generates a first signature final value based on the encrypted information and the public key intermediate value, generates a signature intermediate value based on the first signature final value and the private key of the second server, and sends the public key intermediate value, the first signature final value, and the signature intermediate value to the terminal of the target user, so that the terminal of the target user generates a second signature final value based on the first signature final value, the signature intermediate value, and the private key of the terminal of the target user; generating a public key final value based on the public key intermediate value and the private key of the terminal of the target user, and sending the first signature final value, the second signature final value, and the public key final value to the first server;
[0009] Determine the signature result of the target file to be signed based on the hash value of the target file to be signed, the final public key, the final first signature, and the final second signature.
[0010] In a second aspect, an embodiment of the present application provides a collaborative signature method, which is applied to a second server. The method includes:
[0011] Generate an intermediate public key based on the private key of the second server;
[0012] Decrypt the encrypted information using the private key of the certificate authority center to obtain the hash value of the target file to be signed and the identity information of the target user;
[0013] Generate a final first signature based on the intermediate public key and the hash value of the target file to be signed;
[0014] Generate an intermediate signature based on the final first signature and the private key of the second server;
[0015] Determine the terminal of the target user based on the identity information of the target user;
[0016] Send the intermediate public key, the final first signature, and the intermediate signature to the terminal of the target user, so that the terminal of the target user generates a final second signature based on the final first signature, the intermediate signature, and the private key of the terminal of the target user; and generate a final public key based on the intermediate public key and the private key of the terminal of the target user.
[0017] In a third aspect, an embodiment of the present application provides a collaborative signature method, which is applied to the terminal of the target user. The method includes:
[0018] Generate a final second signature based on the final first signature, the intermediate signature, and the private key of the terminal of the target user sent by the second server;
[0019] Generate a final public key based on the intermediate public key sent by the second server and the private key of the terminal of the target user;
[0020] Send the final first signature, the final second signature, and the final public key to the first server, so that the first server determines the signature result of the target file to be signed based on the hash value of the target file to be signed, the final public key, the final first signature, and the final second signature.
[0021] In a fourth aspect, an embodiment of the present application provides a collaborative signature device, which is applied to the first server. The device includes:
[0022] A signature request information generation module, configured to generate signature request information based on a signature request signal sent by a terminal of a target user; wherein, the signature request information includes: identity information of the target user and a hash value of a target file to be signed;
[0023] An encryption information obtaining module, configured to encrypt the signature request information using a public key of a certificate authority to obtain encrypted information;
[0024] A first sending module, configured to send the encrypted information to a second server, so that the second server generates a public key intermediate value based on a private key of the second server, generates a first signature final value based on the encrypted information and the public key intermediate value, generates a signature intermediate value based on the first signature final value and the private key of the second server, and sends the public key intermediate value, the first signature final value, and the signature intermediate value to the terminal of the target user, so that the terminal of the target user generates a second signature final value based on the first signature final value, the signature intermediate value, and a private key of the terminal of the target user; generates a public key final value based on the public key intermediate value and the private key of the terminal of the target user, and sends the first signature final value, the second signature final value, and the public key final value to the first server;
[0025] A signature result verification module, configured to determine a signature result of the target file to be signed based on the hash value of the target file to be signed, the public key final value, the first signature final value, and the second signature final value.
[0026] In a fifth aspect, an embodiment of the present application provides a collaborative signature device, and the collaborative signature device is applied to a second server, and the device includes:
[0027] A public key intermediate value generation module, configured to generate a public key intermediate value based on a private key of the second server;
[0028] A decryption module, configured to decrypt the encrypted information using a private key of a certificate authority to obtain a hash value of a target file to be signed and identity information of the target user;
[0029] A first signature final value generation module, configured to generate a first signature final value based on the public key intermediate value and the hash value of the target file to be signed;
[0030] A signature intermediate value generation module, configured to generate a signature intermediate value based on the first signature final value and a private key of the second server;
[0031] A terminal confirmation module, configured to determine the terminal of the target user based on the identity information of the target user;
[0032] A second sending module, configured to send the public key intermediate value, the first signature final value, and the signature intermediate value to the terminal of the target user, so that the terminal of the target user generates a second signature final value based on the first signature final value, the signature intermediate value, and the private key of the terminal of the target user; and generates a public key final value based on the public key intermediate value and the private key of the terminal of the target user.
[0033] In a sixth aspect, an embodiment of the present application provides a collaborative signature device, which is applied to the terminal of the target user. The device includes:
[0034] A second signature final value generation module, configured to generate a second signature final value based on the first signature final value, the signature intermediate value, and the private key of the terminal of the target user sent by the second server;
[0035] A public key final value generation module, configured to generate a public key final value based on the public key intermediate value and the private key of the terminal of the target user sent by the second server;
[0036] A third sending module, configured to send the first signature final value, the second signature final value, and the public key final value to the first server, so that the first server determines the signature result of the target file to be signed based on the hash value of the target file to be signed, the public key final value, the first signature final value, and the second signature final value.
[0037] In a seventh aspect, an embodiment of the present application provides a computer storage medium, which stores multiple instructions, and the instructions are suitable for being loaded and executed by a processor to perform the method steps of any of the above aspects.
[0038] In an eighth aspect, an embodiment of the present application provides a first server, which may include: a processor and a memory; wherein, the memory stores a computer program, and the computer program is suitable for being loaded and executed by the processor to perform the method steps of the first aspect above.
[0039] In a ninth aspect, an embodiment of the present application provides a second server, which may include: a processor and a memory; wherein, the memory stores a computer program, and the computer program is suitable for being loaded and executed by the processor to perform the method steps of the second aspect above.
[0040] In a tenth aspect, an embodiment of the present application provides a terminal, which may include: a processor and a memory; wherein, the memory stores a computer program, and the computer program is suitable for being loaded and executed by the processor to perform the method steps of the third aspect above.
[0041] In an eleventh aspect, an embodiment of the present application provides a collaborative signature system, which may include: the first server above, the second server above, and the terminal above.
[0042] The beneficial effects brought by the technical solutions provided in some embodiments of the present application at least include:
[0043] In the embodiments of the present application, the embodiments of the present application can encrypt the signature request information of the target user through the public key of the certificate authorization center, that is, encrypt the user's identity information and the hash value of the target file, so as to protect the user's privacy information from leakage and prevent the hash value of the target file from being tampered with. In addition, the first server can also verify the correctness of the signature value of the target file to be signed based on the first signature final value generated by the private key of the second server, the second signature final value and the public key final value generated by the private key of the terminal of the target user, thereby completing the collaborative signature process in the present application, so as to effectively ensure the security and reliability of information transmission in the system. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required in the embodiments. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0045] Figure 1 An application scenario of the collaborative signature method for the related technology provided in the embodiments of the present application;
[0046] Figure 2 A system architecture diagram of the collaborative signature method provided in the embodiments of the present application;
[0047] Figure 3 A flowchart of the collaborative signature method provided in the embodiments of the present application;
[0048] Figure 4A A flowchart of the collaborative signature algorithm in the second server provided in the embodiments of the present application;
[0049] Figure 4B A flowchart of the collaborative signature algorithm in the terminal provided in the embodiments of the present application;
[0050] Figure 4C A flowchart of the signature value verification algorithm in the first server provided in the embodiments of the present application;
[0051] Figure 5 A structural diagram of the collaborative signature system provided in the embodiments of the present application
[0052] Figure 6 A structural diagram of the collaborative signature device applied to the first server provided in the embodiments of the present application;
[0053] Figure 7 Schematic structural diagram of the collaborative signature device applied to the second server provided by an embodiment of the present application;
[0054] Figure 8 Schematic structural diagram of the collaborative signature device applied to the terminal provided by an embodiment of the present application;
[0055] Figure 9 Schematic structural diagram of the first server provided by an embodiment of the present application;
[0056] Figure 10 Schematic structural diagram of the second server provided by an embodiment of the present application;
[0057] Figure 11 Schematic structural diagram of the terminal provided by an embodiment of the present application. Detailed implementation manners
[0058] When the following description relates to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The implementation manners described in the following exemplary embodiments do not represent all implementation manners consistent with the present application. On the contrary, they are merely examples of systems and methods consistent with some aspects of the present application as detailed in the appended claims.
[0059] In the description of the present application, it should be understood that terms such as "first" and "second" are only used for descriptive purposes and cannot be construed as indicating or implying relative importance. For those of ordinary skill in the art, the specific meanings of the above terms in the present application can be understood according to specific situations. In addition, in the description of the present application, unless otherwise specified, "a plurality of" means two or more than two. "And / or" describes the association relationship of associated objects and indicates that three relationships can exist. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. The character " / " generally represents an "or" relationship between the associated objects before and after.
[0060] Refer to Figure 1 The application scenario of the collaborative signature method in the related art shown. In this application scenario, it includes: the terminal used by the user, the server, and the signature verification party. Among them, the first private key component is stored on the terminal side used by the user; the first private key component of the user and the second private key component of the server are stored on the server side. The first private key component and the second private key component form a complete private key.
[0061] The specific process of collaborative signature can be: in response to the user's request signature operation, the terminal communicates with the server through the network and submits service data to the server. Then, the server uses the two stored private key components to calculate to complete the collaborative signature of the service data. Finally, the collaborative signature result is submitted to the signature verification party, and the signature verification party verifies the collaborative signature result.
[0062] Among them, the terminal refers to the device that provides local services for users; the server refers to the device that provides services related to the business, such as the Certificate Authority (CA) center; the signature verification party refers to the device that verifies whether the collaborative signature result is legal, which can be a trading platform agreed upon by the user and the business party.
[0063] For example, in the process of electronic bidding and tendering, the process of the bid evaluator signing and confirming the evaluation result usually requires the use of collaborative signature technology. Generally, in the electronic bidding and tendering process, the bidder needs to obtain the bidding documents through the trading platform and apply for a digital certificate through the CA center. Then, the bidder needs to use the document preparation tool to prepare the bidding documents offline, affix the unit seal on the bidding documents in the form of an electronic signature, encrypt the bidding documents and upload them to the trading platform. The bid evaluator registers with the trading platform with real names and obtains the account password for logging in to the trading platform. After the bid evaluator confirms the identity information and enters the signature handwriting in the CA center, the CA center issues a digital certificate for it. However, the digital certificate and the corresponding private key need to be entrusted to the CA center and the CA center will proxy its digital signature according to business needs. When the bid evaluator logs in to the trading platform through the correct account password on the terminal and clicks the signature button, the trading platform sends the bid evaluator's identity information and signature request to the CA center. The CA center then retrieves the private key of the corresponding bid evaluator's digital certificate and the private key of the CA center according to the bid evaluator's identity information to complete the digital signature. The CA center returns the signature result to the trading platform, and the signature process of the bid evaluator ends.
[0064] As can be seen from the above, in the related technology, the collaborative signature method can actually be completely signed on behalf of by the server, and the user's terminal side does not participate in the interaction process of the collaborative algorithm, so there is a risk that the private key may be tampered with. Moreover, the collaborative signature method in the related technology does not protect the privacy information of the signature party, and there may be a risk of leakage of the privacy information of the signature party during the transmission process.
[0065] Therefore, the present application provides a collaborative signature method, which can encrypt the signature request information of the target user through the public key of the certificate authority center, that is, encrypt the user's identity information and the hash value of the target file, so as to protect the user's privacy information from leakage and prevent the hash value of the target file from being tampered with. In addition, the first server can also verify the correctness of the signature value of the target file to be signed based on the first signature final value generated by the private key of the second server, the second signature final value generated by the private key of the target user's terminal, and the public key final value, so as to complete the collaborative signature process in the present application, effectively ensuring the security and reliability of information transmission in the system.
[0066] Figure 2The system architecture diagram of the collaborative signature method applied to the embodiments of the present application is shown. Among them, the collaborative signature method provided by the embodiments of the present application can be applied in the local terminal 21 of user 20, the first server 22, and the second server 23. Specifically, the terminal 21 can be connected to the first server 22 and the second server 23 respectively through the network. The network is used to provide a communication link between the terminal 21, the first server 22, and the second server 23. The network can include various connection types, such as wired, wireless communication links, or fiber optic cables, etc. The terminal includes but is not limited to: wearable devices, monitoring devices, handheld devices, personal computers, tablet computers, in-vehicle devices, smartphones, computing devices, or other processing devices connected to a wireless modem, etc. In different networks, the terminal 21 can be called different names, such as: monitoring devices, user equipment, access terminals, user units, user stations, mobile stations, mobile phones, remote stations, remote terminals, mobile devices, user terminals, terminals, wireless communication devices, user agents, or user devices, cellular phones, cordless phones, personal digital assistants (PDAs), terminal devices in 5th generation mobile networks (5G) or future evolved networks, etc. The terminal system refers to the operating system that can run on the terminal, which is a program for managing and controlling the terminal hardware and terminal applications, and is an indispensable system application of the terminal. The system includes but is not limited to the Android system, the IOS system, the Windows phone (WP) system, and the Ubuntu mobile operating system, etc.
[0067] Next, in combination with Figure 2 the system architecture diagram of the collaborative signature method provided by the embodiments of the present application shown, the collaborative signature method provided by the embodiments of the present application will be introduced.
[0068] In one embodiment, Figure 3 as shown, a flowchart of a collaborative signature method is provided. As Figure 3 shown, the collaborative signature method can include the following steps:
[0069] S301, the first server generates signature request information based on the signature request signal sent by the terminal of the target user.
[0070] Among them, the first server represents the server corresponding to the third-party platform. For example, it is the platform where the target user browses the information to be signed. For instance, the company uploads the monthly salary of its employees to the server corresponding to Platform A. Employees can log in to Platform A (i.e., log in to the server corresponding to Platform A) by means of account passwords to view their salary information. If the salary calculation is correct, they can click the "Confirm" button to perform signature verification on the salary information. Alternatively, the first server can also be the server corresponding to the trading platform in the bidding scenario.
[0071] Possibly, the terminal in the embodiments of the present application can be the computer terminal used by the target user. The target user can log in to the first server through a browser to access the first server. For example, the bid evaluator can log in to the trading platform displayed in the computer terminal browser through his account and password. After the bid evaluator views the decrypted bidding documents of Company A online, he fills in the bid evaluation results (such as the comments on Company A's bidding documents or the scores of Company A's bidding documents), and then clicks the "Signature Button" on the browser interface. The computer terminal can then send a signature request signal to the server corresponding to the trading platform.
[0072] Furthermore, the signature request information generated by the first server in the embodiments of the present application may include: the identity information of the target user and the hash value of the target file to be signed.
[0073] Specifically, the identity information of the target user in the embodiments of the present application can be the unique identification information of the target user, which includes but is not limited to: information that can identify the user's identity such as the user's name, ID number, mobile phone number, email address, etc. Furthermore, the first server and the second server can also determine the Internet Protocol Address (IP) of the terminal where the target user is located according to the identity information of the target user, and communicate with it according to the user's IP address. The target file to be signed represents the text content that needs to be electronically signed after being browsed by the target user.
[0074] It can be understood that after the user in the embodiments of the present application views the target file online, in order to protect the security of the content of the target file to be signed, it is necessary to perform a hash process on the target file to be signed to prevent the target file from being leaked or tampered with.
[0075] It should be noted that before the bid evaluator (i.e., the "signing party") clicks the "Signature Button", they need to log in to the collaborative signature application (Application, app) in their mobile terminal, set a signature password "password", so as to randomly generate a private key "d1" (the length of d1 is 256 bits) on the client side of the collaborative signature app. To prevent the user's private key "d1" from being stolen or leaked, "d1" can be encrypted with "password" as the symmetric key to obtain the user's encrypted private key "D1" (the symmetric encryption algorithm here can be AES or SM4), and "D1" is securely stored on the client side of the collaborative signature app.
[0076] S302, the first server encrypts the signature request information with the public key of the certificate authority center to obtain the encrypted information.
[0077] Specifically, in the embodiment of the present application, the first server and the terminal of the target user have previously obtained and stored the digital certificate of the CA center and the public key "P" of the CA center from the CA center.
[0078] It can be understood that in the embodiment of the present application, in order to prevent the signature request information from being intercepted during transmission and causing the leakage of the identity information of the target user, the public key of the CA center is used to encrypt the signature request information, and the encrypted information obtained after encryption is transmitted to improve the security of information transmission.
[0079] For example, the trading platform encrypts the identity information "ID1" of the bid evaluator and the hash value "e" of the tender document to be signed in the signature request information with the public key "P" of the CA, and after obtaining the encrypted information, sends the encrypted information to the second server to initiate the collaborative signature scheme of the target document to be signed between the second server and the terminal of the target user.
[0080] S303, the second server generates a public key intermediate value based on the private key of the second server.
[0081] Possibly, the second server in the embodiment of the present application can be a CA collaborative signature server, and this CA collaborative signature server can communicate with the CA center server to obtain relevant information.
[0082] Specifically, the CA collaborative signature server of the second server in the embodiment of the present application needs to communicate with the CA center server in advance to obtain the digital certificate of the CA center, and this digital certificate includes the public key of the CA center.
[0083] In addition, the CA collaborative signature server in the embodiments of the present application also pre-stores the identity information of multiple users and the public keys of each user. That is to say, in the actual application scenario, the identity information of each user will be pre-stored in the CA collaborative signature server, so that the CA collaborative signature server can determine whether to perform the next operation according to the identity information of the sender.
[0084] Suppose the identity information of the sender matches one of the user information in the CA collaborative signature server, then the CA collaborative signature server will generate a random number as its private key d.
[0085] Possibly, the embodiments of the present application can calculate the public key intermediate value PZ in the following way:
[0086] PZ = d * G;
[0087] Wherein, G represents the base point of order n on the elliptic curve, the parameter n is a fixed value, and * represents the point multiplication operation on the elliptic curve.
[0088] The elliptic curve in the embodiments of the present application refers to the elliptic curve in Elliptic curve cryptography (ECC) cryptography. ECC is an asymmetric encryption algorithm based on the mathematical theory of elliptic curves, which can be used in the collaborative signature process of two peer communication entities. That is to say, the two communication parties can implement collaborative signature by executing the specified protocol.
[0089] S304, the second server decrypts the encrypted information with the private key of the certificate authority to obtain the hash value of the target file to be signed and the identity information of the target user.
[0090] Specifically, the second server in the embodiments of the present application can send the encrypted information to the CA central server, so that the CA central server decrypts the encrypted information with its private key to obtain the hash value of the target file to be signed and the identity information of the target user, and sends the decrypted information back to the second server.
[0091] For example, the CA collaborative signature server can use the CA central server to decrypt the received encrypted information to obtain the identity information ID1 of the bid evaluator and the hash value e of the bid file to be signed.
[0092] Specifically, when the terminal of the target user encrypts the identity information ID1 and the hash value e of the bid file to be signed with the public key P of the CA, the SM2 encryption algorithm can be used; when the CA central server decrypts the received encrypted information, the SM2 decryption algorithm can be used.
[0093] S305. The second server generates a first signature final value based on the public key intermediate value and the hash value of the target file to be signed.
[0094] Possibly, the second server in the embodiments of the present application may include two modules. Module 1 may be a collaborative signature calculation module, which is used to calculate the first signature final value r and the signature intermediate value s0. Module 2 may be a public key calculation module, which is used to calculate the public key intermediate value PZ of the collaborative signature.
[0095] Specifically, the collaborative signature calculation module in the embodiments of the present application may determine the second elliptic curve coordinates based on the public key intermediate value, the n - order base point on the elliptic curve, and a random number. Generate the first signature final value based on the second elliptic curve coordinates and the hash value of the target file to be signed. Generate the signature intermediate value based on the random number, the first signature final value, and the private key of the second server.
[0096] See Figure 4A the flow schematic diagram of the collaborative signature algorithm in the second server shown in
[0097] 1) Generate a random number k, k < n. Wherein, the random number k is randomly generated by the second server in each collaborative signature process, that is, the random number k is different when the target user signs different target files. The value of the parameter n is the same as the order of the n - order base point on the elliptic curve.
[0098] 2) Calculate the second elliptic curve coordinates (x1, y1) = k * G+PZ. Wherein, x1 and y1 are respectively the abscissa and ordinate of the point on the elliptic curve. If the second elliptic curve coordinates (x1, y1) are the origin (0, 0), then return to step 1) to regenerate the random number k. If the second elliptic curve coordinates (x1, y1) are not the origin (0, 0), then continue the calculation.
[0099] 3) Calculate the first signature final value r=(x1 + e) mod n. Wherein, e is the hash value of the target file to be signed, and mod is the modulo operation.
[0100] S306. The second server generates a signature intermediate value based on the first signature final value and the private key of the second server.
[0101] Specifically, the public key calculation module in the embodiments of the present application may generate the signature intermediate value s0 based on the first signature final value r and the private key of the second server, that is, the private key d of the CA collaborative signature server.
[0102] See Figure 4A the flow schematic diagram of the collaborative signature algorithm in the second server shown in
[0103] s0 = [(k + r)·d^(-1) + 1] mod n;
[0104] where · is the large number multiplication modulo n, and d^(-1) is the inverse operation of d modulo n.
[0105] S307. The second server determines the terminal of the target user based on the identity information of the target user.
[0106] It can be understood that in the embodiments of the present application, the IP address of the corresponding terminal can be found according to the user's identity information ID1, and the first signature final value r, the signature intermediate value s0, and the public key intermediate value PZ are transmitted to the terminal of the target user, such as the collaborative signature app client of the bid evaluator, to complete the collaborative signature scheme on the user terminal side in the embodiments of the present application.
[0107] S308. The terminal of the target user generates a second signature final value based on the first signature final value, the signature intermediate value, and the private key of the terminal of the target user sent by the second server.
[0108] It can be understood that in the embodiments of the present application, the private key of the terminal of the target user can be obtained in the following manner: The target user can input the signature password password on the mobile terminal, and the terminal will read the encrypted private key D1 of the user and decrypt D1 with password to obtain the private key dl of the terminal of the target user.
[0109] For example, the bid evaluator inputs the signature password password on the collaborative signature app client, and the app client reads the encrypted private key D1 and decrypts D1 with password as the symmetric key (consistent with the symmetric encryption algorithm used in S301, which can also be the AES algorithm or the SM4 algorithm) to obtain the plaintext private key d1.
[0110] Possibly, the app of the terminal of the user in the embodiments of the present application may include two modules. Module 1 is the collaborative signature calculation module, which can be used to calculate the second signature final value s; Module 2 is the public key calculation module, which can be used to calculate the public key final value PA of the collaborative signature.
[0111] See Figure 4B the flow schematic diagram of the collaborative signature algorithm in the terminal of the user shown. The calculation method of the second signature final value s in the embodiments of the present application is as follows:
[0112] s = [s0·d1^(-1) - r] mod n;
[0113] where · is the large number multiplication modulo n, and d1^(-1) is the inverse operation of d1 modulo n.
[0114] Therefore, the final signature value of the collaborative signature in the embodiment of the present application is (r, s).
[0115] S309. The terminal of the target user generates the final public key based on the intermediate public key sent by the second server and the private key of the terminal of the target user.
[0116] See Figure 4B For the schematic flowchart of the collaborative signature algorithm in the terminal of the user shown, the calculation method of the final public key PA in the embodiment of the present application is as follows:
[0117] PA = d1 * PZ - G;
[0118] Where G is the base point of order n on the elliptic curve, * is the point multiplication operation on the elliptic curve, and - is the point subtraction operation on the elliptic curve.
[0119] Further, after the calculation is completed in the embodiment of the present application, the terminal app will automatically delete the private key d1 used during the calculation in the cache to ensure the security of the private key d1, and then send the final signature value (r, s) and the final public key PA to the first server.
[0120] S310. The first server determines the signature result of the target file to be signed based on the hash value corresponding to the target file to be signed, the final public key, the first final signature value, and the second final signature value.
[0121] Specifically, the first server in the embodiment of the present application can determine the first elliptic curve coordinates based on the final public key, the first final signature value, and the second final signature value; determine the signature verification value based on the first elliptic curve coordinates and the hash value of the target file to be signed; if the signature verification value is the same as the first final signature value, the target file is successfully signed; if the signature verification value is different from the first final signature value, the target file is failed to be signed.
[0122] See Figure 4C For the schematic flowchart of the signature value verification algorithm in the first server shown, the specific algorithm for verifying the validity of the signature value is as follows:
[0123] 1) Calculate the first elliptic curve coordinates (x2, y2) = s * G + (r + s) * PA;
[0124] 2) Calculate the signature verification value r' = (x2 + e) mod n. If the signature verification value r' = the first final signature value r, the final signature value is correct and the target file is successfully signed; otherwise, the final signature value is incorrect and the target file is failed to be signed.
[0125] It can be understood that if the abscissa and ordinate of the first elliptic curve coordinates (x2, y2) and the second elliptic curve coordinates (x1, y1) in step 1) are equal, that is, x1 = x2 and y1 = y2, then the signature verification value r' is also equal to the first signature final value r.
[0126] The specific demonstration process of the relationship between the first elliptic curve coordinates (x2, y2) and the second elliptic curve coordinates (x1, y1) is as follows:
[0127] (x2, y2) = s * G + (r + s) * PA
[0128] = [s0 · d1^(-1) - r] * G + (r + s) · (d1 · d - 1) * G
[0129] = [[s0 · d1^(-1) - r] + [r + [s0 · d1^(-1) - r]] · (d1 · d - 1)] * G
[0130] = [[s0 · d1^(-1) - r] + [s0 · d1^(-1)] · (d1 · d - 1)] * G
[0131] = [s0 · d1^(-1) · d1 · d - r] * G
[0132] = [s0 · d - r] * G
[0133] = [[(k + r) · d^(-1) + 1] · d - r] * G
[0134] = [[(k + r) · d^(-1) · d + d] - r] * G
[0135] = [[(k + r) + d] - r] * G
[0136] = [k + d] * G
[0137] = (x1, y1)
[0138] Therefore, the embodiments of the present application can realize the processes of collaborative signature and signature verification by defining the collaborative signature algorithm and the signature value verification algorithm. And since the processor in the second server of the embodiments of the present application performs parallel processing during operation, therefore, it only needs to consider the processing time of one point multiplication operation when calculating the two elliptic curve coordinates with longer calculation time. In this way, the operation time of the processor can be shortened, the communication times of all parties can be reduced, thereby reducing the waiting time of users and improving the user experience.
[0139] To better understand the collaborative signature method provided by the embodiments of the present application, the embodiments of the present application also provide a collaborative signature system. Figure 5It is a schematic structural diagram of a collaborative signature system provided by an exemplary embodiment of the present application. The collaborative signature system may include a desktop computer, a mobile terminal, a trading platform, and a CA collaborative signature server. Among them, the CA collaborative signature server and the CA center server can communicate with each other, and the collaborative signature system can execute the collaborative signature method described in any of the above embodiments of the present application.
[0140] In a specific example, in the review session of the bidding scenario, the bid evaluator can log in to the trading platform through the desktop computer side, that is, the server at the back end of the trading platform, to browse the bidding documents of each bidding company in the trading platform online, score each bidding document, and then click the "Signature Button" in the browser interface. The computer side can send a signature request signal of the bid evaluator to the corresponding server of the trading platform. The trading platform will generate a signature request message of the bid evaluator based on the signature request signal sent by the bid evaluator's computer side, and encrypt the signature request message using the public key of the CA center to obtain an encrypted message. Subsequently, the trading platform sends the encrypted message to the CA collaborative signature server to enter the collaborative signature stage. The CA collaborative signature server will generate a public key intermediate value based on the private key of the CA collaborative signature server, and communicate with the CA center server, so that the CA center server decrypts the encrypted message using its private key to obtain the hash value of the bidding document to be signed and the identity information of the target user. Then, based on the public key intermediate value and the hash value of the bidding document to be signed, a first signature final value is generated. Then, based on the first signature final value and the private key of the CA collaborative signature server, a signature intermediate value is generated, and the IP address of the bid evaluator's mobile terminal is determined through the identity information of the target user. The first signature final value, the signature intermediate value, and the public key intermediate value are transmitted to the collaborative signature app in the bid evaluator's mobile terminal, so that the bid evaluator can complete the signature verification process of the target document to be signed through the mobile terminal. When the signature verification value is the same as the first signature final value, the bidding document is successfully signed.
[0141] Therefore, the collaborative signature system in the embodiment of the present application can use the browser on the computer side to facilitate users to browse the target document, and use the app on the mobile terminal to enable users to participate in the collaborative signature process. Its operation is simple and convenient, and the app on the mobile terminal side can encrypt and store a part of the private key of the bid evaluator through the bid evaluator's password, effectively improving the security of the system.
[0142] Figure 6 It is a schematic structural diagram of a collaborative signature device provided by an exemplary embodiment of the present application. The collaborative signature method device can execute the collaborative signature method described in any of the above embodiments of the present application. As Figure 6 shown, the collaborative signature device is used for the first server, and the collaborative signature device may include:
[0143] The signature request information generation module 61 is configured to generate signature request information based on a signature request signal sent by a target user's terminal; wherein, the signature request information includes: the identity information of the target user and the hash value of the target file to be signed;
[0144] The encryption information obtaining module 62 is configured to encrypt the signature request information using the public key of the certificate authority to obtain encrypted information;
[0145] The first sending module 63 is configured to send the encrypted information to a second server, so that the second server generates a public key intermediate value based on the private key of the second server, generates a first signature final value based on the encrypted information and the public key intermediate value, generates a signature intermediate value based on the first signature final value and the private key of the second server, and sends the public key intermediate value, the first signature final value, and the signature intermediate value to the target user's terminal, so that the target user's terminal generates a second signature final value based on the first signature final value, the signature intermediate value, and the private key of the target user's terminal; generates a public key final value based on the public key intermediate value and the private key of the target user's terminal, and sends the first signature final value, the second signature final value, and the public key final value to the first server;
[0146] The signature result verification module 64 is configured to determine the signature result of the target file to be signed based on the hash value of the target file to be signed, the public key final value, the first signature final value, and the second signature final value.
[0147] Thus, the present application can encrypt the signature request information of the target user through the public key of the certificate authority, that is, encrypt the identity information of the user and the hash value of the target file, so as to protect the privacy information of the user from being leaked and prevent the hash value of the target file from being tampered with. In addition, the first server can also verify the correctness of the signature value of the target file to be signed based on the first signature final value generated by the private key of the second server, the second signature final value generated by the private key of the target user's terminal, and the public key final value, thereby completing the collaborative signature process in the present application to effectively ensure the security and reliability of information transmission in the system.
[0148] In some embodiments, the signature result verification module 64 includes:
[0149] The first elliptic curve coordinate determination unit determines the first elliptic curve coordinate based on the public key final value, the first signature final value, and the second signature final value;
[0150] The signature verification value determination unit is configured to determine the signature verification value based on the first elliptic curve coordinate and the hash value of the target file to be signed;
[0151] A determination unit, configured to determine that the signature of the target file is successful if the signature verification value is the same as the first final signature value; and determine that the signature of the target file is failed if the signature verification value is different from the first final signature value.
[0152] Figure 7 It is a schematic structural diagram of a collaborative signature device provided by an exemplary embodiment of the present application. This collaborative signature method device can execute the collaborative signature method in any of the above embodiments of the present application. As Figure 7 shown, the collaborative signature device is for a second server, and the collaborative signature device may include:
[0153] A public key intermediate value generation module 71, configured to generate a public key intermediate value based on the private key of the second server;
[0154] A decryption module 72, configured to decrypt the encrypted information using the private key of the certificate authority center to obtain the hash value of the target file to be signed and the identity information of the target user;
[0155] A first final signature value generation module 73, configured to generate a first final signature value based on the public key intermediate value and the hash value of the target file to be signed;
[0156] A signature intermediate value generation module 74, configured to generate a signature intermediate value based on the first final signature value and the private key of the second server;
[0157] A terminal confirmation module 75, configured to determine the terminal of the target user based on the identity information of the target user;
[0158] A second sending module 76, configured to send the public key intermediate value, the first final signature value, and the signature intermediate value to the terminal of the target user, so that the terminal of the target user generates a second final signature value based on the first final signature value, the signature intermediate value, and the private key of the terminal of the target user; and generate a public key final value based on the public key intermediate value and the private key of the terminal of the target user.
[0159] In some embodiments, the first final signature value generation module 73 includes:
[0160] A second elliptic curve coordinate determination unit, configured to determine a second elliptic curve coordinate based on the public key intermediate value, an n-order base point on the elliptic curve, and a random number;
[0161] A first final signature value generation unit, configured to generate the first final signature value based on the second elliptic curve coordinate and the hash value of the target file to be signed;
[0162] The signature intermediate value generation module is specifically configured to:
[0163] Generate the signature intermediate value based on the random number, the first signature final value, and the private key of the second server.
[0164] Figure 8 It is a schematic structural diagram of a collaborative signature device provided by an exemplary embodiment of the present application. This collaborative signature method device can execute the collaborative signature method in any of the above embodiments of the present application. As Figure 8 shown, the terminal of the target user for this collaborative signature device, this collaborative signature device may include:
[0165] A second signature final value generation module 81, configured to generate a second signature final value based on the first signature final value, the signature intermediate value, and the private key of the terminal of the target user sent by the second server;
[0166] A public key final value generation module 82, configured to generate a public key final value based on the public key intermediate value sent by the second server and the private key of the terminal of the target user;
[0167] A third sending module 83, configured to send the first signature final value, the second signature final value, and the public key final value to the first server, so that the first server determines the signature result of the target file to be signed based on the hash value of the target file to be signed, the public key final value, the first signature final value, and the second signature final value.
[0168] It should be noted that when the collaborative signature device provided in the above embodiment executes the collaborative signature method, only the above-mentioned division of each functional module is used for illustration. In actual application, the above functions can be allocated to different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above. In addition, the collaborative signature device provided in the above embodiment and the collaborative signature method embodiment belong to the same concept, and the implementation process thereof is detailed in the method embodiment, which will not be elaborated here.
[0169] The serial numbers of the above embodiments of the present application are only for description and do not represent the advantages or disadvantages of the embodiments.
[0170] Please refer to Figure 9 , which provides a schematic structural diagram of a first server for an embodiment of the present application. As Figure 9 shown, the first server 90 may include: at least one processor 91, at least one network interface 94, a user interface 93, a memory 95, and at least one communication bus 92.
[0171] Among them, the communication bus 92 is used to realize the connection and communication between these components.
[0172] Among them, the user interface 93 may include a display screen and a camera. Optionally, the user interface 93 may further include a standard wired interface and a wireless interface.
[0173] Among them, the network interface 94 may optionally include a standard wired interface and a wireless interface (such as a WI-FI interface).
[0174] Among them, the processor 91 may include one or more processing cores. The processor 91 connects various parts within the entire first server 90 through various interfaces and circuits. By running or executing instructions, programs, code sets, or instruction sets stored in the memory 95, and by calling the data stored in the memory 95, it executes various functions of the first server 90 and processes data. Optionally, the processor 91 may be implemented in at least one of the following hardware forms: digital signal processing (DSP), field-programmable gate array (FPGA), and programmable logic array (PLA). The processor 91 may integrate one or a combination of several of the following: a central processing unit (CPU), a graphics processing unit (GPU), and a modem. Among them, the CPU mainly processes the operating system, the user interface, and application programs, etc.; the GPU is responsible for rendering and drawing the content to be displayed on the display screen; the modem is used to process wireless communications. It can be understood that the above-mentioned modem may not be integrated into the processor 91 and may be implemented separately by a single chip.
[0175] Among them, the memory 95 may include random access memory (RAM) and may also include read-only memory. Optionally, the memory 95 includes a non-transitory computer-readable storage medium. The memory 65 can be used to store instructions, programs, code, code sets, or instruction sets. The memory 95 may include a program storage area and a data storage area. Among them, the program storage area may store instructions for implementing the operating system, instructions for at least one function (such as a touch function, a sound playback function, an image playback function, etc.), instructions for implementing the above-mentioned various method embodiments, etc.; the data storage area may store the data involved in the above-mentioned various method embodiments. Optionally, the memory 95 may further be at least one storage system located far from the aforementioned processor 91. Such as Figure 9As shown in the figure, the memory 95, which is a computer storage medium, may include an operating system, a network communication module, a user interface module, and a collaborative signature method application program.
[0176] In Figure 9 In the first server 90 shown in the figure, the user interface 93 is mainly used to provide an interface for the user to input data and obtain the data input by the user; while the processor 91 can be used to call the collaborative signature method application program stored in the memory 95 and specifically perform the following operations:
[0177] Generate signature request information based on the signature request signal sent by the terminal of the target user; wherein, the signature request information includes: the identity information of the target user and the hash value of the target file to be signed;
[0178] Encrypt the signature request information using the public key of the certificate authority to obtain encrypted information;
[0179] Send the encrypted information to the second server, so that the second server generates a public key intermediate value based on the private key of the second server, generates a first signature final value based on the encrypted information and the public key intermediate value, generates a signature intermediate value based on the first signature final value and the private key of the second server, and sends the public key intermediate value, the first signature final value, and the signature intermediate value to the terminal of the target user, so that the terminal of the target user generates a second signature final value based on the first signature final value, the signature intermediate value, and the private key of the terminal of the target user; generate a public key final value based on the public key intermediate value and the private key of the terminal of the target user, and send the first signature final value, the second signature final value, and the public key final value to the first server;
[0180] Determine the signature result of the target file to be signed based on the hash value of the target file to be signed, the public key final value, the first signature final value, and the second signature final value.
[0181] In some embodiments, when the processor 91 executes the operation of determining the signature result of the target file to be signed based on the hash value of the target file to be signed, the public key final value, the first signature final value, and the second signature final value, it specifically executes:
[0182] Determine the first elliptic curve coordinates based on the public key final value, the first signature final value, and the second signature final value;
[0183] Determine the signature verification value based on the first elliptic curve coordinates and the hash value of the target file to be signed;
[0184] If the signature verification value is the same as the first signature final value, the signature of the target file is successful;
[0185] If the signature verification value is different from the first signature final value, the signature of the target file fails.
[0186] Please refer to Figure 10 , which provides a schematic structural diagram of a second server for an embodiment of the present application. As Figure 10 shown, the second server 100 may include: at least one processor 110, at least one network interface 140, a user interface 130, a memory 150, and at least one communication bus 120.
[0187] Among them, the communication bus 120 is used to implement connection communication between these components.
[0188] Among them, the user interface 130 may include a display screen (Display) and a camera (Camera). Optionally, the user interface 130 may further include a standard wired interface and a wireless interface.
[0189] Among them, the network interface 140 may optionally include a standard wired interface and a wireless interface (such as a WI-FI interface).
[0190] Among them, the processor 110 may include one or more processing cores. The processor 110 uses various interfaces and lines to connect various parts within the entire second server 100, and by running or executing instructions, programs, code sets, or instruction sets stored in the memory 150, as well as calling data stored in the memory 150, it executes various functions of the second server 100 and processes data. Optionally, the processor 110 may be implemented in at least one hardware form of digital signal processing (DSP), field-programmable gate array (FPGA), or programmable logic array (PLA). The processor 110 may integrate one or a combination of several of a central processing unit (CPU), a graphics processing unit (GPU), and a modem, etc. Among them, the CPU mainly processes the operating system, user interface, and application programs, etc.; the GPU is responsible for rendering and drawing the content required to be displayed on the display screen; the modem is used to process wireless communication. It can be understood that the above modem may not be integrated into the processor 110 and may be implemented separately by a single chip.
[0191] Among them, the memory 150 may include a Random Access Memory (RAM), or may also include a Read-Only Memory. Optionally, the memory 150 includes a non-transitory computer-readable storage medium. The memory 150 can be used to store instructions, programs, codes, code sets, or instruction sets. The memory 150 may include a program storage area and a data storage area. Among them, the program storage area may store instructions for implementing an operating system, instructions for at least one function (such as a touch function, a sound playback function, an image playback function, etc.), instructions for implementing the above-mentioned method embodiments, etc.; the data storage area may store data involved in the above-mentioned method embodiments. Optionally, the memory 150 may also be at least one storage system located far from the aforementioned processor 110. As Figure 10 shown, in the memory 150 as a computer storage medium, an operating system, a network communication module, a user interface module, and a collaborative signature method application program may be included.
[0192] In Figure 10 the second server 100 shown, the user interface 130 is mainly used to provide an input interface for the user and obtain user input data; while the processor 110 can be used to call the collaborative signature method application program stored in the memory 150 and specifically perform the following operations:
[0193] Generate a public key intermediate value based on the private key of the second server;
[0194] Decrypt the encrypted information using the private key of the certificate authority to obtain the hash value of the target file to be signed and the identity information of the target user;
[0195] Generate a first signature final value based on the public key intermediate value and the hash value of the target file to be signed;
[0196] Generate a signature intermediate value based on the first signature final value and the private key of the second server;
[0197] Determine the terminal of the target user based on the identity information of the target user;
[0198] Send the public key intermediate value, the first signature final value, and the signature intermediate value to the terminal of the target user, so that the terminal of the target user generates a second signature final value based on the first signature final value, the signature intermediate value, and the private key of the terminal of the target user; generate a public key final value based on the public key intermediate value and the private key of the terminal of the target user.
[0199] In some embodiments, when the processor 110 generates the first signature final value by executing based on the public key intermediate value and the hash value of the target file to be signed, it specifically executes:
[0200] Determine the second elliptic curve coordinate based on the public key intermediate value, the n-order base point on the elliptic curve, and the random number;
[0201] Generate the first signature final value based on the second elliptic curve coordinate and the hash value of the target file to be signed;
[0202] The generating the signature intermediate value based on the first signature final value and the private key of the second server includes:
[0203] Generate the signature intermediate value based on the random number, the first signature final value, and the private key of the second server.
[0204] Please refer to Figure 11 , which provides a schematic structural diagram of a terminal according to an embodiment of the present application. As Figure 11 shown, the terminal 200 may include: at least one processor 210, at least one network interface 240, a user interface 230, a memory 250, and at least one communication bus 220.
[0205] Among them, the communication bus 220 is used to implement connection communication between these components.
[0206] Among them, the user interface 230 may include a display screen (Display), a camera (Camera), and optionally the user interface 230 may further include a standard wired interface and a wireless interface.
[0207] Among them, the network interface 240 may optionally include a standard wired interface and a wireless interface (such as a WI-FI interface).
[0208] Among them, the processor 210 may include one or more processing cores. The processor 210 uses various interfaces and circuits to connect various parts within the entire terminal 200. By running or executing instructions, programs, code sets, or instruction sets stored in the memory 250, and by calling the data stored in the memory 250, it executes various functions of the terminal 250 and processes data. Optionally, the processor 210 may be implemented in at least one hardware form of digital signal processing (DSP), field-programmable gate array (FPGA), or programmable logic array (PLA). The processor 210 may integrate a combination of one or several of a central processing unit (CPU), a graphics processing unit (GPU), and a modem, etc. Among them, the CPU mainly processes the operating system, user interface, application programs, etc.; the GPU is responsible for the rendering and drawing of the content to be displayed on the display screen; the modem is used to process wireless communications. It can be understood that the above-mentioned modem may not be integrated into the processor 210 and may be implemented separately by a single chip.
[0209] Among them, the memory 250 may include random access memory (RAM) and may also include read-only memory. Optionally, the memory 250 includes a non-transitory computer-readable storage medium. The memory 250 can be used to store instructions, programs, code, code sets, or instruction sets. The memory 250 may include a program storage area and a data storage area. Among them, the program storage area may store instructions for implementing the operating system, instructions for at least one function (such as touch function, sound playback function, image playback function, etc.), instructions for implementing the above-mentioned various method embodiments, etc.; the data storage area may store the data involved in the above-mentioned various method embodiments. Optionally, the memory 250 may also be at least one storage system located far from the aforementioned processor 210. As Figure 11 shown, the memory 250, as a computer storage medium, may include an operating system, a network communication module, a user interface module, and a collaborative signature method application program.
[0210] In Figure 11In the terminal 200 of the target user as shown, the user interface 230 is mainly used to provide an interface for the user to input and obtain the data input by the user; and the processor 210 can be used to call the collaborative signature method application program stored in the memory 250 and specifically perform the following operations:
[0211] Generate a second signature final value based on the first signature final value, the signature intermediate value sent by the second server, and the private key of the terminal of the target user;
[0212] Generate a public key final value based on the public key intermediate value sent by the second server and the private key of the terminal of the target user;
[0213] Send the first signature final value, the second signature final value, and the public key final value to the first server, so that the first server determines the signature result of the target file to be signed based on the hash value of the target file to be signed, the public key final value, the first signature final value, and the second signature final value.
[0214] An embodiment of the present application also provides a computer-readable storage medium. Instructions are stored in the computer-readable storage medium. When it runs on a computer or a processor, the computer or the processor is caused to execute one or more steps in the above Figure 3 shown embodiments. If each component module of the above certificate revocation list query device is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in the computer-readable storage medium.
[0215] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable systems. The computer instructions can be stored in a computer-readable storage medium or transmitted through the computer-readable storage medium. The computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center in a wired manner (such as coaxial cable, optical fiber, Digital Subscriber Line (DSL)) or wirelessly (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that the computer can access or a data storage device such as a server or data center that includes one or more integrated available media. The available medium can be a magnetic medium (such as a floppy disk, hard disk, magnetic tape), an optical medium (such as a Digital Versatile Disc (DVD)), or a semiconductor medium (such as a Solid State Disk (SSD)), etc.
[0216] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The program can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above methods. The aforementioned storage medium includes various media that can store program codes, such as a Read Only Memory (ROM), a Random Access Memory (RAM), a magnetic disk, or an optical disc. Without conflict, the technical features in this embodiment and the implementation solutions can be combined arbitrarily.
[0217] The above-described embodiments are merely described in terms of the preferred embodiments of the present application, and do not limit the scope of the present application. Without departing from the design spirit of the present application, various deformations and improvements made by those of ordinary skill in the art to the technical solutions of the present application shall fall within the protection scope determined by the claims of the present application.
Claims
1. A collaborative signature method, the collaborative signature method is applied to a first server, characterized in that, The method includes: Generating signature request information based on a signature request signal sent by a target user's terminal; wherein, the signature request information includes: the identity information of the target user and the hash value of the target file to be signed; Encrypting the signature request information using the public key of a certificate authority to obtain encrypted information; Sending the encrypted information to a second server, so that the second server generates a public key intermediate value based on the private key of the second server, generates a first signature final value based on the encrypted information and the public key intermediate value, determines a second elliptic curve coordinate based on the public key intermediate value, an n - order base point on the elliptic curve, and a random number, the random number being randomly generated by the second server in each collaborative signature process; generating the first signature final value based on the second elliptic curve coordinate and the hash value of the target file to be signed, generating a signature intermediate value based on the random number, the first signature final value, and the private key of the second server, and sending the public key intermediate value, the first signature final value, and the signature intermediate value to the target user's terminal, so that the target user's terminal generates a second signature final value based on the first signature final value, the signature intermediate value, and the private key of the target user's terminal; wherein, the calculation formula for the signature intermediate value is S0 = [(k + r)·d^(-1)+1]mod n; the S0 is the signature intermediate value, the k is the random number, the r is the first signature final value, the d is the private key of the second server, the n is the n - order base point on the elliptic curve, S = [S0·d1^(-1)-r]mod n, the S is the second signature final value, the d1 is the private key of the target user's terminal; generating a public key final value based on the public key intermediate value and the private key of the target user's terminal, and sending the first signature final value, the second signature final value, and the public key final value to the first server; Determining the signature result of the target file to be signed based on the hash value of the target file to be signed, the public key final value, the first signature final value, and the second signature final value.
2. The method according to claim 1, characterized in that, The determining the signature result of the target file to be signed based on the hash value of the target file to be signed, the public key final value, the first signature final value, and the second signature final value includes: Determining a first elliptic curve coordinate based on the public key final value, the first signature final value, and the second signature final value; Determining a signature verification value based on the first elliptic curve coordinate and the hash value of the target file to be signed; If the signature verification value is the same as the first signature final value, the target file is successfully signed; If the signature verification value is different from the first signature final value, the target file is failed to be signed.
3. A collaborative signature method, the collaborative signature method being applied to a second server, characterized in that, The method includes: Generating a public key intermediate value based on the private key of the second server; Decrypting the encrypted information using the private key of the certificate authority to obtain the hash value of the target file to be signed and the identity information of the target user; Generate a first signature final value based on the public key intermediate value and the hash value of the target file to be signed; Generate a signature intermediate value based on the first signature final value and the private key of the second server; Determine the terminal of the target user based on the identity information of the target user; Send the public key intermediate value, the first signature final value, and the signature intermediate value to the terminal of the target user, so that the terminal of the target user generates a second signature final value based on the first signature final value, the signature intermediate value, and the private key of the terminal of the target user. The calculation formula of the second signature final value is S = [S0·d1^(-1)-r] mod n, where S is the second signature final value, d1 is the private key of the terminal of the target user, S0 is the signature intermediate value, and n is the n-order base point on the elliptic curve; generate a public key final value based on the public key intermediate value and the private key of the terminal of the target user; The generating a first signature final value based on the public key intermediate value and the hash value of the target file to be signed includes: Determine a second elliptic curve coordinate based on the public key intermediate value, the n-order base point on the elliptic curve, and a random number, where the random number is randomly generated by the second server in each collaborative signature process; Generate the first signature final value based on the second elliptic curve coordinate and the hash value of the target file to be signed; The generating a signature intermediate value based on the first signature final value and the private key of the second server includes: Generate the signature intermediate value based on the random number, the first signature final value, and the private key of the second server; where the calculation formula of the signature intermediate value is S0 = [(k + r)·d^(-1)+1] mod n; k is the random number, r is the first signature final value, and d is the private key of the second server.
4. A collaborative signature method, which is applied to the terminal of the target user, and is characterized in that, The method includes: Generate a second signature final value based on the first signature final value, the signature intermediate value, and the private key of the terminal of the target user sent by the second server. The signature intermediate value is generated by the random number, the first signature final value, and the private key of the second server. The calculation formula of the signature intermediate value is S0 = [(k + r)·d^(-1)+1] mod n; S0 is the signature intermediate value, k is the random number, r is the first signature final value, d is the private key of the second server, n is the n-order base point on the elliptic curve, the first signature final value is generated by the second elliptic curve coordinate and the hash value of the target file to be signed, the random number is a numerical value randomly generated by the second server in each collaborative signature process, the second elliptic curve coordinate is determined by the public key intermediate value, the n-order base point on the elliptic curve, and the random number, and the calculation formula of the second signature final value is S = [S0·d1^(-1)-r] mod n, where S is the second signature final value and d1 is the private key of the terminal of the target user; Generate a public key final value based on the public key intermediate value sent by the second server and the private key of the terminal of the target user; Send the first signature final value, the second signature final value, and the public key final value to a first server, so that the first server determines a signature result of a target file to be signed based on a hash value of the target file to be signed, the public key final value, the first signature final value, and the second signature final value.
5. A collaborative signature device, which is applied to a first server, and is characterized in that, The device includes: A signature request information generation module, configured to generate signature request information based on a signature request signal sent by a terminal of a target user; wherein, the signature request information includes: identity information of the target user and a hash value of a target file to be signed; An encryption information obtaining module, configured to encrypt the signature request information by using a public key of a certificate authority to obtain encrypted information; A first sending module, configured to send the encrypted information to a second server, so that the second server generates a public key intermediate value based on a private key of the second server, generates a first signature final value based on the encrypted information and the public key intermediate value, determines a second elliptic curve coordinate based on the public key intermediate value, an n-order base point on an elliptic curve, and a random number, the random number being randomly generated by the second server in each collaborative signature process; generates the first signature final value based on the second elliptic curve coordinate and the hash value of the target file to be signed, generates a signature intermediate value based on the random number, the first signature final value, and the private key of the second server, and sends the public key intermediate value, the first signature final value, and the signature intermediate value to the terminal of the target user, so that the terminal of the target user generates a second signature final value based on the first signature final value, the signature intermediate value, and a private key of the terminal of the target user; wherein, a calculation formula of the signature intermediate value is S0 = [(k + r) · d^(-1)+1]]mod n; the S0 is the signature intermediate value, the k is the random number, the r is the first signature final value, the d is the private key of the second server, and the n is the n-order base point on the elliptic curve; generates a public key final value based on the public key intermediate value and the private key of the terminal of the target user, and sends the first signature final value, the second signature final value, and the public key final value to the first server, S = [S0 · d1^(-1)-r]mod n, the S is the second signature final value, and the d1 is the private key of the terminal of the target user; A signature result verification module, configured to determine a signature result of the target file to be signed based on the hash value of the target file to be signed, the public key final value, the first signature final value, and the second signature final value.
6. A collaborative signature device, the collaborative signature device being applied to a second server, characterized in that The device includes: A public key intermediate value generation module, configured to generate a public key intermediate value based on the private key of the second server; A decryption module, configured to decrypt the encrypted information by using a private key of a certificate authority to obtain the hash value of the target file to be signed and the identity information of the target user; A first signature final value generation module, configured to generate a first signature final value based on the public key intermediate value and the hash value of the target file to be signed; A signature intermediate value generation module, configured to generate a signature intermediate value based on the first signature final value and the private key of the second server; A terminal confirmation module, configured to determine the terminal of the target user based on the identity information of the target user; A second sending module, configured to send the public key intermediate value, the first signature final value, and the signature intermediate value to the terminal of the target user, so that the terminal of the target user generates a second signature final value based on the first signature final value, the signature intermediate value, and the private key of the terminal of the target user. The calculation formula of the second signature final value is S = [S0·d1^(-1)-r] mod n, where S is the second signature final value, d1 is the private key of the terminal of the target user, S0 is the signature intermediate value, and n is the n-order base point on the elliptic curve; generate a public key final value based on the public key intermediate value and the private key of the terminal of the target user; determine a second elliptic curve coordinate based on the public key intermediate value, the n-order base point on the elliptic curve, and a random number, where the random number is randomly generated by the second server in each collaborative signature process; generate the first signature final value based on the second elliptic curve coordinate and the hash value of the target file to be signed; generate the signature intermediate value based on the random number, the first signature final value, and the private key of the second server; where the calculation formula of the signature intermediate value is S0 = [(k+r)·d^(-1)+1] mod n; S0 is the signature intermediate value, k is the random number, r is the first signature final value, and d is the private key of the second server.
7. A collaborative signature device, which is applied to the terminal of a target user, characterized in that The device includes: A second signature final value generation module, configured to generate a second signature final value based on the first signature final value, the signature intermediate value, and the private key of the terminal of the target user sent by the second server. The signature intermediate value is generated by a random number, the first signature final value, and the private key of the second server. The calculation formula of the signature intermediate value is S0 = [(k+r)·d^(-1)+1] mod n; S0 is the signature intermediate value, k is the random number, r is the first signature final value, d is the private key of the second server, n is the n-order base point on the elliptic curve, the first signature final value is generated by the second elliptic curve coordinate and the hash value of the target file to be signed, the random number is a numerical value randomly generated by the second server in each collaborative signature process, the second elliptic curve coordinate is determined by the public key intermediate value, the n-order base point on the elliptic curve, and the random number, and the calculation formula of the second signature final value is S = [S0·d1^(-1)-r] mod n, where S is the second signature final value and d1 is the private key of the terminal of the target user; A public key final value generation module, configured to generate a public key final value based on the public key intermediate value sent by the second server and the private key of the terminal of the target user; A third sending module, configured to send the first signature final value, the second signature final value, and the public key final value to a first server, so that the first server determines a signature result of a target file to be signed based on a hash value of the target file to be signed, the public key final value, the first signature final value, and the second signature final value.
8. A first server, characterized in that, Comprising: A processor and a memory; wherein, the memory stores a computer program, and the computer program is adapted to be loaded and executed by the processor to perform the method steps of claim 1 or 2.
9. A second server, characterized in that, Comprising: A processor and a memory; wherein, the memory stores a computer program, and the computer program is adapted to be loaded and executed by the processor to perform the method steps of claim 3.
10. A terminal, characterized in that, Comprising: A processor and a memory; wherein, the memory stores a computer program, and the computer program is adapted to be loaded and executed by the processor to perform the method steps of claim 4.
11. A collaborative signature system, characterized in that, Comprising: The first server according to claim 8, the second server according to claim 9, and the terminal according to claim 10.
Citation Information
Patent Citations
Collaborative signature method and device, electronic equipment and storage medium
CN115378615A