Efficient Signature Method and System Based on SM9 Algorithm
Through an efficient signature method based on the SM9 algorithm, the exclusive parameter set is generated and the main private key is split, which solves the problem of difficulty in flexibly adjusting digital signatures and single use of the main private key in the existing technology, and differentiated processing is realized for different data attributes and signature tasks risks, improving the security and efficiency of signatures.
Patent Information
- Application Number
- CN202510386640.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-31
- Publication Date
- 2025-06-17
- Estimated Expiration
- 2045-03-31
AI Technical Summary
The existing digital signature algorithms are difficult to flexibly adjust according to different data attributes and signature task requirements, which leads to the inability to fully utilize the algorithm advantages when processing complex and diverse data. The use of the master and private keys is single, and it is not possible to perform differentiated processing based on the risks and risks of the signature task, making it difficult to achieve optimal balance in different scenarios.
An efficient signature method based on the SM9 algorithm is adopted, and a special parameter set adapted to this signature task is generated by obtaining the attributes of the data to be signed, and the main private key is split to obtain multiple sub-private keys with different key levels. Dynamically set the key level of the sub-private key based on the risk hazards of the signature task, and weighted signature operations are performed based on the sub-private keys of different key levels to generate multiple signature semi-finished products with key level weight imprints, and finally integrate them into the signature finished product.
Through adaptation, the generation of exclusive parameter sets and flexible splitting of the main and private keys is achieved, differentiated processing of different data attributes and signature tasks risks is improved, the security, efficiency and adaptability of digital signatures are improved, and the optimal security and efficiency balance can be achieved in different scenarios.
Smart Images

Figure CN119892362B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data processing, and particularly relates to an efficient signature method and system based on the SM9 algorithm. Background Art
[0002] In the digital information age, the security and authenticity of data are becoming increasingly important. As one of the key technologies for ensuring data security, digital signatures are widely used in many fields.
[0003] Existing digital signature algorithms usually adopt a fixed parameter set, which is difficult to flexibly adjust according to different data attributes and signature task requirements. As a result, when dealing with complex and diverse data, the advantages of the algorithm cannot be fully utilized. At the same time, the use of the main private key is single, and no differential processing is carried out according to the potential risks of the signature task, making it difficult to achieve the optimal balance between the security and efficiency of the signature in different scenarios. Summary of the Invention
[0004] The main purpose of the present invention is to provide an efficient signature method and system based on the SM9 algorithm, aiming to overcome the defect that the current digital signature lacks differential processing and has low signature security.
[0005] To achieve the above purpose, the present invention provides an efficient signature method based on the SM9 algorithm, including the following steps:
[0006] Obtain the attributes of the data to be signed;
[0007] Based on the attributes of the data to be signed, generate a dedicated parameter set adapted to the current signature task based on the SM9 algorithm; the dedicated parameter set includes core operation parameters adapted to the attributes;
[0008] Split the main private key to obtain multiple sub-private keys with different key levels; the key level of each sub-private key is dynamically set according to the potential risks of the current signature task;
[0009] Based on the sub-private keys with different key levels, perform weighted signature operations on the core operation parameters in the dedicated parameter set respectively to generate multiple signature semi-finished products with key level weight imprints;
[0010] Integrate all the signature semi-finished products to obtain a signature finished product for signing the data to be signed.
[0011] Further, the attributes of the data to be signed include data type, data length, and key elements in the data.
[0012] Further, generating a dedicated parameter set adapted to the current signature task based on the SM9 algorithm according to the attributes of the data to be signed includes:
[0013] Parse the attributes of the data to be signed, identify the sensitivity level of the data to be signed, and mark it;
[0014] Based on the above marking, retrieve the corresponding basic parameter template in the SM9 algorithm;
[0015] Combine the data length of the data to be signed to adjust the hash function parameters in the basic parameter template;
[0016] Based on the adjusted parameter template, incorporate the current system timestamp information to calibrate the random number generation parameters in the parameter template, and generate a dedicated parameter set adapted to this signature task.
[0017] Further, split the master private key to obtain multiple sub-private keys with different key levels, including:
[0018] Analyze the risk level of the data to be signed;
[0019] Determine the splitting quantity of the master private key and the key levels of the sub-private keys according to the risk level of the data to be signed;
[0020] Based on the above splitting quantity, use the Shamir secret sharing algorithm to split the master private key to obtain the corresponding number of sub-private keys;
[0021] Mark the corresponding key level information for each sub-private key, and configure different storage strategies for sub-private keys with different key levels; among them, the sub-private key with the highest key level is stored in a secure storage device with multiple encryption and physical isolation, and integrity verification and backup are performed regularly.
[0022] Further, based on sub-private keys with different key levels, perform weighted signature operations on the core operation parameters in the dedicated parameter set respectively to generate multiple signature semi-finished products with key level weight imprints, including:
[0023] Real-time monitor multiple indicators of the operation environment, use them as the initial parameters of the chaotic system, and dynamically generate the weights of sub-private keys with different key levels through chaotic mapping;
[0024] Combine optical computing and electronic computing, and perform weighted signature operations on the core operation parameters in the dedicated parameter set with the dynamically generated weights;
[0025] Verify the signature operation process based on zero-knowledge proof technology. If the verification passes, obtain multiple signature semi-finished products with key level weight imprints.
[0026] Further, integrate all the signature semi-finished products to obtain the signature finished product for signing the data to be signed, including:
[0027] Generate a first matrix based on the attributes of the data to be signed;
[0028] Generate a second matrix based on the exclusive parameter set;
[0029] Based on the first matrix, transform the second matrix to obtain a transformation matrix;
[0030] Generate a transformation key based on the transformation matrix, and encrypt and store each of the sub-private keys, signature semi-finished products, and signature finished products based on the transformation key.
[0031] Further, based on the first matrix, transforming the second matrix to obtain a transformation matrix includes:
[0032] Analyze each element of the first matrix, detect English character elements therefrom and connect them in sequence to obtain a first figure;
[0033] Add the first figure to the second matrix, and use the elements in the second matrix that overlap with the first figure as transformation elements;
[0034] Calculate the mean value of the numerical character elements in the first matrix;
[0035] Add the mean value to each of the transformation elements in the second matrix to obtain a transformation matrix.
[0036] The present invention also provides an efficient signature system based on the SM9 algorithm, including:
[0037] An acquisition unit for acquiring the attributes of the data to be signed;
[0038] A generation unit for generating an exclusive parameter set adapted to the current signature task based on the attributes of the data to be signed according to the SM9 algorithm; the exclusive parameter set includes core operation parameters adapted to the attributes;
[0039] A splitting unit for splitting the main private key to obtain multiple sub-private keys with different key levels; the key level of each sub-private key is dynamically set according to the risk hazards of the current signature task;
[0040] An operation unit for performing weighted signature operations on the core operation parameters in the exclusive parameter set respectively based on the sub-private keys with different key levels, and generating multiple signature semi-finished products with key level weight imprints;
[0041] A signature unit for integrating all the signature semi-finished products to obtain a signature finished product for signing the data to be signed.
[0042] The efficient signature method and system based on the SM9 algorithm provided by the present invention include: obtaining the attributes of the data to be signed; generating a dedicated parameter set adapted to the current signature task based on the SM9 algorithm according to the attributes of the data to be signed; the dedicated parameter set includes core operation parameters adapted to the attributes; splitting the master private key to obtain multiple sub-private keys with different key levels; the key level of each sub-private key is dynamically set according to the potential risks of the current signature task; based on the sub-private keys with different key levels, performing weighted signature operations on the core operation parameters in the dedicated parameter set respectively to generate multiple signature semi-finished products with key level weight imprints; integrating all the signature semi-finished products to obtain a signature finished product for signing the data to be signed. In the present invention, a dedicated parameter set is adaptively generated according to the attributes of the data to be signed, the master private key is flexibly split and signature operations are performed specifically, and different digital signatures are generated for different data to be signed, improving the security, efficiency and adaptability of the digital signature. BRIEF DESCRIPTION OF THE DRAWINGS
[0043] Figure 1 is a schematic diagram of the steps of the efficient signature method based on the SM9 algorithm in an embodiment of the present invention;
[0044] Figure 2 is a block diagram of the structure of the efficient signature system based on the SM9 algorithm in an embodiment of the present invention;
[0045] Figure 3 is a schematic block diagram of the structure of a computer device in an embodiment of the present invention.
[0046] The implementation, functional features and advantages of the present invention will be further described with reference to the embodiments and the accompanying drawings. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0047] In order to make the objectives, technical solutions and advantages of the present invention clearer, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention, and are not used to limit the present invention.
[0048] Referring to Figure 1 , an embodiment of the present invention provides an efficient signature method based on the SM9 algorithm, including the following steps:
[0049] Step S1, obtaining the attributes of the data to be signed;
[0050] Step S2, generating a dedicated parameter set adapted to the current signature task based on the SM9 algorithm according to the attributes of the data to be signed; the dedicated parameter set includes core operation parameters adapted to the attributes;
[0051] Step S3, split the master private key to obtain multiple sub-private keys with different key levels; the key level of each sub-private key is dynamically set according to the risk of this signature task;
[0052] Step S4, based on the sub-private keys of different key levels, weighted signature operations are performed on the core operation parameters in the exclusive parameter set to generate multiple signature semi-finished products with key level weight imprints;
[0053] Step S5, integrating all the semi-finished signatures to obtain the finished signatures to sign the data to be signed.
[0054] In this embodiment, as described in step S1 above, the attributes of the data to be signed cover multiple aspects, such as data type (text, image, audio or video, etc.), data length (data volume), and key elements in the data (such as sensitive content such as account information and transaction amount in financial data; important information such as patient diagnosis results and genetic data in medical data). Accurately acquiring these attributes provides a basic basis for the subsequent generation of a dedicated parameter set based on the SM9 algorithm, so that the signature process can better adapt to the characteristics of the data and improve the security and effectiveness of the signature.
[0055] As described in step S2 above, based on the data attributes obtained in step S1, this step uses the characteristics of the SM9 algorithm to customize a dedicated parameter set. The SM9 algorithm itself has a certain degree of flexibility, and by analyzing the attributes of the data, it can generate a set of parameters in a targeted manner. For example, if the data to be signed is highly sensitive financial transaction data, in order to ensure security, the core operation parameters in the exclusive parameter set will enhance the encryption strength, such as using more complex hash function parameters, larger finite field parameters, etc.; if the data is ordinary public text and the security requirements are relatively low, the parameters can be adjusted to improve the operation efficiency. The exclusive parameter set generated in this way enables the SM9 algorithm to achieve a balance between security and efficiency according to the data attributes in this signature task.
[0056] As described in step S3 above, this step breaks the traditional single private key usage mode and splits the master private key (a key pair pre-generated with the master public key in the SM9 algorithm) based on the risk assessment of the signature task. By comprehensively considering the importance of the data to be signed, the impact that may be caused by tampering and other risk factors, the number of splits of the master private key and the critical level of each sub-private key are determined. For example, for signature tasks involving high risks, the master private key can be split into multiple parts, in which a higher proportion of high-criticality sub-private keys are set to perform signature operations of key parts to enhance the security of the signature; for signature tasks of general daily data, the number of splits can be appropriately reduced, and the proportion of high-criticality sub-private keys can be reduced. The above-mentioned method of dynamically setting the critical level of the sub-private key enables the signing process to flexibly adjust the security policy according to different risk scenarios.
[0057] As described in step S4 above, after obtaining the sub-private keys of different key levels and the exclusive parameter set, this step performs the signature operation. Sub-private keys of different key levels have different weights in the signature operation. The sub-private keys of high key levels have higher weights in the operation, which means that they have a greater impact on the signature result, and correspondingly, more complex and safer operation methods will be adopted, such as increasing the number of scalar multiplication operations in elliptic curve cryptography or using more advanced encryption transformations; the sub-private keys of low key levels have lower weights and the operation is relatively simple to improve the overall operation efficiency. Through this weighted signature operation, the role of sub-private keys of different key levels is fully utilized, which not only ensures the security of the signature, but also takes into account the operation efficiency, and generates semi-finished signatures with different key level weight imprints, laying the foundation for the generation of the final signature product.
[0058] As described in step S5 above, all the semi-finished signatures are integrated to obtain the finished signatures to sign the data to be signed. The multiple semi-finished signatures generated previously are integrated. The integration process can be a simple splicing, or it can be based on a preset algorithm and logic, combined with the key level weight imprints of each semi-finished signature, to ensure that the integrated signature product contains all the necessary information and complies with the signature specification of the SM9 algorithm. The final signature product can be used to sign the data to be signed, as an effective proof of the authenticity and integrity of the data, and plays a key role in the subsequent data transmission, storage and verification process.
[0059] In an embodiment of the present invention, an exclusive parameter set is generated according to the attributes of the data to be signed, the master private key is flexibly split and the signature operation is performed in a targeted manner, and differentiated digital signatures are generated according to the different data to be signed, thereby improving the security, efficiency and adaptability of the digital signature.
[0060] In one embodiment, the attributes of the data to be signed include data type, data length, and key elements in the data.
[0061] In one embodiment, according to the attributes of the data to be signed, a dedicated parameter set adapted to the current signature task is generated based on the SM9 algorithm, including:
[0062] Parse the attributes of the data to be signed, identify the sensitivity level of the data to be signed, and make a mark;
[0063] Based on the mark, retrieve the corresponding basic parameter template in the SM9 algorithm;
[0064] Combine the data length of the data to be signed and adjust the hash function parameters in the basic parameter template;
[0065] Based on the adjusted parameter template, incorporate the current system timestamp information and calibrate the random number generation parameters in the parameter template to generate a dedicated parameter set adapted to the current signature task.
[0066] In this embodiment, the sensitivity level of the above-mentioned data to be signed is one of the key factors determining the signature security strength. Through in-depth analysis of the data attributes, the sensitivity level is judged from multiple aspects such as data type and the information content contained. For example, if the data contains information such as personal ID numbers and bank card passwords, it can be determined as highly sensitive data; if it is general public news and information, the sensitivity level is relatively low. Clearly mark the identified sensitivity level, such as dividing it into three levels: high, medium, and low, to provide a clear basis for selecting the appropriate basic parameter template later and ensure that the signature process can match the corresponding security level according to the data sensitivity level.
[0067] A variety of basic parameter templates are preset in the above-mentioned SM9 algorithm to adapt to signature tasks with different security requirements. Based on the mark of the data sensitivity level in the previous step, the appropriate template can be accurately retrieved from the algorithm reserve. For highly sensitive data, a template with high-strength encryption and complex verification mechanisms will be called to ensure the security of the data during the signature and subsequent use processes; for low-sensitive data, to improve the operation efficiency, a relatively simplified template that focuses on fast processing will be selected. This targeted template retrieval enables the SM9 algorithm to flexibly adjust the emphasis on security and efficiency according to the actual situation of the data.
[0068] The above data length is another important factor affecting the signature operation. When performing hash operations on data of different lengths, the requirements for the hash function are different. For the data to be signed with a relatively long length, in order to ensure the uniqueness and security of the hash result, it is necessary to adjust the hash function parameters in the basic parameter template. For example, increasing the number of iterations of the hash function, expanding the value range of the hash value, etc., so that the hash function can better handle large amounts of data, reduce the probability of hash collisions, and improve the security and reliability of the signature. For data with a relatively short length, the hash function operation can be appropriately simplified to improve the operation efficiency while ensuring basic security. By combining the adjustment of the hash function parameters according to the data length, the adaptability of the signature algorithm to data of different scales is further optimized.
[0069] The above system timestamp information has the characteristics of uniqueness and real-time. Incorporate the current system timestamp information into the adjusted parameter template, and use the characteristics of the timestamp to calibrate the random number generation parameters. This means that each generated random number sequence is closely related to the current time, increasing the randomness and unpredictability of the signature. For example, according to the numerical change of the timestamp, dynamically adjust the seed value or iteration formula of the random number generation algorithm, so that the generated random numbers are more diverse. After such calibration, the parameter template finally generates a dedicated parameter set adapted to this signature task, which not only considers the sensitivity and length of the data, but also combines the real-time factor, comprehensively improving the security and uniqueness of the signature, making the signature more difficult to be forged or cracked.
[0070] In one embodiment, the master private key is split to obtain multiple sub-private keys with different key levels, including:
[0071] Analyze the risk level of the data to be signed;
[0072] Determine the split number of the master private key and the key levels of the sub-private keys according to the risk level of the data to be signed;
[0073] Based on the split number, use the Shamir secret sharing algorithm to split the master private key to obtain the corresponding number of sub-private keys;
[0074] Mark the corresponding key level information for each sub-private key, and configure different storage strategies for sub-private keys with different key levels; among them, the sub-private key with the highest key level is stored in a secure storage device with multiple encryptions and physical isolation, and integrity checks and backups are performed regularly.
[0075] In this embodiment, first, the data to be signed is comprehensively evaluated to determine its risk level. The evaluation process comprehensively considers various factors, such as the sensitivity of the data, the severity of the consequences that may be caused by data leakage or tampering, and the security requirements of the field to which the data belongs. Accurately analyzing the risk level provides a basis for subsequent reasonable splitting of the master private key and determining the key levels of the sub-private keys.
[0076] Furthermore, based on the risk level determined in the previous step, a corresponding master private key splitting strategy is formulated. The higher the risk level, the more sub-private keys are usually split from the master private key to ensure signature security, and the proportion of high-key-level sub-private keys will also increase accordingly. For example, for data with an extremely high risk level, the master private key is split into multiple sub-private keys, and a relatively large number of high-key-level sub-private keys are set; while for data with a low risk level, the number of sub-private keys split from the master private key is small, and the key levels are mainly distributed at lower levels. In this way, the splitting of the master private key is matched with the data risk, ensuring signature security while avoiding waste of computing resources and increased management complexity caused by excessive splitting.
[0077] The above Shamir secret sharing algorithm is a mature key splitting technology. It splits the master private key into multiple sub-private keys, and these sub-private keys have certain characteristics, that is, the original master private key can be restored only when a sufficient number (determined by algorithm parameters) of sub-private keys are collected. Based on the splitting number determined in the previous step, the master private key is input into the Shamir secret sharing algorithm as the secret value. The algorithm performs operations within a finite field, generates corresponding sub-private key shares by selecting an appropriate polynomial. For example, if it is determined to split the master private key into 5 sub-private keys, the algorithm will generate 5 sub-private keys within the finite field, and these sub-private keys cannot restore the master private key when they exist alone. Only when a specific threshold is met (such as the combination of 3 or more sub-private keys), can the master private key be restored. This splitting method ensures that even if some sub-private keys are leaked, the security of the master private key will not be directly endangered.
[0078] Finally, to better manage and protect the split sub-private keys, each sub-private key is marked with its corresponding key level information. This enables different security measures to be taken according to the key level when using and managing the sub-private keys subsequently. For sub-private keys at different key levels, differentiated storage strategies are configured to achieve reasonable resource allocation and maximize security. The sub-private keys at the highest key level are crucial for signature security, and thus have extremely high requirements for storage security. They are stored in a secure storage device with multiple encryption technologies. Through the combination of multiple encryption algorithms, the difficulty of cracking is increased. At the same time, physical isolation means are adopted, such as placing the storage device in an independent secure area, physically isolating it from the external network to prevent network attacks. The integrity of these sub-private keys at the highest key level is regularly verified to check whether they have been tampered with or damaged, and backups are made to prevent the loss of sub-private keys due to reasons such as storage device failures. This hierarchical storage and management strategy not only ensures signature security but also improves the reliability and stability of the system.
[0079] In one embodiment, based on sub-private keys at different key levels, weighted signature operations are respectively performed on the core operation parameters in the exclusive parameter set to generate multiple semi-finished signatures with key level weight imprints, including:
[0080] Monitor multiple indicators of the operation environment in real time as the initial parameters of the chaotic system, and dynamically generate the weights of sub-private keys at different key levels through chaotic mapping;
[0081] Combine optical computing and electronic computing, and perform weighted signature operations on the core operation parameters in the exclusive parameter set using the dynamically generated weights;
[0082] Verify the signature operation process based on zero-knowledge proof technology. If the verification passes, multiple semi-finished signatures with key level weight imprints are obtained.
[0083] In this embodiment, before performing the signature operation, multiple key indicators of the operation environment need to be monitored in real time. These indicators include but are not limited to the current load of the system, available computing resources, network bandwidth, and real-time latency of data transmission, etc. These indicators comprehensively reflect the real-time state of the operation environment.
[0084] Use the above real-time monitored metrics as the initial parameters of the chaotic system. The chaotic system has the characteristic of being extremely sensitive to initial conditions. A tiny change in the initial parameters will lead to a huge difference in the system output. By leveraging this characteristic of the chaotic system, the generation of the sub-private key weights has a high degree of randomness and unpredictability. The chaotic system processes the initial parameters through a chaotic mapping, which is a non-linear transformation that can perform complex iterative operations on the initial parameters in the chaotic space. After the chaotic mapping, the weights of different key-level sub-private keys are dynamically generated. Due to the inherent randomness of the chaotic system and its sensitivity to initial conditions, the weights generated each time are unique and difficult to be predicted by external attackers, thus providing an additional layer of security for the signature operation. This way of dynamically generating weights can flexibly adjust the importance of sub-private keys in the signature operation according to the real-time changes in the operation environment, ensuring that the signature process can maintain a high level of security and adaptability under different environmental conditions.
[0085] Combine optical computing and electronic computing, and perform a weighted signature operation on the core operation parameters in the exclusive parameter set using the dynamically generated weights: This step innovatively integrates two technologies, optical computing and electronic computing. Optical computing has the ability to process data in a high-speed parallel manner and can handle a large number of data operations in a short time, especially suitable for processing some computing tasks with extremely high speed requirements. Electronic computing, on the other hand, has advantages in logical control and precise numerical calculation. The combination of the two can give full play to their respective strengths.
[0086] Based on the weights of different key-level sub-private keys dynamically generated in the first step, perform a weighted signature operation on the core operation parameters in the exclusive parameter set. For the sub-private keys of high key levels, utilize the high-speed parallelism of optical computing to perform complex encryption operations on the core operation parameters to fully play their important role in the signature process and ensure the security of the signature; for the sub-private keys of low key levels, use electronic computing to perform relatively simple operations, which not only ensures the accuracy of the operations but also saves computing resources to a certain extent. By this method of combining two computing methods and performing differential operations according to the sub-private key weights, not only the efficiency of the signature operation is improved, but also the security requirements of sub-private keys at different key levels in the signature process are taken into account, achieving a balance between security and efficiency.
[0087] The above zero - knowledge proof technology is a technology that proves a statement to be true to the verifier without revealing any actual information. During the signature operation process, by applying the zero - knowledge proof technology, the signer can make the verifier convinced that the signature operation process is correct and legal without disclosing the specific details of the signature operation to the verifier (such as the weights of sub - private keys, the specific values of core operation parameters, and intermediate results during the operation process, etc.). The verification process is based on the zero - knowledge proof protocol. The verifier verifies the proof provided by the signer through a series of verification steps and challenge - response mechanisms. If the verification passes, it indicates that the signature operation process meets the expected security and correctness requirements. At this time, multiple semi - finished signatures with imprints of key - level weights are obtained. The above semi - finished signatures not only contain the weight information corresponding to the key levels of the sub - private keys but also have undergone strict verification to ensure their reliability and integrity. This verification process based on the zero - knowledge proof technology further enhances the security and privacy protection of the signature process, prevents the leakage of key information during the signature operation process, and at the same time ensures the quality and credibility of the semi - finished signatures.
[0088] In one embodiment, after integrating all the semi - finished signatures to obtain a finished signature for signing the data to be signed, it includes:
[0089] Generating a first matrix based on the attributes of the data to be signed;
[0090] Generating a second matrix based on the exclusive parameter set;
[0091] Based on the first matrix, transforming the second matrix to obtain a transformation matrix;
[0092] Generating a transformation key based on the transformation matrix, and encrypting and storing each of the sub - private keys, semi - finished signatures, and finished signatures based on the transformation key.
[0093] In this embodiment, first, the attributes of the data to be signed include various aspects of information such as data type, data length, key elements, etc. By quantifying and encoding these attributes, they are transformed into matrix form. For example, for the data type, one - hot encoding can be used to map different types to specific vectors in the matrix; the data length can be used as a certain dimension value in the matrix after normalization processing; key elements are filled into the corresponding positions of the matrix in a specific numerical form according to their importance and characteristics. The generated first matrix can comprehensively and concisely represent the attribute characteristics of the data to be signed, providing a basis for subsequent matrix transformation and encryption operations. The generation method of this matrix aims to transform complex data attributes into a form convenient for mathematical operations and processing, so as to better establish connections with other data in the encryption storage link and enhance the overall security.
[0094] The above-mentioned exclusive parameter set is a parameter set adapted to this signature task generated based on the attributes of the data to be signed according to the SM9 algorithm, which contains important information such as core operation parameters. Similarly, each parameter in the exclusive parameter set is sorted out and digitally represented to construct a second matrix. For example, different parameters are arranged in different rows and columns of the matrix in an orderly manner according to their roles and mutual relationships in the algorithm. This matrix represents the specific parameter configuration used in this signature task, which is the key basis for the signature operation and an indispensable part of the subsequent encryption storage process. By converting the exclusive parameter set into matrix form, it can be operated in the same mathematical space as the first matrix, providing the possibility for generating more complex and secure encryption transformations.
[0095] Furthermore, the second matrix is transformed using the first matrix, and this process applies the relevant theories and methods of matrix operations. For example, matrix multiplication, addition, or other more complex matrix transformation rules can be used to make targeted adjustments to the second matrix according to the information on the attributes of the data to be signed contained in the first matrix. Since the first matrix reflects the characteristics of the data to be signed and the second matrix represents the exclusive parameters of the signature task, transforming the second matrix based on the first matrix can make the generated transformation matrix integrate the key information of both, and this transformation matrix is closely related to this signature task and the data to be signed. This transformation of the parameter matrix based on data attributes increases the relevance of the encryption process to the specific signature task, making the encrypted information more difficult to crack because the attacker not only needs to understand the encryption algorithm but also needs to master the detailed attributes of the data to be signed to conduct an effective attack.
[0096] Finally, based on the transformation matrix, a transformation key is generated through a specific key generation algorithm. This algorithm uses the characteristics such as the combination and arrangement of elements in the transformation matrix to generate a unique key through mathematical operations. Since the transformation matrix integrates the information of the attributes of the data to be signed and the exclusive parameter set, the generated transformation key is also highly relevant to this signature task and has strong pertinence. After obtaining the transformation key, this key is used to encrypt and store each sub-private key, signature semi-finished product, and signature finished product. The encryption process uses a suitable encryption algorithm, such as a symmetric encryption algorithm or an asymmetric encryption algorithm, to convert these important data into ciphertext form for storage. The purpose of this is to further protect the key information involved in the signature process and prevent it from being stolen or tampered with during storage. Even if the attacker obtains the stored data, without the correct transformation key, they cannot restore the original sub-private key, signature semi-finished product, and signature finished product, thus effectively ensuring the security and integrity of the signature data.
[0097] In one embodiment, based on the first matrix, transforming the second matrix to obtain a transformation matrix includes:
[0098] Analyze each element of the first matrix, detect English character elements therefrom and connect them in sequence to obtain a first figure;
[0099] Add the first figure to the second matrix, and use the elements in the second matrix that overlap with the first figure as transformation elements;
[0100] Calculate the mean value of the numeric character elements in the first matrix;
[0101] Add the mean value to each of the transformation elements in the second matrix to obtain a transformation matrix.
[0102] In this embodiment, the above first matrix is generated based on the attributes of the data to be signed, and its elements include various types, such as numeric characters, English characters, etc. The core purpose of this step is to screen out English character elements from the first matrix. Connect the detected English character elements in the order in which they appear in the first matrix. This connection method combines the originally scattered characters into a whole with a specific meaning, namely the first figure. This first figure can be regarded as a feature identifier extracted from the attributes of the data to be signed, and it will serve as an important input in the subsequent matrix transformation process.
[0103] The above second matrix is generated based on a dedicated parameter set and represents the specific parameter configuration used for this signature task. Adding the first figure to the second matrix means integrating the feature identifier of the data to be signed attributes into the parameter matrix of the signature task. This addition operation can be regarded as a process of integrating data attribute information with signature parameters, enabling subsequent transformations to comprehensively consider these two aspects of factors. After adding the first figure to the second matrix, find the elements in the second matrix that overlap with the first figure. These overlapping elements are selected as transformation elements because they are the direct intersection of data attribute features and signature parameters. Transforming these elements can more effectively reflect the attribute information of the data to be signed into the final transformation matrix, thus making the transformation matrix more in line with the actual requirements of this signature task.
[0104] The numeric character elements in the above first matrix also contain important information about the attributes of the data to be signed. Calculate the mean value of these numeric character elements. This mean value can be regarded as a comprehensive manifestation of the numeric features in the attributes of the data to be signed, and it serves as an adjustment factor in the subsequent matrix transformation to adjust the transformation elements in the second matrix, thereby further integrating the attribute information of the data to be signed into the transformation matrix.
[0105] Add the mean value of the first matrix digital character elements obtained from the above calculation to each transformation element of the second matrix. In this way, the digital feature information of the data attributes to be signed is transmitted to the key part (i.e., the transformation elements) of the second matrix. After such adjustment, the transformation elements not only contain the exclusive parameter information of the signature task, but also incorporate the attribute characteristics of the data to be signed, thus obtaining a new matrix, namely the transformation matrix. The above transformation matrix synthesizes the attribute information of the data to be signed and the exclusive parameter information of the signature task. Subsequently, a transformation key will be generated based on this transformation matrix for encrypting and storing each sub-private key, signature semi-finished product, and signature finished product. Since the transformation matrix is closely related to this signature task, the generated transformation key also has strong pertinence, which can better ensure the security and integrity of the signed data.
[0106] In one embodiment, generating a transformation key based on the transformation matrix includes:
[0107] Map the elements in the transformation matrix to the quantum state space to construct a quantum matrix, simulate quantum fluctuations on it with a quantum computer, measure the perturbed quantum matrix, and extract the quantum eigenvector;
[0108] Collect background noise and perform digital processing to extract the feature sequence; through the information entropy maximization algorithm, fuse it with the quantum eigenvector to obtain the fusion vector;
[0109] Input the fusion vector into a pre-constructed simulated biological neural network, and extract a stable and highly non-linear output vector from the output layer;
[0110] Adopt the spatio-temporal coding technology, determine the coding parameters by combining the geographical location and time information, process the output vector, and generate a transformation key containing spatio-temporal identifiers.
[0111] In this embodiment, mapping the elements in the transformation matrix to the quantum state space is a process of converting classical information into quantum information. In the quantum state space, each element will exist in the form of quantum bits, and multiple quantum bits combined together construct the quantum matrix. Quantum states have characteristics such as superposition and entanglement, which can bring advantages that classical computing does not have for subsequent processing, greatly increasing the complexity and security of information. Use a quantum computer to simulate the quantum fluctuation phenomenon and apply perturbations to the constructed quantum matrix. Quantum fluctuation is the random fluctuation of energy and particles in a quantum system. Simulate this uncertainty to act on the quantum matrix. Then measure the perturbed quantum matrix. Since quantum measurement will cause the quantum state to collapse, a set of definite measurement results will be obtained. Extract the quantum eigenvector from these measurement results. This vector contains the unique characteristics of the quantum matrix after being perturbed and is an important basis for generating the key subsequently.
[0112] Collect various background noises, such as cosmic microwave background noise, thermal noise of electronic devices, etc. These background noises have natural randomness and unpredictability. Digitally process the collected background noises, convert them into digital signals that can be processed by a computer, and extract a feature sequence from them, which represents the main features of the background noises. Use the information entropy maximization algorithm to fuse the feature sequence of the background noises with the previously obtained quantum feature vector. Information entropy is an index to measure information uncertainty. Through this algorithm, the fused vector can have the maximum information entropy, that is, the maximum randomness and uncertainty. The fused vector obtained in this way further enhances the complexity and security of the information.
[0113] Pre-construct a simulated biological neural network, which is a simulation of the working mode of biological brain neurons. This network consists of a large number of neuron nodes and synapses connecting these nodes, and has powerful information processing and learning capabilities. Input the fused vector into this simulated biological neural network. The neurons in the network will process and transmit the input information according to their own weights and biases. After multiple iterations and adjustments, the network will gradually reach a stable state. Extract a stable and highly non-linear output vector from the output layer of the network. Due to the non-linear characteristics of the biological neural network, this output vector contains complex information processing results, increasing the uniqueness and security of the key.
[0114] Adopt spatio-temporal coding technology, and combine the current geographical location and time information to determine the coding parameters. The geographical location information can be obtained through the Global Positioning System (GPS), etc., and the time information can be obtained from an accurate clock system. Different geographical locations and times will correspond to different coding parameters, adding spatio-temporal dimension identifiers to the key. Process the previously obtained output vector with the determined coding parameters to integrate the spatio-temporal information into the vector. After processing, finally generate a transformed key containing spatio-temporal identifiers. This key with spatio-temporal identifiers is not only closely combined with the information related to the signature task, but also further increases the uniqueness and security of the key, making the key more difficult to be cracked and forged.
[0115] In one embodiment, generating a transformation key based on the transformation matrix includes:
[0116] Extract all the numerical elements in the first matrix and generate a first numerical sequence according to a preset rule; extract all the numerical elements in the second matrix and generate a second numerical sequence according to a preset rule;
[0117] Extract one number in turn from the first numerical sequence and the second numerical sequence to form corresponding coordinate points; connect each coordinate point to generate a connected graph;
[0118] Form a third digital sequence from the digital elements in the transformation matrix, and generate a plurality of target coordinate points based on the third digital sequence;
[0119] In the same coordinate system, according to the positional relationship between each of the target coordinate points and the connection graph, select the coordinate points that meet the preset conditions from the target coordinate points as the key coordinate points;
[0120] Generate the transformation key based on the numbers in each of the key coordinate points.
[0121] In this embodiment, the first matrix is generated based on the attributes of the data to be signed, which contains various types of elements, such as numbers, letters, symbols, etc. This step focuses on screening out all the digital elements. This is because digital elements usually contain the quantization information related to the data to be signed and can be used as a key data source in the subsequent process of generating the transformation key. Arrange and combine the extracted digital elements according to the preset rules to form the first digital sequence. The preset rules can be the order of appearance of the digital elements in the matrix, the order of the rows or columns where they are located, etc. For example, if arranged in row-major order of the matrix elements, the digital elements in the first row will be arranged in sequence first, and then the digital elements in the second row will be arranged, and so on. This first digital sequence provides a set of digital bases for constructing coordinate points in the subsequent steps.
[0122] The second matrix is generated based on a dedicated parameter set and may also contain various elements. Extract the digital elements from it. These digital elements represent the quantization information of the specific parameters used in this signature task and are crucial for generating the transformation key. Similar to generating the first digital sequence, arrange the digital elements in the second matrix according to the preset rules to form the second digital sequence. The preset rules here can be the same as those for generating the first digital sequence or can be adjusted according to specific requirements. This second digital sequence cooperates with the first digital sequence and is jointly used to generate coordinate points.
[0123] In mathematics, a coordinate point is usually represented by two numbers for the abscissa and the ordinate respectively. In this step, take a number from the first digital sequence in sequence as the abscissa, and take a number from the second digital sequence in sequence as the ordinate, and combine them in pairs to form the corresponding coordinate points. For example, the first number in the first digital sequence and the first number in the second digital sequence form the first coordinate point, the second number in the first digital sequence and the second number in the second digital sequence form the second coordinate point, and so on. In this way, the two digital sequences are converted into a series of coordinate points in the coordinate system, and these coordinate points form a graphic basis with a specific distribution.
[0124] Connect the previously generated coordinate points in a certain order (such as the order of generation) in the coordinate system. After connecting these coordinate points, a connected graph with a specific shape will be formed. The shape and characteristics of this connected graph depend on the numerical elements in the first matrix and the second matrix, as well as the preset numerical sequence generation rules. It is a visual manifestation of the attributes of the data to be signed and the information of the exclusive parameter set. Subsequently, key coordinate points will be filtered based on this connected graph.
[0125] The transformation matrix is obtained through a series of matrix transformation operations, integrating the information of the data to be signed and the exclusive parameter set. Combine the numerical elements in the transformation matrix into a third numerical sequence according to certain rules (such as row-first or column-first). Generate multiple target coordinate points based on the third numerical sequence. A method similar to that for generating the previous coordinate points can be adopted. For example, combine two numbers in the third numerical sequence to form a coordinate point. These target coordinate points represent another form of the information contained in the transformation matrix and are used for subsequent comparison of the positional relationship with the connected graph.
[0126] Place all the target coordinate points and the connected graph in the same coordinate system. By calculating the relative positional relationship between the target coordinate points and the connected graph, such as determining whether the target coordinate points are inside, outside the connected graph, or the distance from the graph boundary, etc. The preset conditions can be set according to the requirements of security and key generation. For example, select the coordinate points inside the connected graph, or select the coordinate points within a certain range from the connected graph boundary, etc. According to the preset conditions, filter out the qualified coordinate points from all the target coordinate points, and use these coordinate points as the key coordinate points. These key coordinate points integrate the information of the data to be signed, the exclusive parameter set, and the matrix transformation, and are the key data for generating the transformation key.
[0127] Combine and process the numbers in each key coordinate point according to certain rules. For example, arrange the abscissa and ordinate of the coordinate points in sequence, or perform specific mathematical operations (such as summation, product, etc.). Finally, generate the transformation key. This transformation key is unique and closely related to the current signature task, and can be used to encrypt and store each sub-private key, signature semi-finished product, and signature finished product to ensure the security of the signed data.
[0128] Refer to Figure 2 , in another embodiment of the present invention, an efficient signature system based on the SM9 algorithm is further provided, including:
[0129] An acquisition unit for acquiring the attributes of the data to be signed;
[0130] A generation unit for generating an exclusive parameter set adapted to the current signature task based on the attributes of the data to be signed according to the SM9 algorithm; the exclusive parameter set includes core operation parameters adapted to the attributes;
[0131] A splitting unit, configured to split the master private key to obtain multiple sub-private keys with different key levels; the key level of each sub-private key is dynamically set according to the risk hazards of the current signature task.
[0132] An operation unit, configured to perform weighted signature operations on the core operation parameters in the exclusive parameter set respectively based on the sub-private keys with different key levels, and generate multiple signature semi-finished products with key level weight imprints.
[0133] A signature unit, configured to integrate all the signature semi-finished products to obtain a signature finished product for signing the data to be signed.
[0134] In this embodiment, for the specific implementation of each unit in the above system embodiment, please refer to the description in the above method embodiment, and details are not described herein again.
[0135] Refer to Figure 3 , in an embodiment of the present invention, a computer device is further provided. The computer device may be a server, and its internal structure may be as Figure 3 shown. The computer device includes a processor, a memory, a display screen, an input device, a network interface, and a database connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store the corresponding data in this embodiment. The network interface of the computer device is used to communicate with an external terminal through a network connection. The computer program, when executed by the processor, implements the above method.
[0136] Those skilled in the art can understand that Figure 3 the structure shown in
[0137] is only a block diagram of a part of the structure related to the solution of the present invention, and does not constitute a limitation on the computer device to which the solution of the present invention is applied.
[0138] In summary, the efficient signature method and system based on the SM9 algorithm provided in the embodiment of the present invention include: obtaining the attributes of the data to be signed; generating an exclusive parameter set adapted to this signature task based on the SM9 algorithm according to the attributes of the data to be signed; the exclusive parameter set includes core operation parameters adapted to the attributes; splitting the master private key to obtain multiple sub-private keys with different key levels; the key level of each sub-private key is dynamically set according to the risk hazards of this signature task; based on the sub-private keys of different key levels, weighted signature operations are performed for the core operation parameters in the exclusive parameter set respectively, and multiple signature semi-finished products with key level weight imprints are generated; all signature semi-finished products are integrated to obtain signature finished products to sign the data to be signed. In the present invention, an exclusive parameter set is generated according to the attributes of the data to be signed, the master private key is flexibly split and the signature operation is performed in a targeted manner, and differentiated digital signatures are generated for different data to be signed, thereby improving the security, efficiency and adaptability of digital signatures.
[0139] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, storage, database or other media provided by the present invention and used in the embodiments may include non-volatile and / or volatile memory. Non-volatile memory may include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory may include random access memory (RAM) or external cache memory. As an illustration and not limitation, RAM is available in a variety of forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double-speed data rate SDRAM (SSRSDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink) DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM.
[0140] It should be noted that in this text, the term "including", "comprising" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, device, article or method including a series of elements not only includes those elements, but also includes other elements not explicitly listed, or further includes elements inherent to such process, device, article or method. Without further limitation, an element defined by the statement "including one..." does not exclude the existence of additional identical elements in the process, device, article or method including such element.
[0141] The above are only the preferred embodiments of the present invention, and do not limit the patent scope of the present invention. Any equivalent structure or equivalent process transformation made by using the content of the specification and drawings of the present invention, or directly or indirectly applied in other related technical fields, shall be equally included in the patent protection scope of the present invention.
Claims
1. An efficient signature method based on the SM9 algorithm, characterized in that: The following steps are involved: Get the attributes of the data to be signed; According to the attributes of the data to be signed, a dedicated parameter set adapted to this signature task is generated based on the SM9 algorithm; the dedicated parameter set includes core operation parameters adapted to the attributes; The master private key is split to obtain multiple sub-private keys with different key levels. The key level of each sub-private key is dynamically set according to the risk of this signing task. Based on the sub-private keys of different key levels, weighted signature operations are performed on the core operation parameters in the exclusive parameter set to generate multiple signature semi-finished products with key level weight imprints; Integrate all the semi-finished signatures to obtain the finished signatures to sign the data to be signed.
2. The efficient signature method based on the SM9 algorithm according to claim 1, characterized in that: The attributes of the data to be signed include the data type, data length, and key elements in the data.
3. The efficient signature method based on the SM9 algorithm according to claim 1, characterized in that: According to the attributes of the data to be signed, a dedicated parameter set adapted to this signature task is generated based on the SM9 algorithm, including: Analyze the attributes of the data to be signed, identify the sensitivity of the data to be signed, and mark it; Based on the mark, the corresponding basic parameter template in the SM9 algorithm is retrieved; Adjust the hash function parameters in the basic parameter template in combination with the data length of the data to be signed; Based on the adjusted parameter template, the current system timestamp information is integrated, the random number generation parameters in the parameter template are calibrated, and a dedicated parameter set adapted to this signature task is generated.
4. The efficient signature method based on the SM9 algorithm according to claim 1, characterized in that: The master private key is split into multiple sub-private keys with different key levels, including: Analyze the risk level of the data to be signed; Determine the number of splits of the master private key and the key level of the sub-private key according to the risk level of the data to be signed; Based on the number of splits, the master private key is split using the Shamir secret sharing algorithm to obtain a corresponding number of sub-private keys; Each sub-private key is marked with the corresponding key level information, and different storage strategies are configured for sub-private keys of different key levels; among them, the sub-private keys of the highest key level are stored in a secure storage device with multiple encryption and physical isolation, and integrity verification and backup are performed regularly.
5. The efficient signature method based on the SM9 algorithm according to claim 1, characterized in that: Based on the sub-private keys of different key levels, weighted signature operations are performed on the core operation parameters in the exclusive parameter set to generate multiple semi-finished signatures with key level weight imprints, including: Real-time monitoring of multiple indicators of the computing environment as the initial parameters of the chaotic system, dynamically generating weights of sub-private keys at different key levels through chaotic mapping; Combining optical calculation with electronic calculation, using dynamically generated weights to perform weighted signature calculation on the core calculation parameters in the exclusive parameter set; The signature operation process is verified based on zero-knowledge proof technology. If the verification is successful, multiple semi-finished signatures with key level weight imprints are obtained.
6. The efficient signature method based on the SM9 algorithm according to claim 1, characterized in that: All semi-finished signatures are integrated to obtain the finished signatures, which include: Generate a first matrix based on the attributes of the data to be signed; generating a second matrix based on the exclusive parameter set; Based on the first matrix, transform the second matrix to obtain a transformation matrix; A transformation key is generated based on the transformation matrix, and each of the sub-private keys, the semi-finished signature product and the finished signature product is encrypted and stored based on the transformation key.
7. The efficient signature method based on the SM9 algorithm according to claim 6, characterized in that: Based on the first matrix, transforming the second matrix to obtain a transformation matrix includes: Analyze each element of the first matrix, detect English character elements therefrom and connect them in sequence to obtain a first graph; Add the first graphic to the second matrix, and use the elements in the second matrix that overlap with the first graphic as transformation elements; Calculating the mean of the digital character elements in the first matrix; The mean value is added to each of the transformation elements in the second matrix to obtain a transformation matrix.
8. An efficient signature system based on the SM9 algorithm, characterized in that: include: An acquisition unit, used to acquire the attributes of the data to be signed; A generating unit, configured to generate a dedicated parameter set adapted to the current signature task based on the SM9 algorithm according to the attributes of the data to be signed; the dedicated parameter set includes core operation parameters adapted to the attributes; The splitting unit is used to split the master private key into multiple sub-private keys with different key levels. The key level of each sub-private key is dynamically set according to the risk of this signature task. A computing unit, configured to perform weighted signature computing on the core computing parameters in the exclusive parameter set based on the sub-private keys of different key levels, and generate a plurality of semi-finished signature products with key level weight imprints; The signature unit is used to integrate all the semi-finished signatures to obtain the finished signatures in order to sign the data to be signed.
Citation Information
Patent Citations
Digital currency wallet, transaction method, transaction system and computer storage medium
CN109961276A
Universal hierarchical signature encryption system and construction method
CN113259094A