Selective information verification method for digital certificate
By receiving and verifying the certificate display information sent by the digital certificate holder and its corresponding Merkel proof and BLS signature information, reconstructing the Merkel tree and proofreading its root node, solving the security and efficiency of digital certificate selective information verification in the prior art, and achieving efficient and secure digital certificate verification.
Patent Information
- Application Number
- CN202510082202.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-20
- Publication Date
- 2025-05-06
AI Technical Summary
It is difficult for the prior art to verify the reliability and integrity of the digital certificate without exposing the entire contents of the digital certificate, especially when multiple digital certificates require selective information verification at the same time. How to ensure the security of the verification is a key issue.
By receiving the certificate display information sent by the digital certificate holder and its corresponding Merkel proof and BLS signature information, the Merkel tree is reconstructed and its root node is calculated, the Merkel tree root corresponding to the certificate is proofreaded, and the authenticity of the BLS signature information is verified to realize the selective information verification of the digital certificate.
While ensuring the integrity of digital certificates, it effectively reduces the data volume overhead during verification, realizes efficient verification of digital certificates, and ensures security when multiple digital certificates are verified through joint signatures.
Smart Images

Figure CN119945770A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the technical field of network security, and in particular to a selective information verification method for a digital certificate. Background Art
[0002] With the development of the Internet, more and more credentials are digitized, and different digital certificates represent different identities of the holders. Digital certificates are closely linked to personal information, which makes the privacy protection of digital certificates increasingly important. In order to improve verification efficiency and reduce unnecessary data transmission, people usually perform selective information verification on digital certificates. In the face of network security risks of digital certificates, selective information verification is an issue worthy of attention. At present, there are many methods for selective information verification of digital certificates. How to verify the reliability of the disclosed information and how to prove the integrity of the certificate without exposing all the certificate contents is still a key issue. Summary of the invention
[0003] The present disclosure aims to solve at least one of the problems existing in the prior art and provide a selective information verification method for a digital certificate.
[0004] In one aspect of the present disclosure, a method for selective information verification of a digital certificate is provided, the method comprising:
[0005] Receive certificate display information and its corresponding Merkle proof sent by the holder of the digital certificate, as well as BLS signature information corresponding to one or more digital certificates involved in the certificate display information; wherein the certificate display information includes partial content information of one or more digital certificates involved therein;
[0006] Reconstructing a corresponding Merkle tree using the certificate display information and its corresponding Merkle proof, and calculating a Merkle tree root of the reconstructed Merkle tree;
[0007] The Merkle root of the reconstructed Merkle tree is collated with the Merkle root of its corresponding digital certificate, and the authenticity of the BLS signature information is verified.
[0008] Optionally, when the certificate display information includes partial content information of a digital certificate involved in the certificate display information, the BLS signature information is obtained by performing a BLS signature on the Merkle tree root of the digital certificate involved in the certificate display information.
[0009] Optionally, when the certificate display information includes partial content information of multiple digital certificates involved, the certificate display information includes multiple sub-certificate display information, each sub-certificate display information corresponds to partial content information of a digital certificate;
[0010] The step of reconstructing a corresponding Merkle tree using the certificate display information and its corresponding Merkle proof, and calculating a Merkle tree root of the reconstructed Merkle tree, includes:
[0011] Using each of the sub-certificate presentation information and its corresponding Merkle proof, a Merkle tree corresponding to each of the sub-certificate presentation information is reconstructed, and the Merkle tree roots of each of the reconstructed Merkle trees are calculated respectively.
[0012] Optionally, the BLS signature information is obtained by aggregating the BLS signatures of the Merkle tree roots of the digital certificates corresponding to the sub-certificate presentation information.
[0013] Optionally, the Merkle tree root of the digital certificate is calculated based on a Merkle tree with content information of the digital certificate as leaf nodes.
[0014] Optionally, verifying the authenticity of the BLS signature information includes:
[0015] The authenticity of the BLS signature information is verified using the public key infrastructure system.
[0016] Another aspect of the present disclosure provides a selective information verification device for a digital certificate, the device comprising:
[0017] A receiving module, used to receive certificate display information and its corresponding Merkle proof sent by the holder of the digital certificate and BLS signature information corresponding to one or more digital certificates involved in the certificate display information; wherein the certificate display information includes partial content information of one or more digital certificates involved therein;
[0018] A reconstruction module, used to reconstruct a corresponding Merkle tree using the certificate display information and its corresponding Merkle proof, and calculate a Merkle tree root of the reconstructed Merkle tree;
[0019] The verification module is used to check the Merkle root of the reconstructed Merkle tree with the Merkle root of its corresponding digital certificate and verify the authenticity of the BLS signature information.
[0020] Another aspect of the present disclosure provides an electronic device, including:
[0021] at least one processor; and,
[0022] a memory communicatively connected to at least one processor; wherein,
[0023] The memory stores instructions that can be executed by at least one processor. The instructions are executed by the at least one processor so that the at least one processor can execute the selective information verification method of the digital certificate described above.
[0024] Another aspect of the present disclosure provides a computer-readable storage medium storing a computer program, which implements the selective information verification method of the digital certificate described above when executed by a processor.
[0025] Another aspect of the present disclosure provides a computer program product, including a computer program, which implements the selective information verification method of the digital certificate described above when the computer program is executed by a processor.
[0026] Compared with the prior art, the present invention cleverly utilizes the composite hash structure and existence proof characteristics of the Merkle tree to realize the selective information disclosure of digital certificates, effectively reduces the data volume overhead during digital certificate verification while ensuring the integrity of the digital certificate, and realizes efficient verification of digital certificates. At the same time, combined with the characteristics of BLS signature in security verification and joint signature, when multiple digital certificates need to perform selective information verification at the same time, the authenticity verification of multiple digital certificates can be realized by using joint signature, thereby further ensuring the security of digital certificate verification. BRIEF DESCRIPTION OF THE DRAWINGS
[0027] One or more embodiments are exemplarily described by pictures in the corresponding drawings, and these exemplifications do not constitute limitations on the embodiments. Elements with the same reference numerals in the drawings represent similar elements, and unless otherwise stated, the figures in the drawings do not constitute proportional limitations.
[0028] Figure 1 A flowchart of a selective information verification method for a digital certificate provided in one embodiment of the present disclosure;
[0029] Figure 2 A schematic diagram of an application scenario of a selective information verification method for a digital certificate provided by another embodiment of the present disclosure;
[0030] Figure 3 A data flow diagram of a selective information verification method for a digital certificate in a single certificate scenario provided by another embodiment of the present disclosure;
[0031] Figure 4 A schematic diagram of a Merkle tree structure and a Merkle proof provided for another embodiment of the present disclosure;
[0032] Figure 5 A data flow diagram of a selective information verification method for a digital certificate in a multi-certificate scenario provided by another embodiment of the present disclosure;
[0033] Figure 6 A schematic diagram of the structure of a selective information verification device for a digital certificate provided by another embodiment of the present disclosure;
[0034] Figure 7 A schematic structural diagram of an electronic device provided in another embodiment of the present disclosure. DETAILED DESCRIPTION
[0035] In order to make the purpose, technical scheme and advantages of the embodiments of the present disclosure clearer, the embodiments of the present disclosure will be described in detail below in conjunction with the accompanying drawings. However, it can be understood by those skilled in the art that in each embodiment of the present disclosure, many technical details are proposed in order to enable readers to better understand the present disclosure. However, even without these technical details and various changes and modifications based on the following embodiments, the technical scheme claimed for protection in the present disclosure can also be implemented. The division of the following embodiments is for the convenience of description and should not constitute any limitation on the specific implementation of the present disclosure. The various embodiments can be combined and referenced with each other without contradiction.
[0036] The verification process of a digital certificate usually involves three roles, namely the issuer, the holder, and the verifier. Among them, the issuer creates and issues a digital certificate for the holder, and records the relevant information of the digital certificate to the cloud server. The holder sends the digital certificate he owns to the verifier who needs to verify his identity. The verifier can verify the authenticity and reliability of the digital certificate sent by the holder through the relevant information of the digital certificate recorded by the cloud server. Selective verification of a digital certificate means that the holder does not want to provide all the information of the digital certificate to the verifier, but only wants to provide part of the information of the digital certificate for verification by the verifier. In other words, the selective verification process of a digital certificate will neither leak all the information of the digital certificate, nor allow the verifier to verify the reliability and authenticity of part of the information of the digital certificate.
[0037] One embodiment of the present disclosure relates to a selective information verification method for a digital certificate, the process of which is as follows: Figure 1 As shown, the process includes steps S110 to S130 and can be applied to the verifier of the digital certificate.
[0038] Step S110, receiving certificate display information sent by the holder of the digital certificate and its corresponding Merkle proof and BLS signature information corresponding to one or more digital certificates involved in the certificate display information. The certificate display information includes partial content information of one or more digital certificates involved.
[0039] Specifically, certificate display information refers to partial content information of a digital certificate disclosed by the holder of a digital certificate to a verifier, which may come from one digital certificate or from multiple digital certificates. When it comes from multiple digital certificates, the certificate display information may include partial content information of each digital certificate.
[0040] The Merkle proof corresponding to the certificate display information can be generated by the holder of the digital certificate based on the Merkle tree of the digital certificate. Among them, the Merkle tree of the digital certificate can be constructed by the issuer of the digital certificate. The issuer can define the content information of the digital certificate as the various attributes of the digital certificate, and then construct a Merkle tree with the various attributes of the digital certificate as leaf nodes, and calculate the Merkle tree root of the Merkle tree as the Merkle tree root of the digital certificate. In other words, the Merkle tree root of the digital certificate can be calculated based on the Merkle tree with the content information of the digital certificate as the leaf node. On this basis, the holder of the digital certificate can generate the corresponding Merkle proof based on the partial attributes of the digital certificate corresponding to the certificate display information selected by it, for verification and use by the verifier of the digital certificate.
[0041] The Merkle tree structure can achieve selective disclosure and verification of certificate information, but it cannot guarantee that the information sent by the holder to the verifier will not be tampered with. To this end, this implementation introduces the BLS (Boneh-Lynn-Shacham) signature algorithm to ensure the security of data interaction. Among them, the BLS signature algorithm is a cryptographic algorithm based on bilinear mapping, named after its three inventors Dan Boneh, Ben Lynn and Hovav Shacham. The BLS signature algorithm uses bilinear pairing for verification, and the signature itself is an element of the elliptic curve.
[0042] Exemplarily, in a single certificate scenario, that is, when the certificate display information includes partial content information of a digital certificate involved, the BLS signature information is obtained by performing a BLS signature on the Merkle tree root of the digital certificate involved in the certificate display information.
[0043] Specifically, the single certificate scenario refers to a scenario where only one digital certificate needs to be selectively verified. This scenario mainly includes two situations: one is that the holder needs to selectively disclose part of the content information of a digital certificate held by him to a verifier, that is, a digital certificate of the holder needs a verifier to perform selective information verification; the other is that the holder needs to selectively disclose part of the content information of a digital certificate held by him to multiple verifiers, that is, a digital certificate of the holder needs multiple verifiers to perform selective information verification. For example, in the job search process, the job seeker needs to disclose the information of his degree certificate to different companies for verification. At this time, the job seeker is the holder of the digital certificate, and each company is the verifier of the digital certificate. Since the verification requirements of different companies may be different, the job seeker as the holder can choose to disclose only part of the relevant information on the degree certificate to the corresponding company according to the verification requirements of different companies, so that each company as the verifier completes the corresponding degree verification and realizes the privacy protection of personal information. The above two situations in the single certificate scenario are essentially the same, both of which are that the holder selectively discloses the content of a digital certificate held by him to the verifier so that the verifier completes the selective information verification of the digital certificate.
[0044] Since the single certificate scenario only involves one digital certificate, in the single certificate scenario, when performing BLS signing on the Merkle tree root of the digital certificate, only the ordinary BLS signature can be used. The process of performing BLS signing on the Merkle tree of the digital certificate can be completed by the issuer of the digital certificate, and the issuer sends the BLS signature information obtained by the BLS signing process to the holder.
[0045] Exemplarily, in a multi-certificate scenario, when the certificate display information includes partial content information of multiple digital certificates involved, the certificate display information includes multiple sub-certificate display information, each sub-certificate display information corresponds to partial content information of a digital certificate, and the BLS signature information is obtained by aggregating the BLS signatures of the Merkle tree roots of the digital certificates corresponding to each sub-certificate display information.
[0046] Specifically, the multi-certificate scenario refers to a scenario where multiple digital certificates need to undergo selective information verification. In this scenario, the holder of a digital certificate has multiple digital certificates, which come from different issuers. The holder selectively discloses different content to the verifier for the multiple digital certificates he owns, and the verifier needs to verify the authenticity and reliability of these digital certificates at the same time. The sub-certificate display information is used to indicate the partial content information to be verified in the corresponding digital certificate.
[0047] In a multi-certificate scenario, since each sub-certificate displays information corresponding to a digital certificate, and each digital certificate has a Merkle tree root, the aggregability of BLS signatures can be used to calculate the joint signature of the BLS signatures of each Merkle tree root to achieve an aggregate signature, and the joint signature is used as the BLS signature information in multiple scenarios. Among them, the BLS signature process for each digital certificate can be completed by the issuer of the corresponding digital certificate, and each issuer sends the corresponding BLS signature to the holder, and the holder aggregates the BLS signatures corresponding to each digital certificate to obtain the final BLS signature information.
[0048] Step S120, reconstructing the corresponding Merkle tree using the certificate display information and its corresponding Merkle proof, and calculating the Merkle root of the reconstructed Merkle tree.
[0049] Specifically, the Merkle tree does not require a complete tree structure to verify the existence of a leaf node and the integrity of all leaf nodes. This verification is achieved through Merkle proof. Therefore, Merkle proof can be used to achieve selective information verification of the content of a digital certificate without disclosing the complete content of the digital certificate.
[0050] Since the single certificate scenario only involves one digital certificate, the Merkle root of the reconstructed Merkle tree in the single certificate scenario is the Merkle root of the reconstructed Merkle tree corresponding to the digital certificate involved in the scenario.
[0051] The multi-certificate scenario involves multiple digital certificates. Therefore, in the multi-certificate scenario, it is necessary to determine the reconstructed Merkle root corresponding to each digital certificate, so as to use the reconstructed Merkle root to verify each digital certificate. At this time, step S120 includes: using each sub-certificate display information and its corresponding Merkle proof, reconstructing the Merkle tree corresponding to each sub-certificate display information, and calculating the Merkle root of each reconstructed Merkle tree. Since each sub-certificate display information corresponds to part of the content information of a digital certificate, the calculated Merkle root of each Merkle tree is the reconstructed Merkle root corresponding to the corresponding digital certificate.
[0052] Step S130, the Merkle root of the reconstructed Merkle tree is collated with the Merkle root of its corresponding digital certificate, and the authenticity of the BLS signature information is verified.
[0053] Specifically, the Merkle root of the digital certificate is calculated by the issuer of the digital certificate. The issuer can store the Merkle root of the digital certificate to a cloud server so that the verifier can obtain the Merkle root of the digital certificate to be verified through the cloud server, and use step S130 to check the reconstructed Merkle root of the Merkle tree with the Merkle root of the corresponding digital certificate to verify the authenticity of the information displayed by the corresponding certificate.
[0054] In particular, in a single certificate scenario, the Merkle tree root of the Merkle tree reconstructed in step S120 is the reconstructed Merkle tree root corresponding to the digital certificate in this scenario. By comparing the reconstructed Merkle tree root with the Merkle tree root calculated based on the Merkle tree of the digital certificate, the authenticity of the certificate display information of the digital certificate can be verified.
[0055] In a multi-certificate scenario, the root of the Merkle tree reconstructed in step S120 is the reconstructed Merkle tree roots corresponding to the multiple digital certificates in the scenario. By comparing the reconstructed Merkle tree roots corresponding to each digital certificate with the Merkle tree roots calculated based on the Merkle tree of the corresponding digital certificate, the authenticity of the information displayed by the sub-certificates corresponding to each digital certificate can be verified.
[0056] Exemplarily, in step S130, verifying the authenticity of the BLS signature information includes: verifying the authenticity of the BLS signature information using a public key infrastructure system.
[0057] Specifically, the Public Key Infrastructure (PKI) system is a public key management facility that can securely transfer and manage public keys. This embodiment can use the PKI system to securely transfer and manage the public key corresponding to the BLS signature information, so as to verify the authenticity of the BLS signature information through the corresponding public key. Among them, in a single certificate scenario, the public key corresponding to the BLS signature information is the public key used when the digital certificate in this scenario is signed by BLS, and can be stored by the issuer of the digital certificate to the cloud server, so that the verifier can obtain the public key from the cloud server, and then use the public key to complete the authenticity verification of the BLS signature information. In a multi-certificate scenario, the public key corresponding to the BLS signature information is the public key used by each digital certificate in this scenario when signing BLS, and can be stored by the issuer of each digital certificate to the cloud server, so that the verifier can obtain these public keys from the cloud server, and then use these public keys to complete the authenticity verification of the BLS signature information.
[0058] Compared with the prior art, the selective information verification method for digital certificates provided in the embodiments of the present disclosure cleverly utilizes the composite hash structure and existence proof characteristics of the Merkle tree to realize selective information disclosure of digital certificates, effectively reduces the data volume overhead during digital certificate verification while ensuring the integrity of the digital certificate, and realizes efficient verification of digital certificates. At the same time, combined with the characteristics of BLS signature in security verification and joint signature, when multiple digital certificates need to perform selective information verification at the same time, the authenticity verification of multiple digital certificates can be realized by using joint signature, thereby further ensuring the security of digital certificate verification.
[0059] In order to enable those skilled in the art to better understand the above embodiments, Figures 2 to 5 , respectively, the selective information verification process of digital certificates in single certificate scenarios and multi-certificate scenarios is described in detail. Among them, both single certificate scenarios and multi-certificate scenarios involve three roles of digital certificate issuer, holder, and verifier.
[0060] In a single certificate scenario, combine Figure 2 , assuming that the issuer 1 sends the information contained in the digital certificate 1, such as information a1, information a2, information a3, and information a4, to the holder to complete the issuance of the certificate, and the issuer 1 also sends the relevant information of the digital certificate 1 to the cloud server to complete the certificate registration. The holder sends part of the content in the digital certificate 1, such as information a1 and information a3, as selective verification content to the verifier to complete the certificate sending for verification by the verifier. The verifier can use the relevant information of the digital certificate 1 stored in the cloud server to complete the verification of the selective verification content, namely information a1 and information a3, thereby realizing the certificate verification of the selective verification content.
[0061] Combined Figure 3 ,In a single certificate scenario, the selective information verification process of a digital certificate includes the following steps 11 to 19 .
[0062] Step 11: The issuer determines the format of the digital certificate C and records it as F.
[0063] Step 12, assuming that the content information of the digital certificate C is divided into N attributes, the format F of the digital certificate can be a JSON object containing N fields, and each attribute can be recorded as a1 to aN. When N = 4, the digital certificate C can be expressed as C = {a1, a2, a3, a4}, where a1, a2, a3, and a4 are the attributes of the digital certificate C. The issuer constructs a Merkle tree with each attribute of the digital certificate C as a leaf node and calculates its Merkle tree root R.
[0064] For example, combining Figure 4, when the digital certificate C is represented as C = {a1, a2, a3, a4}, the construction process of the Merkle tree of the digital certificate C and the calculation process of the Merkle root R include: first, hash a1 to a4 respectively to obtain the corresponding h1 to h4, where h1 = H(a1), h2 = H(a2), h3 = H(a3), h4 = H(a4), and H represents a hash algorithm such as SHA256. Then, the four hash values h1 to h4 are combined in pairs and hashed again to obtain h12 and h34, where h12 = H(h1||h2), h34 = H(h3||h4), and || represents the concatenation of the previous and next values. Finally, h12 and h34 are hashed again to obtain the Merkle root R = H(h12||h34).
[0065] Step 13: The issuer signs the Merkle tree root R through the BLS signature algorithm to obtain a digital signature σ, where σ = G(sk·H(msg)), G represents a prime number set, H represents a hash function, H and G will generate the prime order corresponding to the elliptic curve, sk represents the private key of the symmetric encryption for signing, and msg represents the information to be encrypted. Here, msg = R.
[0066] In step 14, the issuer stores the format F, Merkle root R, and digital signature σ of the Merkle root R of the digital certificate C to the cloud server to complete the registration of the certificate format and other certificate information, and sends the digital certificate C and digital signature σ to the holder at the same time. The issuer also publishes the public key pk corresponding to the digital signature σ to the cloud server. The cloud server is used to record the integrity information of the digital certificate C and provide relevant verification information to the verifier, so that the verifier can complete the selective information verification of the digital certificate C.
[0067] Step 15: After receiving the complete content of the digital certificate C, the holder selectively discloses part of the information as the selective verification information P according to the verifier's needs, and generates the Merkle proof proofM corresponding to P. The holder sends the selective verification information P, the corresponding Merkle proof proofM and the digital signature σ to the verifier.
[0068] Step 16, the verifier receives the selective verification information P, the corresponding Merkle proof M and the digital signature σ sent by the holder, wherein the selective verification information P is the certificate display information, the Merkle proof M is the Merkle proof corresponding to the certificate display information, and the digital signature σ is the BLS signature information corresponding to the digital certificate C involved in the certificate display information.
[0069] Step 17: The verifier uses the selective verification information P and its corresponding Merkle proof proofM to reconstruct the Merkle tree of the digital certificate C, and calculates the Merkle root R' of the Merkle tree.
[0070] For example, combining Figure 4 , when the digital certificate C is expressed as C = {a1, a2, a3, a4}, and the selective verification information P is expressed as P = (a1, a3), proofM = (h2||h4). At this time, the verifier can use P and proofM to reconstruct the Merkle tree and calculate the corresponding Merkle tree root R'.
[0071] Step 18, the verifier interacts with the cloud server to verify the authenticity of P. For example, since the cloud server has stored the Merkle root R of the digital certificate C provided by the issuer, the cloud server can check R' with R. If the two are consistent, true is fed back to the verifier, otherwise false is returned to the verifier, thereby completing the authenticity verification of P. Alternatively, the verifier can also obtain the Merkle root R of the digital certificate C from the cloud server, and then check R' with R to verify the authenticity of P.
[0072] Step 19, the verifier interacts with the cloud server to verify the authenticity of the digital signature σ. For example, since the cloud server has stored the public key pk provided by the issuer, the cloud server can use the public key pk to complete the authenticity verification of the digital signature σ. Alternatively, the verifier can also obtain the public key pk from the cloud server and then use the public key pk to complete the authenticity verification of the digital signature σ.
[0073] In a multi-certificate scenario, combine Figure 2 , assuming that issuer 1 sends information contained in digital certificate 1 such as information a1, information a2, information a3, and information a4 to the holder to complete the issuance of the certificate, and issuer 2 sends information contained in digital certificate 2 such as information b1, information b2, information b3, and information b4 to the holder to complete the issuance of the certificate, and issuer 1 also sends relevant information of digital certificate 1 to the cloud server to complete the certificate registration, and issuer 2 also sends relevant information of digital certificate 2 to the cloud server to complete the certificate registration, and the holder sends part of the content in digital certificate 1 such as information a1 and information a3 and part of the content in digital certificate 2 such as information b1 and information b3 as selective verification content to the verifier to complete the certificate sending for verification by the verifier, then the verifier can use the relevant information of digital certificate 1 and digital certificate 2 stored in the cloud server to complete the verification of the selective verification content, namely information a1 and information a3 and information b1 and information b3, thereby realizing certificate verification of selective verification content.
[0074] Combined Figure 5 In a multi-certificate scenario, assuming there are two issuers, issuer 1 and issuer 2, the selective information verification process of the digital certificate includes the following steps 21 to 29.
[0075] In step 21, issuer 1 and issuer 2 respectively determine the formats of the digital certificates they issue, wherein the format of the digital certificate of issuer 1 is recorded as F1, and the format of the digital certificate of issuer 2 is recorded as F2. Issuer 1 and issuer 2 send F1 and F2 to the cloud server respectively to complete the certificate format registration.
[0076] In step 22, issuer 1 and issuer 2 publish their public keys pk1 and pk2 used for BLS signing to the cloud server respectively.
[0077] Step 23, record the digital certificate issued by issuer 1 to the holder as C1, and record the digital certificate issued by issuer 2 to the holder as C2, where C1 = {a1, a2, a3, a4}, C2 = {b1, b2, b3, b4}, issuer 1 and issuer 2 respectively use the attributes of digital certificate C1 and digital certificate C2 as leaf nodes to construct a Merkle tree, and calculate the corresponding Merkle tree roots respectively, where the Merkle tree root of digital certificate C1 is recorded as R1, R1 = H(h12||h34), at this time, h12 = H(h1||h2), h34 = H(h3||h4), h1 = H(a1), h2 = H(a2), h3 = H(a3), h4 = H(a4). The Merkle tree root of digital certificate C2 is recorded as R2, R2 = H(h12||h34), at this time, h12 = H(h1||h2), h34 = H(h3||h4), h1 = H(b1), h2 = H(b2), h3 = H(b3), h4 = H(b4).
[0078] Step 23, Issuer 1 and Issuer 2 sign the Merkle tree roots R1 and R2 respectively through the BLS signature algorithm to obtain the corresponding digital signatures σ1 and σ2. Replace σ with σ1, replace sk with the corresponding private key, and replace msg with R1, and you can get the digital signature σ1 according to σ=G(sk·H(msg)). Similarly, replace σ with σ2, replace sk with the corresponding private key, and replace msg with R2, and you can get the digital signature σ2 according to σ=G(sk·H(msg)).
[0079] In step 24, issuer 1 stores the format F1 of digital certificate C1, Merkle root R1, and digital signature σ1 of Merkle root R1 to the cloud server, and issuer 2 stores the format F2 of digital certificate C2, Merkle root R2, and digital signature σ2 of Merkle root R2 to the cloud server. At the same time, issuer 1 sends digital certificate C1 and digital signature σ1 to the holder, and issuer 2 sends digital certificate C2 and digital signature σ2 to the holder.
[0080] Step 25, after the holder receives the complete contents of digital certificates C1 and C2, according to the verifier's needs, the holder selectively discloses part of the information from digital certificates C1 and C2 respectively, obtains the corresponding selective verification information P1 and P2 as the certificate display information, generates Merkle proofs proofM1 and proofM2 corresponding to P1 and P2 respectively, and performs aggregate signatures on digital signatures σ1 and σ2 to obtain the corresponding joint signature σA. The joint signature σA is the BLS signature information corresponding to the digital certificates C1 and C2 involved in the certificate display information, which can be expressed as σ A =Σ{σi}, i=1, 2. The holder sends the selective verification information P1 and P2, the corresponding Merkle proofs proofM1 and proofM2, and the joint signature σA to the verifier.
[0081] In step 26, the verifier receives the selective verification information P1 and P2, the corresponding Merkle proofs proofM1 and proofM2, and the joint signature σA sent by the holder.
[0082] Step 27, the verifier uses the selective verification information P1 and its corresponding Merkle proof proofM1 to reconstruct the Merkle tree of the digital certificate C1, and calculates the Merkle root R1' of the Merkle tree, and uses the selective verification information P2 and its corresponding Merkle proof proofM2 to reconstruct the Merkle tree of the digital certificate C2, and calculates the Merkle root R2' of the Merkle tree.
[0083] Step 28, the verifier interacts with the cloud server to verify the authenticity of P1 and P2. For example, since the cloud server has stored the Merkle root R1 of the digital certificate C1 provided by the issuer, the cloud server can check R1' with R1. If the two are consistent, true is fed back to the verifier, otherwise false is returned to the verifier, thereby completing the authenticity verification of P1. Alternatively, the verifier can also obtain the Merkle root R1 of the digital certificate C1 from the cloud server, and then check R1' with R1 to verify the authenticity of P1. Similarly, the cloud server can check R2' with R2. If the two are consistent, true is fed back to the verifier, otherwise false is returned to the verifier, thereby completing the authenticity verification of P2. Alternatively, the verifier can also obtain the Merkle root R2 of the digital certificate C2 from the cloud server, and then check R2' with R2 to verify the authenticity of P2. If the verification result shows that R1' is consistent with R1 and R2' is consistent with R2, it indicates that the selective verification information P1 and P2 provided by the holder are true and reliable.
[0084] Step 29, the verifier interacts with the cloud server to verify the authenticity of the joint signature σA. For example, since the cloud server has stored the public key pk1 provided by issuer 1 and the public key pk2 provided by issuer 2, the cloud server can use the public key pk1 and the public key pk2 to complete the authenticity verification of the joint signature σA. Alternatively, the verifier can also obtain the public key pk1 and the public key pk2 from the cloud server, and then use the public key pk1 and the public key pk2 to complete the authenticity verification of the joint signature σA.
[0085] It should be noted that the above multi-certificate scenario is only described for a scenario involving two issuers. The selective verification process of digital certificates when the multi-certificate scenario includes more than two issuers is similar to the selective verification process of digital certificates when it includes two issuers. Assuming that the multi-certificate scenario includes M issuers, involving a total of M digital certificates, i∈M, then the format corresponding to the digital certificate Ci can be recorded as Fi, the corresponding Merkle root can be recorded as Ri, the digital signature of the Merkle root Ri can be recorded as σi, and the joint signature of the digital signatures of the Merkle roots of each digital certificate can be recorded as σ A =Σ{σi}, at the same time, the selective verification information corresponding to the digital certificate Ci can be recorded as Pi, and the corresponding Merkle proof can be recorded as proofMi.
[0086] Another embodiment of the present disclosure relates to a selective information verification device for a digital certificate, such as Figure 6 As shown, it includes a receiving module 610, a reconstruction module 620, and a verification module 630.
[0087] The receiving module 610 is used to receive the certificate display information sent by the holder of the digital certificate and its corresponding Merkle proof and the BLS signature information corresponding to one or more digital certificates involved in the certificate display information. The certificate display information includes partial content information of one or more digital certificates involved.
[0088] The reconstruction module 620 is used to reconstruct the corresponding Merkle tree using the certificate display information and its corresponding Merkle proof, and calculate the Merkle root of the reconstructed Merkle tree.
[0089] The verification module 630 is used to check the Merkle root of the reconstructed Merkle tree with the Merkle root of its corresponding digital certificate and verify the authenticity of the BLS signature information.
[0090] The specific implementation method of the selective information verification device for the digital certificate provided in the embodiment of the present disclosure can be found in the selective information verification method for the digital certificate provided in the embodiment of the present disclosure, which will not be repeated here.
[0091] Compared with the prior art, the selective information verification device for digital certificates provided in the embodiments of the present disclosure cleverly utilizes the composite hash structure and existence proof characteristics of the Merkle tree to realize selective information disclosure of digital certificates, effectively reduces the data volume overhead during digital certificate verification while ensuring the integrity of the digital certificate, and realizes efficient verification of digital certificates. At the same time, combined with the characteristics of BLS signature in security verification and joint signature, when multiple digital certificates need to perform selective information verification at the same time, the authenticity verification of multiple digital certificates can be realized by using joint signature, thereby further ensuring the security of digital certificate verification.
[0092] Another embodiment of the present disclosure relates to an electronic device, such as Figure 7 As shown, including:
[0093] at least one processor 701; and,
[0094] A memory 702 is communicatively connected to at least one processor 701; wherein,
[0095] The memory 702 stores instructions that can be executed by at least one processor 701. The instructions are executed by the at least one processor 701 so that the at least one processor 701 can execute the selective information verification method of the digital certificate described in the above embodiment.
[0096] Among them, the memory and the processor are connected in a bus manner, and the bus may include any number of interconnected buses and bridges, and the bus connects various circuits of one or more processors and memories together. The bus can also connect various other circuits such as peripherals, voltage regulators, and power management circuits, which are well known in the art and are therefore not further described herein. The bus interface provides an interface between the bus and the transceiver. The transceiver can be one element or multiple elements, such as multiple receivers and transmitters, providing a unit for communicating with various other devices on a transmission medium. The data processed by the processor is transmitted on a wireless medium via an antenna, and further, the antenna also receives data and transmits the data to the processor.
[0097] The processor is responsible for managing the bus and general processing, and can also provide various functions, including timing, peripheral interfaces, voltage regulation, power management, and other control functions. Memory can be used to store data used by the processor when performing operations.
[0098] Another embodiment of the present disclosure relates to a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the selective information verification method of a digital certificate described in the above embodiment.
[0099] That is, those skilled in the art can understand that all or part of the steps in the method described in the above embodiments can be completed by instructing the relevant hardware through a program, and the program is stored in a storage medium, including several instructions for making a device (which can be a single-chip microcomputer, chip, etc.) or a processor (processor) perform all or part of the steps of the method described in each embodiment of the present disclosure. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM), random access memory (RAM), disk or optical disk and other media that can store program codes.
[0100] Another embodiment of the present disclosure relates to a computer program product, including a computer program, which implements the selective information verification method of the digital certificate described in the above embodiment when the computer program is executed by a processor.
[0101] Those skilled in the art will appreciate that the above-mentioned embodiments are specific embodiments for implementing the present disclosure, and in actual applications, various changes may be made thereto in form and detail without departing from the spirit and scope of the present disclosure.
Claims
1. A selective information verification method for a digital certificate, characterized in that: The method comprises: Receive certificate display information and its corresponding Merkle proof sent by the holder of the digital certificate, as well as BLS signature information corresponding to one or more digital certificates involved in the certificate display information; wherein the certificate display information includes partial content information of one or more digital certificates involved therein; Reconstructing a corresponding Merkle tree using the certificate display information and its corresponding Merkle proof, and calculating a Merkle tree root of the reconstructed Merkle tree; The Merkle root of the reconstructed Merkle tree is collated with the Merkle root of its corresponding digital certificate, and the authenticity of the BLS signature information is verified.
2. The method according to claim 1, characterized in that When the certificate display information includes partial content information of a digital certificate involved in the certificate display information, the BLS signature information is obtained by performing a BLS signature on the Merkle tree root of the digital certificate involved in the certificate display information.
3. The method according to claim 1, characterized in that When the certificate display information includes partial content information of multiple digital certificates involved, the certificate display information includes multiple sub-certificate display information, each sub-certificate display information corresponds to partial content information of a digital certificate; The step of reconstructing a corresponding Merkle tree using the certificate display information and its corresponding Merkle proof, and calculating a Merkle tree root of the reconstructed Merkle tree, includes: Using each of the sub-certificate presentation information and its corresponding Merkle proof, a Merkle tree corresponding to each of the sub-certificate presentation information is reconstructed, and the Merkle tree roots of each of the reconstructed Merkle trees are calculated respectively.
4. The method according to claim 3, characterized in that: The BLS signature information is obtained by aggregating the BLS signatures of the Merkle tree roots of the digital certificates corresponding to the sub-certificate presentation information.
5. The method according to any one of claims 1 to 4, characterized in that: The Merkle tree root of the digital certificate is calculated based on a Merkle tree with the content information of the digital certificate as a leaf node.
6. The method according to any one of claims 1 to 4, characterized in that: The verifying the authenticity of the BLS signature information includes: The authenticity of the BLS signature information is verified using the public key infrastructure system.
7. A selective information verification device for a digital certificate, characterized in that: The device comprises: A receiving module, used to receive certificate display information and its corresponding Merkle proof sent by the holder of the digital certificate and BLS signature information corresponding to one or more digital certificates involved in the certificate display information; wherein the certificate display information includes partial content information of one or more digital certificates involved therein; A reconstruction module, used to reconstruct a corresponding Merkle tree using the certificate display information and its corresponding Merkle proof, and calculate a Merkle tree root of the reconstructed Merkle tree; The verification module is used to check the Merkle root of the reconstructed Merkle tree with the Merkle root of its corresponding digital certificate and verify the authenticity of the BLS signature information.
8. An electronic device, characterized in that: include: at least one processor; as well as, a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method according to any one of claims 1 to 6.
9. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 6 is implemented.
10. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the method according to any one of claims 1 to 6 is implemented.
Citation Information
Cited By
Digital certificate batch issuing method, verification method, device, equipment and program product
CN121690636A