High-performance timestamp issuing method and system based on national cryptographic algorithm

By adopting the Guoxin algorithm and efficient data management technology in the timestamp issuing system, the bottlenecks and security risks of traditional systems are solved, and the fast, secure generation and verification of timestamps are achieved, meeting the needs of high performance and strong security.

CN119966631APending Publication Date: 2025-05-09BEIJING CATHAY INTERNET INFORMATION TECH CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411901064.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-23
Publication Date
2025-05-09

AI Technical Summary

Technical Problem

The traditional timestamp issuing system is based on international encryption algorithms, which has performance bottlenecks and security risks, making it difficult to meet the needs of independent and controllable information security.

Method used

The high-performance timestamp issuance method based on Guomi algorithm is adopted, and through efficient data storage management, data preloading and high concurrency technology, combined with Guomi SM3 and SM2 algorithms, the fast, secure generation and verification of timestamps are achieved.

Benefits of technology

It improves the performance of timestamp issuance services, meets the high-performance needs under large-scale concurrent requests, and at the same time enhances security, meeting the dual needs of high performance and strong security in e-government, e-commerce and other fields.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119966631A_ABST
    Figure CN119966631A_ABST
Patent Text Reader

Abstract

The invention provides a high-performance timestamp signing and issuing method based on a national cryptographic algorithm, and the method comprises the steps: receiving a timestamp signing and issuing request, and analyzing a request parameter; high-precision time synchronization information is obtained through the network time protocol server; after the request parameter and the time synchronization information are combined, digest calculation is carried out by using a national cipher SM3 algorithm to generate a digest value; signing the digest value by using a secret key of a timestamp signing and issuing mechanism by adopting a national secret SM2 algorithm; the timestamp information is integrated and coded, a timestamp in a standard format is packaged, and the timestamp is signed and issued to a requester; wherein the timestamp information comprises time synchronization information, an abstract value, a signature and information of a timestamp issuing mechanism. According to the invention, the quick and safe generation and verification of the timestamp are realized, and the dual requirements of high performance and high security of the timestamp service in the fields of e-government affairs, e-commerce, intellectual property protection and the like are met.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of information security and time synchronization, and in particular to a high-performance timestamp issuance method and system based on a national secret algorithm. Background Art

[0002] With the rapid development of information technology, timestamp, as an important means to ensure data integrity and time accuracy, has been widely used in electronic data authentication, intellectual property protection, judicial evidence collection and other fields.

[0003] Traditional timestamp issuance systems often use international encryption algorithms based on the OpenSSL cryptographic library, which have performance bottlenecks and security risks. At the same time, with the increasing demand for independent and controllable information security, it has become an inevitable trend to use domestic cryptographic algorithms to build timestamp issuance systems. By using efficient data storage management, data preloading and high concurrency and other technical means, we can reduce resource consumption, improve concurrent processing capabilities, and optimize timestamp issuance service performance. Summary of the invention

[0004] In response to the problems existing in the prior art, a high-performance timestamp issuance method and system based on the national secret algorithm is provided. By optimizing service performance through efficient data storage management, data preloading, high concurrency and other technologies combined with the national secret algorithm, the fast and secure generation and verification of timestamps can be achieved, meeting the high performance and strong security requirements under large-scale concurrent requests.

[0005] The first aspect of the present invention proposes a high-performance timestamp issuance method based on a national secret algorithm, comprising:

[0006] Receive timestamp issuance request and parse request parameters;

[0007] Obtain high-precision time synchronization information through the Network Time Protocol server;

[0008] After combining the request parameters with the time synchronization information, the national secret SM3 algorithm is used to perform digest calculation to generate a digest value;

[0009] The national secret SM2 algorithm is used to sign the summary value using the key of the timestamp issuing agency;

[0010] The timestamp information is integrated and encoded to generate a timestamp in a standard format, which is issued to the requesting party; wherein the timestamp information includes time synchronization information, a summary value, a signature, and information of a timestamp issuing agency.

[0011] As a preferred solution, after obtaining the request parameters, it is verified whether the length of the digest value in the request parameters matches the digest algorithm used, and it is checked whether the key and certificate of the timestamp issuing authority exist.

[0012] As a preferred solution, a data preloading mechanism is also included to preload commonly used timestamp information:

[0013] Initialize a container to preload commonly used timestamp information;

[0014] After the system receives the timestamp request, it obtains the container and updates the corresponding timestamp information into the container according to the request parameters;

[0015] Calculate the digest and signature of the updated timestamp information in the container and save the result in the container;

[0016] Export the data in the container and perform data encoding processing to facilitate subsequent issuance.

[0017] As a preferred solution, it also includes, after completing the timestamp issuance, storing the timestamp in an independent storage module, and continuing to receive subsequent timestamp issuance requests; the storage module is used to store the timestamp in a database.

[0018] The second aspect of the present invention proposes a high-performance timestamp issuance system based on a national secret algorithm, comprising:

[0019] Management module, responsible for the full life cycle management of certificates and keys, including generation, storage, update and destruction;

[0020] A time synchronization module is used to provide time synchronization information consistent with the network time protocol server;

[0021] The timestamp storage module is used to temporarily store the generated timestamps and transfer them to the database;

[0022] The cryptographic operation module is used to perform summary calculation and signature processing according to the national secret algorithm to generate summary and signature data containing accurate timestamps;

[0023] The timestamp issuance module is used to parse the external timestamp issuance request to obtain the request parameters, call the management module, time synchronization module and cryptographic operation module to generate timestamp information, and encode the timestamp in a standard format and issue it to the requester.

[0024] As a preferred solution, the specific working process of the timestamp issuance module includes:

[0025] Parse the external timestamp issuance request and obtain the request parameters;

[0026] Verify the validity of request parameters and check whether the key and certificate exist in the management module;

[0027] Obtain time synchronization information through the time synchronization module;

[0028] Call the cryptographic operation module to perform summary calculation and signature on the time synchronization information and request parameters to generate summary and signature data;

[0029] The summary, signature, time synchronization information and certificate are encapsulated in a data structure, and data encoding is performed before being issued to the requesting party.

[0030] As a preferred solution, the timestamp storage module includes:

[0031] A storage module, comprising a plurality of storage units, wherein the storage units are used to store the timestamps issued by the timestamp issuing module in real time;

[0032] The monitoring module is used to cyclically check whether there are new timestamps in the storage unit, and store the new timestamps safely in the database.

[0033] As a preferred solution, the timestamp issuing module further includes a timestamp container module, and the timestamp container module is preloaded with default data for pre-storing and managing the timestamp information to be generated.

[0034] As a preferred solution, the timestamp issuance module supports parallel processing of multiple timestamp issuance requests.

[0035] As a preferred solution, the cryptographic operation module regularly updates the public and private key pairs of the national secret algorithm.

[0036] Compared with the prior art, the beneficial effects of adopting the above technical scheme are as follows: the present invention uses technical means such as efficient data storage management, data preloading and high concurrency to improve service performance, and integrates secure national secret algorithms to achieve fast and secure generation and verification of timestamps, meeting the dual requirements of high performance and strong security for timestamp services in the fields of e-government, e-commerce, and intellectual property protection. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] Figure 1 This is a flow chart of the high-performance timestamp issuance method based on the national secret algorithm proposed by the present invention.

[0038] Figure 2 Schematic diagram of a high-performance timestamp issuance system based on a national secret algorithm in one embodiment of the present invention.

[0039] Figure 3 Schematic diagram of a timestamp storage module in one embodiment of the present invention. DETAILED DESCRIPTION

[0040] Embodiments of the present application are described in detail below, and examples of the embodiments are shown in the accompanying drawings, wherein the same or similar reference numerals throughout represent the same or similar modules or modules with the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain the present application, and cannot be construed as limitations on the present application. On the contrary, the embodiments of the present application include all changes, modifications and equivalents that fall within the spirit and connotation of the appended claims.

[0041] In order to achieve fast and secure generation and verification of timestamps and meet the high performance and strong security requirements under large-scale concurrent requests, the embodiment of the present invention proposes a high-performance timestamp issuance method based on the national secret algorithm. Please refer to Figure 1 , the specific plan is as follows:

[0042] Step 1: Receive the timestamp issuance request and parse the request parameters.

[0043] After receiving the timestamp issuance request, parse it to obtain the request parameters. In order to ensure the legitimacy and integrity of the data, it is necessary to strictly verify the request parameter data with the issuance, including checking whether the length of the digest value in the request parameter matches the digest algorithm used, and checking whether the key and certificate of the timestamp issuing authority (TSA) exist, so as to prevent the processing of illegal or erroneous data.

[0044] If the verification fails, it is directly encapsulated as an abnormal timestamp response and logged.

[0045] Step 2: Obtain high-precision time synchronization information through the Network Time Protocol server.

[0046] In this embodiment, high-precision time synchronization information is obtained through a network time protocol (NTP) server, which is the key to ensuring the accuracy of the timestamp. Through precise calculation, the current accurate time value can be obtained.

[0047] Step 3: After combining the request parameters with the time synchronization information, use the national encryption SM3 algorithm to perform digest calculation and generate a digest value.

[0048] SM3 is a hash function with high security strength, which can effectively generate a fixed-length summary value for the subsequent signature process. Therefore, in this embodiment, the national secret SM3 algorithm is used for summary calculation.

[0049] Step 4: Use the national secret SM2 algorithm and use the key of the timestamp issuing agency to sign the summary value.

[0050] In this embodiment, the national secret SM2 algorithm is used to sign the summary value generated in the previous step using the private key of the TSA. This step ensures that the timestamp cannot be tampered with and the authenticity of the source.

[0051] Step 5: Integrate and encode the timestamp information to generate a timestamp in a standard format, and issue it to the requester; wherein the timestamp information includes time synchronization information, a summary value, a signature, and information of a timestamp issuing agency.

[0052] In this embodiment, all necessary information (digest value, digital signature, timestamp, TSA certificate information, etc.) is integrated into the container and encoded to generate a timestamp in a standard format. This timestamp will be issued to the requesting party as a valid credential for data authenticity and time proof.

[0053] Among them, a data preloading mechanism is established through the container to preload commonly used timestamp information, which can reduce the delay in subsequent operations and improve the overall response speed. Specifically:

[0054] (1) Initialize a container, which is an efficient data structure used to preload commonly used timestamp information;

[0055] (2) After the system receives the timestamp request, it obtains the container and updates the corresponding timestamp information (including timestamp version, TSA policy, data summary value, timestamp sequence number, issuance time and other key information) to the container according to the request parameters;

[0056] (3) Calculate the digest and signature of the updated timestamp information in the container and save the result in the container;

[0057] (4) Export the data in the container and perform data encoding processing to facilitate subsequent issuance.

[0058] It should be noted that in the timestamp issuance method proposed in the present invention, after the timestamp issuance is completed, the timestamp is stored in an independent storage module, and subsequent timestamp issuance requests continue to be received; the storage module is used to store the timestamp in the database. That is, after the operation of issuing the timestamp is completed, the timestamp data is immediately delivered to the storage module without waiting for the database saving operation to be completed. In this way, the system can continue to process other requests, thereby improving the throughput of the system.

[0059] In order to increase the security of the system, in practical applications, the public and private key pairs of the SM2 algorithm should be replaced regularly, and the unique identifier and timestamp of the request should be recorded to prevent the replay of malicious requests.

[0060] Please refer to Figure 2 The embodiment of the present invention also proposes a high-performance timestamp issuance system based on a national secret algorithm, including:

[0061] Management module, responsible for the full life cycle management of certificates and keys, including generation, storage, update and destruction;

[0062] A time synchronization module is used to provide time synchronization information consistent with the network time protocol server;

[0063] The timestamp storage module is used to temporarily store the generated timestamps and transfer them to the database;

[0064] The cryptographic operation module is used to perform summary calculation and signature processing according to the national secret algorithm to generate summary and signature data containing accurate timestamps. In this embodiment, the cryptographic operation module 3 is implemented using a high-performance cryptographic card that complies with national standards, supports hardware acceleration of SM2 and SM3 algorithms, has efficient encryption, decryption, signing, signature verification and hash computing capabilities, and improves the algorithm operation efficiency.

[0065] The timestamp issuance module is used to parse the external timestamp issuance request to obtain the request parameters, call the management module, time synchronization module and cryptographic operation module to generate timestamp information, and encode the timestamp in a standard format and issue it to the requester.

[0066] In this embodiment, the timestamp issuance module is the core of the entire system. It is responsible for receiving and processing external requests and generating signature data with timestamps as responses. Relying on efficient data storage management, data preloading, and high concurrency technologies, it provides high-performance HTTP services and the encapsulation and parsing functions of various data structures in the timestamp technical specifications. The specific working process of the timestamp issuance module includes:

[0067] (1) Parse the external timestamp issuance request and obtain the request parameters;

[0068] (2) Verify the validity of the request parameters and check whether the key and certificate exist in the management module;

[0069] (3) Obtaining time synchronization information through the time synchronization module;

[0070] (4) Calling the cryptographic operation module to perform digest calculation and signature on the time synchronization information and request parameters to generate digest and signature data;

[0071] (5) Encapsulate the summary, signature, time synchronization information, and certificate into a data structure, perform data encoding, and issue it to the requesting party.

[0072] The timestamp storage module is responsible for storing the generated timestamp information, using an efficient database management system and indexing mechanism to support efficient retrieval and query. Figure 3 The timestamp storage module includes a storage module and a detection module, wherein:

[0073] A storage module, comprising a plurality of storage units, wherein the storage units are used to temporarily store the timestamps issued by the timestamp issuing module so as to quickly respond to the issuance request;

[0074] The monitoring module is used to cyclically check whether there are new timestamps in the storage unit, and store the new timestamps safely in the database.

[0075] When the system receives a timestamp issuance request, the timestamp issuance module will start executing, and the issued timestamp information will be delivered to the storage unit. When the monitoring unit continuously checks the storage unit in a loop, it will find the newly added timestamp data. It will obtain the timestamp data from the storage unit and store it securely in the database.

[0076] It should be noted that, in this embodiment, the timestamp issuance module also includes a timestamp container module for providing a preloading mechanism to preload commonly used timestamp information, reduce unnecessary calculations, thereby reducing response time and optimizing system performance. Specifically, when the system starts, a container is created in the system context, which is specifically used to store timestamp information, and the default data is loaded into the container in advance. When the system issues a timestamp, it obtains this timestamp container from the context, and updates the timestamp version, TSA policy, data summary value, timestamp sequence number, and issuance time and other key information to the container according to the request message. Subsequently, the system will perform summary and signature calculations on the updated timestamp information in the container, and after the calculation is completed, the results will be saved back to the timestamp container. Finally, the system will export the data in the timestamp container and perform data encoding processing for subsequent use.

[0077] In the time stamp issuance system proposed in this embodiment, the time stamp issuance module supports parallel processing of multiple time stamp issuance requests.

[0078] In particular, according to an embodiment of the present application, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present application includes a computer program product, which includes a computer program carried on a computer readable medium, and the computer program includes a program code for executing the method shown in the flowchart.

[0079] It should be noted that the computer-readable medium shown in the embodiment of the present application may be a computer-readable signal medium or a computer-readable storage medium or any combination of the above two. The computer-readable storage medium may be, for example, - but not limited to - an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or device, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM), a flash memory, an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present application, a computer-readable storage medium may be any tangible medium containing or storing a program, which may be used by an instruction execution system, device or device or used in combination with it. In the present application, a computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, wherein a computer-readable program code is carried. Such propagated data signals may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. Computer-readable signal media may also be any computer-readable medium other than computer-readable storage media, which may send, propagate, or transmit programs for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium may be transmitted using any appropriate medium, including but not limited to: wireless, wired, etc., or any suitable combination of the above.

[0080] The flowchart and block diagram in the accompanying drawings illustrate the possible architecture, functions and operations of the system, method and computer program product according to various embodiments of the present application. Wherein, each box in the flowchart or block diagram can represent a module, a program segment, or a part of the code, and the above-mentioned module, program segment, or a part of the code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order from the order marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram or flowchart, and the combination of boxes in the block diagram or flowchart can be implemented with a dedicated hardware-based system that performs a specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.

[0081] The units involved in the embodiments described in this application may be implemented by software or hardware, and the units described may also be set in a processor. The names of these units do not, in some cases, constitute limitations on the units themselves.

[0082] As another aspect, the present application also provides a computer program product or a computer program, which includes a computer instruction stored in a computer-readable storage medium. A processor of a computer device reads the computer instruction from the computer-readable storage medium, and the processor executes the computer instruction, so that the computer device executes the high-performance timestamp issuance method based on the national secret algorithm described in the above embodiment.

[0083] As another aspect, the present application also provides a computer-readable medium, which may be included in the electronic device described in the above embodiment; or may exist independently without being assembled into the electronic device. The above computer-readable medium carries one or more programs, and when the above one or more programs are executed by an electronic device, the electronic device implements the high-performance timestamp issuance method based on the national secret algorithm described in the above embodiment.

[0084] It should be noted that, although several modules or units of the equipment for action execution are mentioned in the above detailed description, this division is not mandatory. In fact, according to the embodiments of the present application, the features and functions of two or more modules or units described above can be embodied in one module or unit. On the contrary, the features and functions of one module or unit described above can be further divided into being embodied by multiple modules or units.

[0085] Through the description of the above implementation methods, it is easy for those skilled in the art to understand that the example implementation methods described here can be implemented by software or by combining software with necessary hardware. Therefore, the technical solution according to the implementation methods of the present application can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, and includes several instructions to enable a computing device (which can be a personal computer, a server, a touch terminal, or a network device, etc.) to execute the method according to the implementation methods of the present application.

[0086] For those skilled in the art, the specific meanings of the above terms in the present invention can be understood in specific situations; the drawings in the embodiments are used to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Generally, the components of the embodiments of the present invention described and shown in the drawings herein can be arranged and designed in various different configurations.

[0087] Although the embodiments of the present application have been shown and described above, it can be understood that the above embodiments are exemplary and cannot be understood as limitations on the present application. Ordinary technicians in this field can change, modify, replace and modify the above embodiments within the scope of the present application.

Claims

1. A high-performance timestamp issuance method based on a national secret algorithm, characterized in that: include: Receive timestamp issuance request and parse request parameters; Obtain high-precision time synchronization information through the Network Time Protocol server; After combining the request parameters with the time synchronization information, the national secret SM3 algorithm is used to perform digest calculation to generate a digest value; The national secret SM2 algorithm is used to sign the summary value using the key of the timestamp issuing agency; The timestamp information is integrated and encoded, and a timestamp in a standard format is encapsulated and issued to the requesting party; wherein the timestamp information includes time synchronization information, a summary value, a signature, and information of a timestamp issuing agency.

2. According to claim 1, the high-performance timestamp issuance method based on the national secret algorithm is characterized in that: After obtaining the request parameters, verify whether the digest value length in the request parameters matches the digest algorithm used, and check whether the key and certificate of the timestamp issuing authority exist.

3. The high-performance timestamp issuance method based on the national secret algorithm according to claim 1 or 2 is characterized in that: It also includes a data preloading mechanism to preload commonly used timestamp information: Initialize a container to preload commonly used timestamp information; After the system receives the timestamp request, it obtains the container and updates the corresponding timestamp information into the container according to the request parameters; Calculate the digest and signature of the updated timestamp information in the container and save the result in the container; Export the data in the container and perform data encoding processing to facilitate subsequent issuance.

4. According to claim 1, the high-performance timestamp issuance method based on the national secret algorithm is characterized in that: It also includes, after completing the timestamp issuance, storing the timestamp in an independent storage module, and continuing to receive subsequent timestamp issuance requests; the storage module is used to store the timestamp in a database.

5. A high-performance timestamp issuance system based on a national secret algorithm, characterized in that: include: Management module, responsible for the full life cycle management of certificates and keys, including generation, storage, update and destruction; A time synchronization module is used to provide time synchronization information consistent with the network time protocol server; The timestamp storage module is used to temporarily store the generated timestamps and transfer them to the database; The cryptographic operation module is used to perform summary calculation and signature processing according to the national secret algorithm to generate summary and signature data containing accurate timestamps; The timestamp issuance module is used to parse the external timestamp issuance request to obtain the request parameters, call the management module, time synchronization module and cryptographic operation module to generate timestamp information, and encode the timestamp in a standard format and issue it to the requester.

6. The high-performance timestamp issuance system based on the national secret algorithm according to claim 5 is characterized in that: The specific working process of the timestamp issuance module includes: Parse the external timestamp issuance request and obtain the request parameters; Verify the validity of request parameters and check whether the key and certificate exist in the management module; Obtain time synchronization information through the time synchronization module; Call the cryptographic operation module to perform summary calculation and signature on the time synchronization information and request parameters to generate summary and signature data; The summary, signature, time synchronization information and certificate are encapsulated in a data structure, and data encoding is performed before being issued to the requesting party.

7. The high-performance timestamp issuance system based on the national secret algorithm according to claim 5 is characterized in that: The timestamp storage module comprises: A storage module, comprising a plurality of storage units, wherein the storage units are used to store the timestamps issued by the timestamp issuing module in real time; The monitoring module is used to cyclically check whether there are new timestamps in the storage unit, and store the new timestamps safely in the database.

8. The high-performance timestamp issuance system based on the national secret algorithm according to claim 5 is characterized in that: The timestamp issuing module also includes a timestamp container module, which is preloaded with default data and is used to pre-store and manage the timestamp information to be generated.

9. The high-performance timestamp issuance system based on the national secret algorithm according to claim 5 is characterized in that: The timestamp issuance module supports parallel processing of multiple timestamp issuance requests.

10. The high-performance timestamp issuance system based on the national secret algorithm according to claim 5 is characterized in that: The cryptographic operation module periodically updates the public and private key pairs of the national cryptographic algorithm.