Space-based cloud big data block chain digital signature method
By adopting a blockchain-based digital signature method on the space-based cloud platform, using elliptic curve signature and recursive binary tree verification, the problems of data security and traceability of the space-based cloud platform are solved, and efficient and secure storage and transmission of data are achieved.
Patent Information
- Application Number
- CN202510093655.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-21
- Publication Date
- 2025-05-30
AI Technical Summary
The space-based cloud platform faces security issues such as illegal external intrusion and internal overridden access tampering, which makes it difficult to guarantee the integrity, security and traceability of data.
The digital signature method based on blockchain is adopted to realize data encryption and verification through elliptic curve signature and recursive binary tree verification to ensure the integrity and identity authentication of the data during transmission.
It effectively reduces the possibility of data stolen from space-based cloud storage, ensures data integrity, security and traceability, and significantly improves the efficiency of signature verification.
Smart Images

Figure CN120074830A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of aerospace cloud computing, relates to the field of big data security, and specifically relates to a space-based cloud big data blockchain digital signature method. Background Art
[0002] As an information fusion and convergence center, the space-based cloud will face many space-based security problems. On the one hand, due to the openness of the space-based cloud space link, external attackers with various purposes illegally invade the network system to steal or damage resources. On the other hand, due to the highly shared resources of the space-based cloud platform, internal users accessing the platform may access and tamper with sensitive information for their own interests beyond their access needs and permissions. How to ensure the integrity, security and traceability of space-based cloud data has become an unsolved problem at present.
[0003] Blockchain uses the principle of asymmetric cryptography to encrypt data, and at the same time relies on the powerful computing power formed by consensus algorithms such as the workload proof of each node in the distributed system to resist external attacks and ensure that blockchain data cannot be tampered with or forged, so it can ensure the integrity of space-based cloud data. The blockchain consensus layer adopts a specific economic incentive mechanism to ensure that all nodes in the distributed system have the motivation to participate in the process of generating and verifying data blocks. A single user cannot tamper with data without obtaining the consensus protocol, so it can ensure the security of space-based cloud data. Blockchain stores data using a chained block structure with timestamps, adding a time dimension to the data, and has extremely strong verifiability and traceability, so it can ensure the traceability of space-based cloud data. In short, blockchain can ensure the integrity, security and traceability of space-based cloud data.
[0004] Digital signature can make data more secure, can effectively protect data access rights, and adding digital signature to blockchain can obtain a higher level of security. Digital signature consists of digital digest and asymmetric encryption technology. First, the information is shortened into a fixed-length string through digital digest technology, and then it is encrypted to form a digital signature. Digital signature can provide identity authentication and non-repudiation of the signed data while ensuring the integrity of the data transmission process.
[0005] The present invention mainly aims at the security problems of the space-based cloud platform (external illegal intrusion or internal unauthorized access and tampering), and proposes a digital signature method based on blockchain, which can reduce the possibility of space-based cloud stored data being stolen, ensure the integrity, security and traceability of space-based cloud data, and solve the security problems of space-based cloud big data cloud storage technology. Summary of the Invention
[0006] To solve the above technical problems, in view of the deficiencies in the prior art, the purpose of the present invention is to provide a space-based cloud big data blockchain digital signature method, which reduces the possibility of space-based cloud storage data being stolen, ensures the integrity, security and traceability of space-based cloud data, and solves the security problems of space-based cloud big data cloud storage technology.
[0007] The following technical solutions are adopted to achieve it:
[0008] A space-based cloud big data blockchain digital signature method includes the following steps:
[0009] S1: Initialize the digital signature system, E(F p ) is an elliptic curve defined over the finite field F p , and a specific summation polynomial about E(F p ) is obtained;
[0010] S2: Reconstruct the batch verification equation, and convert the verification of the elliptic curve signature into verifying whether the sum of points on the elliptic curve E(F p ) is 0;
[0011] S3: Construct a recursive binary tree. If the sum of points on the elliptic curve E(F p ) is 0, convert the result determination of the specific summation polynomial into whether the left and right subtrees of the binary tree contain the same root;
[0012] S4: Calculate the node root, obtain the set of potential results of the variable X in the left and right subtrees, search for the same root, and determine whether there is an intersection in the set of potential results of the variable X in the left and right subtrees. If there is an intersection, the specific summation polynomial is 0, that is, the verification passes; otherwise, the verification fails.
[0013] Optionally, the initialization of the digital signature system specifically includes:
[0014] E(Fp): y 2 = x 3 + ax + b is an elliptic curve defined over the finite field F p ; Given the elliptic curve E(F p ), where p is the order of the finite field F p , P represents the generator on E(F p ), and a random integer d is selected from [0, p - 1] as the private key, then the public key corresponding to d is Q = dP;
[0015] Substitute the generation parameters a and b of E(F p ) into the summation polynomial, and a specific summation polynomial about E(F p ) can be obtained, as shown in the following formula:
[0016] f 3 (x1 , x 2 , x 3 ) = (x 1 -x 2 ) 2 x 3 2 -2((x 1 +x 2 )(x 1 x 2 +a) + 2b)x 3 + ((x 1 x 2 -a) 2 -4b(x 1 +x 2 ))。
[0017] Optionally, the reconstructed batch verification equation specifically includes:
[0018] Input n standard ECDSA signatures, denoted as {M i , r i , s i}, i ∈ [1, n], where M i is the specific message, (r i , s i ) represents the signature result; for any r i among them, it satisfies (r i , y i ) ∈ E(F p );
[0019] (r 1 , y 1 ) + (r 2 , y 2 ) + … + (r n , y n ) + (α, β) = ο;
[0020] Among them, (α, β) is a point on the elliptic curve E(F p );
[0021] If the above equation holds, then the n standard ECDSA signatures are all legal;
[0022] Otherwise, the n standard ECDSA signatures contain at least one invalid signature.
[0023] Optionally, the construction of the recursive binary tree specifically includes:
[0024] Input n standard ECDSA signatures and their corresponding intermediate results R = (α, β). At the top layer of the binary tree, its root node represents r in this batch of signatures 1 , r2 , r 3 ,... r n , and the summation polynomial with \(R = (\alpha, \beta)\) as parameters:
[0025] f n+1 = f n+1 (r 1 , r 2 , r 3 ,…, r n , \(\alpha)\);
[0026] In the next layer of the binary tree, its left and right nodes respectively split half of the parameters of the root node and add the same intermediate variable \(X\) in the resultant calculation process.
[0027] Then the summation polynomial represented by the left node can be expressed as:
[0028]
[0029] The summation polynomial represented by the right node can be expressed as:
[0030]
[0031] The splitting of the larger parameters of the node will continue recursively, and the termination condition is that the node contains only three parameters. Such a node will be used as the leaf node of the binary tree.
[0032] At the top layer of the recursive binary tree, referring to the definition of the summation polynomial, calculate the summation polynomial \(f\) represented by the root node n+1 (r 1 , r 2 , r 3 ,…, \(\alpha)\), which is equivalent to the Sylvester determinant of calculating the summation polynomials represented by its left and right nodes. The same rule applies to other nodes.
[0033] Optionally, the calculation of the node root specifically includes:
[0034]
[0035] Pre-check whether the above formula satisfies the quadratic residue modulo \(p\), and illegal results will be directly discarded;
[0036] After verification, the roots of the above formula can be obtained, represented by \(X\) t1 and \(X\) t2 respectively;
[0037] For its sibling node \(f\) 3 (r 3 , \(X\) t-1 , \(X\) t ), respectively substitute \(X\)t = x t1 and X t = x t2 Substituting into the polynomial, then f 3 (r 3 , X t-1 , X t ) can be regarded as a univariate polynomial about X t-1 . By finding its roots, the set of potential results of X t-1 is:
[0038] {x (t-1)1 , x (t-1)2 , x (t-1)3 , x (t-1)4};
[0039] The set of potential results of the variable X in the left subtree is obtained as:
[0040]
[0041] m is a power of 2 and represents the total number of potential results of the variable X;
[0042] Similarly, in this way, the set of potential results of the variable X in the right subtree can be obtained as:
[0043]
[0044] Optionally, the searching for the same root specifically includes:
[0045] The sets of potential results of the left and right subtrees regarding the variable X are stored in a hash set. It is necessary to determine whether there is an intersection between the two hash sets to calculate f n+1 (r 1 , r 2 , r 3 …, r n , α);
[0046] If there are identical elements in the set, then:
[0047] f n+1 (r 1 , r 2 , r 3 …, r n , α) = 0;
[0048] Conversely, f n+1 (r 1 , r 2 , r 3 …, r n , α) ≠ 0.
[0049] A space-based cloud blockchain platform integrates any one of the space-based cloud big data blockchain digital signature methods of the present invention.
[0050] Compared with the prior art, the present invention has the following technical effects:
[0051] 1) The present invention mainly aims at the security problems of the space-based cloud platform (external illegal intrusion or internal unauthorized access and tampering), and proposes a digital signature method based on blockchain, which can reduce the possibility of the space-based cloud stored data being stolen and ensure the integrity, security and traceability of the space-based cloud data.
[0052] 2) The present invention is integrated on the space-based cloud blockchain platform. The time overhead maintains a relatively stable growth rate in the range where the number of single ECDSA signatures increases from 1 to 13. Compared with the initial ECDSA, there is an advantage of about 100 - 300 ms, and the efficiency advantage is obvious. BRIEF DESCRIPTION OF THE DRAWINGS
[0053] Figure 1 is a flowchart of the space-based cloud big data blockchain digital signature method provided by an embodiment of the present invention.
[0054] The following further elaborates on the specific content of the present invention in conjunction with embodiments. DETAILED DESCRIPTION OF THE INVENTION
[0055] In order to make the objectives, technical solutions and advantages of the present invention clearer, the present invention will be further described in detail below in conjunction with the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the basic concept of the present invention and are not used to limit the present invention. Those skilled in the art can understand other advantages and effects of the present invention from the content described in this specification. The present invention can also be implemented or applied in other different specific embodiments, and various modifications or changes can be made to the details of this specification based on different viewpoints and applications without departing from the spirit of the present invention.
[0056] The present invention provides a space-based cloud big data blockchain digital signature method, which is integrated on the space-based cloud blockchain platform, and the efficiency advantage is obvious. The present invention includes two parts: digital signature and integration on the space-based cloud blockchain platform. First, system initialization; secondly, reconstruct the batch verification equation; then construct a recursive binary tree; then calculate the node root; then search for the same root, and finally integrate on the space-based cloud blockchain platform. The present invention mainly aims at the security problems of the space-based cloud platform (external illegal intrusion or internal unauthorized access and tampering), and proposes a digital signature method based on blockchain, which can reduce the possibility of the space-based cloud stored data being stolen and ensure the integrity, security and traceability of the space-based cloud data.
[0057] Such as Figure 1As shown, the method includes the following steps:
[0058] Step 1, in the present invention, it includes digital signature system initialization, reconstructing batch verification equations, constructing a recursive binary tree, calculating the node root, and searching for the same root;
[0059] Step 2, the blockchain digital signature method involved in the present invention is integrated on the space-based cloud blockchain platform to verify the efficiency.
[0060] (1) Digital signature system initialization: E(F p ) is an elliptic curve defined over the finite field F p , and a specific summation polynomial about E(F p ) is obtained to avoid the complex calculation process of high-degree polynomials;
[0061] E(F p ): y 2 = x 3 + ax + b is an elliptic curve defined over the finite field Fp. Given the elliptic curve E(Fp), where p is the order of the finite field F p , P represents the generator on E(F p ), and an integer d is randomly selected from [0, p - 1] as the private key, then the public key corresponding to d is Q = dP. Substituting the generator parameters a and b of E(F p ) into the summation polynomial, a specific summation polynomial about E(F p ) can be obtained, as shown in the following formula:
[0062] f 3 (x 1 , x 2 , x 3 ) = (x 1 - x 2 ) 2 x 3 2 - 2((x 1 + x 2 )(x 1 x 2 + a) + 2b)x 3 + ((x 1 x 2 - a) 2 - 4b(x 1 + x 2 ));
[0063] (2) Reconstructing batch verification equations: The verification of the elliptic curve signature is transformed into verifying whether the sum of points on the elliptic curve E(F p ) is 0;
[0064] Input n standard ECDSA signatures, denoted as {M i , r i , s i}, where i ∈ [1, n], and M i is a specific message. For any r i among them, it satisfies (r i , y i ) ∈ E(F p ). Refer to the formula of the initial batch verification scheme for elliptic curve signatures:
[0065]
[0066] where t represents the number of different signers. Integrating the ECDSA signature verification operations for this batch gives:
[0067]
[0068] where n is the order of the base point G, Q represents the public key Q = dG, and d ∈ [1, n - 1] is the private key. R = uP + vQ. Assuming the input signature is (r, s), calculate w = s -1 (mod n), u = H(M)w (mod n), v = rw (mod n), and H(M) is the hash value of the message M.
[0069] The right side of the above formula is the intermediate result of verifying the public key and signature s. Therefore, the verification process of the standard ECDSA signature is converted into verifying whether the operation results on the left and right sides of the above formula are equal. If the results are equal, then all n standard ECDSA signatures are legal. Otherwise, at least one of the n standard ECDSA signatures is invalid. The operation result on the right side of the above formula can be represented as R, as shown in the following formula:
[0070]
[0071] According to the basic properties of elliptic curve addition operations, (α, β) ∈ F p and (α, β) is a point on the elliptic curve E(F p ). Therefore, the original batch verification formula can be expressed as follows:
[0072]
[0073] That is, to check whether holds. Substitute R i = (r i , y i ) into the above formula and further simplify to get:
[0074] (r 1 , y 1 ) + (r 2 , y2 ) + … + (r n , y n ) + (α, β) = ο;
[0075] Therefore, if the above equation holds, then n standard ECDSA signatures are all legal. Otherwise, at least one of the n standard ECDSA signatures is invalid. The verification of the elliptic curve signature is transformed into verifying whether the sum of the points in the above equation is 0.
[0076] (3) Construct a recursive binary tree:
[0077] Referring to the basic properties of the elliptic curve summation polynomial, if the above equation holds, then f n+1 (r 1 , r 2 , r 3 , …, α) = 0. To improve the efficiency of ECDSA signature verification and maximize the number of ECDSA signatures supported by batch verification, the root extraction operation modulo p will be strictly restricted to be completed in f 3 . The construction and calculation process of the summation polynomial will be represented by the recursive binary tree of the resultant.
[0078] Input n standard ECDSA signatures and their corresponding intermediate results R = (α, β), as shown in the formula . At the top layer of the binary tree, its root node represents the summation polynomial with r 1 , r 2 , r 3 ,... r n , and R = (α, β) as parameters:
[0079] f n+1 = f n+1 (r 1 , r 2 , r 3 , …, r n , α);
[0080] In the next layer of the binary tree, its left node and right node respectively split half of the parameters of the root node and add the same intermediate variable X in the resultant calculation process.
[0081] Then the left node can be represented as:
[0082]
[0083] The right node can be represented as:
[0084]
[0085] The parameter splitting of large nodes will be continuously recursive, and the termination condition is that the node only contains three parameters. Such a node will be used as the leaf node of the binary tree. It should be noted that although the newly added resultant intermediate variables of sibling nodes in each layer are the same, the newly added resultant intermediate variables between non-sibling nodes in each layer are different. The recursive binary tree is a non-complete binary tree.
[0086] At the top layer of the recursive binary tree, referring to the definition of the summation polynomial, calculate the summation polynomial f n+1 (r 1 ,r 2 ,r 3 ,…,α) represented by the root node, and calculate the summation polynomial represented by its left node:
[0087]
[0088] and the summation polynomial represented by the right node;
[0089]
[0090] is equivalent to the Sylvester determinant. The same rule applies to other nodes. Thus, we can obtain:
[0091]
[0092] (4) Calculate the node root:
[0093] At the bottom leaf nodes of the recursive binary tree, substitute x 1 =r 1 ,x 2 =r 2 into the following formula:
[0094] f 3 (x 1 ,x 2 ,x 3 )=(x 1 -x 2 ) 2 x 3 2 -2((x 1 +x 2 )(x 1 x 2 +a)+2b)x 3 +((x 1 x 2 -a) 2 -4b(x 1 +x 2 ));
[0095] We can obtain
[0096] f3 (r 1 ,r 2 ,X t ) = (r 1 - r 2 ) 2 X t 2 - 2((r 1 + r 2 )r 1 r 2 + 2b)X t + ((r 1 r 2 - a) 2 - 4b(r 1 + r 2 )) = 0 (mod p);
[0097] Substitute the specific parameters a and b of the elliptic curve into the above formula and simplify it to
[0098] AX t 2 + BX t + C = 0 (mod p);
[0099] Through equation transformation, we can get
[0100]
[0101] To avoid invalid operations, we can pre-check whether the above formula satisfies the quadratic residue under modulo p, which is very easy under the Koblitz elliptic curve. Illegal results will be directly discarded. After verification, the roots of the above formula can be obtained, denoted as X t1 and X t2 . For its sibling node f 3 (r 3 ,X t-1 ,X t ), substitute X t = x t1 and X t = x t2 into the polynomial respectively, then f 3 (r 3 ,X t-1 ,X t ) can be regarded as a univariate polynomial about X t-1 . By finding its roots, the set of potential results of X t-1 is:[[]]
[0102] {x (t-1)1 ,x (t-1)2 ,x (t-1)3 ,x (t-1)4};
[0103] In this way, the set of potential results of variable X in the left subtree can be obtained as follows:
[0104]
[0105] m is a power of 2 and represents the total number of potential results of variable X.
[0106] Similarly, in this way, the set of potential results of variable X in the right subtree can be obtained as follows:
[0107]
[0108] (5) Search for the same root:
[0109] The sets of potential results of variable X in the left and right subtrees are stored in a hash set. Just by judging whether there is an intersection between the two hash sets, f can be calculated n+1 (r 1 ,r 2 ,r 3 …,r n ,α). If there are identical elements in the set, then:
[0110] f n+1 (r 1 ,r 2 ,r 3 …,r n ,α) = 0;
[0111] Conversely,
[0112] f n+1 (r 1 ,r 2 ,r 3 …,r n ,α) ≠ 0;
[0113] (6) Space-based cloud blockchain integration
[0114] The blockchain digital signature method involved in the present invention is integrated on the space-based cloud blockchain platform. The time overhead maintains a relatively stable growth rate in the range where the number of single ECDSA signatures increases from 1 to 13. Compared with the initial ECDSA, there is an advantage of about 100 ms - 300 ms, and the efficiency advantage is relatively obvious.
[0115] Application example:
[0116] The blockchain digital signature method involved in the present invention is integrated on the space-based cloud blockchain platform. It is implemented in JAVA language, and the integrated development environment (IDE) is the IDEA Ultimate 2020.2 version. The relevant cryptographic operations on the elliptic curve will be implemented through Bouncy Castle 1.5.0, the JAVA security package included in JDK1.8, and the JPBC library (JAVA Paring-based cryptography library). The elliptic curve adopts secp256k1 used in ECDSA signature in Bitcoin: y 2 = x 3 + 7.
[0117] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent replacements, and improvements made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.
Claims
1. A digital signature method for space-based cloud big data blockchain, characterized in that: The steps include: S1: Digital signature system initialization, E(F p ) is defined in the finite field F p On the elliptic curve, we get p )’s specific summation polynomial; S2: Reconstruct the batch verification equation, and the verification of the elliptic curve signature is transformed into verifying the elliptic curve E(F p ) is 0; S3: Construct a recursive binary tree. If the elliptic curve E(F p ) is 0, and the result of the specific summation polynomial is converted into a binary tree to determine whether the left and right subtrees contain the same root; S4: Calculate the node root, obtain the potential result set of variable X in the left and right subtrees, search for the same root, and determine whether the potential result sets of variable X in the left and right subtrees have an intersection. If there is an intersection, the specific summation polynomial is 0, that is, the verification passes; otherwise, the verification fails.
2. The digital signature method of the Tianji Cloud Big Data Blockchain according to claim 1 is characterized in that: The digital signature system initialization specifically includes: E(Fp):y 2 =x 3 +ax+b is defined in the finite field F p Elliptic curve on; given elliptic curve E(F p ), where p is a finite field F p The order of P represents E(F p ) and randomly select an integer d from [0, p-1] as the private key, then the public key corresponding to d is Q = dP; E(F p ) into the summation polynomial, we can get p ), as shown below: <h2 style=";text-align:left;direction:ltr">f3(x1,x2,x3)=(x1-x2)<h2 style=";text-align:left;direction:ltr"> 2 <h2 style=";text-align:left;direction:ltr"> x3<h2 style=";text-align:left;direction:ltr"> 2 <h2 style=";text-align:left;direction:ltr"> -2((x1+x2)(x1x2+a)+2b)x3+((x1x2-a)<h2 style=";text-align:left;direction:ltr"> 2 <h2 style=";text-align:left;direction:ltr"> -4b(x1+x2))。 3. The digital signature method of the Tianji Cloud Big Data Blockchain according to claim 1 or 2 is characterized in that: The reconstructed batch verification equation specifically includes: Input n standard ECDSA signatures, represented as {M i , r i ,s i }, i∈[1,n], where M i For specific messages, (r i ,s i ) represents the signature result; for any r i , satisfying (r i ,y i )∈E(F p ); (r1,y1)+(r2,y2)+…+(r n ,y n )+(a,b)=o; Among them, (α, β) is the elliptic curve E(F p ) on the point; If the above formula holds, then all n standard ECDSA signatures are legal; Otherwise, the n standard ECDSA signatures contain at least one invalid signature.
4. The digital signature method for the Tianji Cloud Big Data Blockchain according to claim 1 or 2 is characterized in that: The construction of the recursive binary tree specifically includes: Input n standard ECDSA signatures and their corresponding intermediate results R = (α, β). In the top layer of the binary tree, the root node represents r1, r2, r3, ...r in this batch of signatures. n , and R = (α, β) is the summation polynomial of the parameters: f n+1 =f n+1 (r1,r2,r3,…,r n ,α); In the next layer of the binary tree, its left node and right node respectively split half of the parameter of the root node and add the same intermediate variable X in the result calculation process; Then the summation polynomial represented by the left node can be expressed as: The summation polynomial represented by the right node can be expressed as: The parameter splitting of large nodes will be performed recursively. The termination condition is that the node contains only three parameters. Such nodes will be used as leaf nodes of the binary tree. In the top level of the recursive binary tree, refer to the definition of the sum polynomial and calculate the sum polynomial f represented by the root node n+1 (r1, r2, r3, …, α), which is equivalent to calculating the Sylvester determinant of the sum polynomial represented by its left node and the sum polynomial represented by its right node. The same rule applies to other nodes.
5. The method for digital signature of the Tianji Cloud Big Data Blockchain according to claim 1 or 2, characterized in that: The computing node root specifically includes: Check in advance whether the above formula satisfies the quadratic residue under modulo p. Illegal results will be discarded directly. After verification, we can get the roots of the above formula, respectively using X t1 and X t2 express; For its sibling node f3(r3,X t-1 ,X t ), respectively X t =x t1 and X t =x t2 Substitute the polynomial into the equation, then f3(r3,X t-1 ,X t ) can be seen as about X t-1 A univariate polynomial, whose root can be obtained as X t-1 The potential result set is: {x (t-1)1 ,x (t-1)2 ,x (t-1)3 ,x (t-1)4 }; The potential result set of variable X in the left subtree is obtained as: m is a power of 2 and represents the total number of potential outcomes of variable X; Similarly, in this way, the potential result set of variable X in the right subtree can be obtained as follows:
6. The method for digital signature of the Tianji Cloud Big Data Blockchain according to claim 1 or 2, characterized in that: The searching for the same root specifically includes: The potential result sets of the left and right subtrees about the variable X are stored in hash sets. It is necessary to determine whether the two hash sets have an intersection to calculate f. n+1 (r1,r2,r3…,r n ,α); If there are identical elements in the set, then: f n+1 (r1,r2,r3…,r n ,α)=0; On the contrary, f n+1 (r1,r2,r3…,r n ,α)≠0.
7. A space-based cloud blockchain platform, characterized in that: The Tianjiyun blockchain platform integrates the Tianjiyun big data blockchain digital signature method described in any one of claims 1-6.