Cooperative signature method and related device
Through the collaborative signature method, the mobile terminal and the collaborative terminal each retain their private keys, and through elliptic curve point calculation and signature information verification, the problem of single point leakage of private keys in traditional digital signature solutions is solved, improving information security.
Patent Information
- Application Number
- CN202510235701.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-28
- Publication Date
- 2025-06-06
AI Technical Summary
In traditional digital signature schemes, the private key is completely held by a single entity, and there is a risk of single point of leakage, resulting in information security risks.
Through the collaborative signature method, the mobile terminal and the collaborative terminal each retain their own private keys, and through elliptic curve point calculation and signature information verification, the target signature is completed in a coordinated manner.
Improve the protection capability of private keys, prevent information security risks caused by single point of leakage, and ensure the security and integrity of target signatures.
Smart Images

Figure CN120110679A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of digital signatures, and in particular to a collaborative signature method and related devices. Background Art
[0002] A digital signature is an electronic signature used to verify the authenticity and integrity of digital information. Digital signature is one of the important basic primitives of cryptography, which can provide functions similar to handwritten signatures in digital form, such as identity authentication, non-repudiation, and anti-tampering. It has important applications in scenarios such as e-commerce, e-government, and blockchain services. There are many technical routes for the design of digital signature schemes, such as constructing signature schemes based on difficult number theory problems such as prime factor decomposition and solving discrete logarithms. In traditional digital signature schemes, the private key is completely held and used by a single entity. Once the confidentiality measures of the private key holder are not strict, there is a risk of single-point leakage of information. Summary of the invention
[0003] The embodiments of the present application provide a collaborative signature method and related devices, which can improve the protection capability of private keys and prevent information security risks caused by single point leakage.
[0004] A first aspect of an embodiment of the present application provides a collaborative signature method, which is applied to a collaborative end. The method includes:
[0005] Receiving an intermediate elliptic curve point sent by a mobile terminal, where the intermediate elliptic curve point is calculated by the mobile terminal according to a first random number and an elliptic curve base point;
[0006] Calculate a final elliptic curve point according to the intermediate elliptic curve point, the second random number, the sub-private key of the collaboration end, and the elliptic curve base point;
[0007] Calculate the final target signature validity verification message and the intermediate target signature integrity verification message according to the final elliptic curve point;
[0008] The final target signature validity verification message and the intermediate target signature integrity verification message are sent to the mobile terminal, so that the mobile terminal determines the target signature based on the final target signature validity verification message and the intermediate target signature integrity verification message, and the target signature includes the final target signature validity verification message and the final target signature integrity verification message.
[0009] Optionally, the calculating a final elliptic curve point according to the intermediate elliptic curve point, the second random number, the sub-private key of the collaboration end, and the elliptic curve base point includes:
[0010] The final elliptic curve point is calculated according to the first formula, wherein the first formula is: Q = (d 2 +k2 )[*]G+d 2 -1 [*]Q 1 , Q is the final elliptic curve point, Q 1 is the middle elliptic curve point, k 2 is the second random number, d 2 is the sub-private key of the collaboration end, and G is the elliptic curve base point.
[0011] Optionally, the calculating, according to the final elliptic curve point, a final target signature validity verification message and an intermediate target signature integrity verification message includes:
[0012] Calculate the final target signature validity verification message according to the horizontal coordinate of the final elliptic curve point and the hash value of the message to be verified, the hash value of the message to be verified is sent by the mobile terminal to the collaboration terminal, and the message to be verified is obtained by the mobile terminal concatenating the message to be signed with the identity identifiers of the mobile terminal and the collaboration terminal;
[0013] An intermediate target signature integrity verification message is calculated based on the sub-private key of the collaboration end and the final target signature validity verification message.
[0014] Optionally, the calculating the final target signature validity verification message according to the abscissa of the final elliptic curve point and the hash value of the message to be verified includes:
[0015] The final target signature validity verification message is calculated according to the second formula, where the second formula is: r = (x 1 +e)mod q, r is the final target signature validity verification message, x 1 is the horizontal coordinate of the final elliptic curve point, e is the hash value of the message to be verified, and q is the number of elements in the finite field of the elliptic curve.
[0016] Optionally, the calculating of the intermediate target signature integrity verification message according to the sub-private key of the collaboration end and the final target signature validity verification message includes:
[0017] The intermediate target signature integrity verification message is calculated according to the third formula, and the third formula is: 1 =d 2 (r+d 2 +k 2 )mod q,s 1 Signature integrity verification message for intermediate targets.
[0018] Optionally, the method further includes:
[0019] Receiving a first part of a public key sent by the mobile terminal, where the first part of the public key is calculated by the mobile terminal according to the sub-private key of the mobile terminal;
[0020] Randomly generate a sub-private key of the collaboration end;
[0021] Calculating a public key according to the first part of the public key and the sub-private key of the collaboration end, and calculating a second part of the public key according to the sub-private key of the collaboration end;
[0022] The second part of the public key is sent to the mobile terminal, so that the mobile terminal calculates the public key according to the second part of the public key and the sub-private key of the mobile terminal.
[0023] Optionally, before receiving the intermediate elliptic curve point sent by the mobile terminal, the method further includes:
[0024] receiving a login password sent by the mobile terminal, where the login password is set when the mobile terminal registers with the collaboration terminal;
[0025] Query the user database to check whether the login password is correct;
[0026] If the login password is correct, a comparison success message is sent to the mobile terminal.
[0027] A second aspect of an embodiment of the present application provides a collaborative signature method, which is applied to a mobile terminal, and the method includes:
[0028] generating a first random number;
[0029] Calculate an intermediate elliptic curve point according to the first random number and the elliptic curve base point;
[0030] Sending the intermediate elliptic curve point to the cooperating end;
[0031] Receiving a final target signature validity verification message and an intermediate target signature integrity verification message sent by the mobile terminal, wherein the final target signature validity verification message and the intermediate target signature integrity verification message are calculated by the mobile terminal according to the intermediate elliptic curve point;
[0032] Calculate a final target signature integrity verification message according to the private key of the mobile terminal, the first random number, the final target signature validity verification message and the intermediate target signature integrity verification message;
[0033] The final target signature validity verification message and the final target signature integrity verification message are used as the target signature.
[0034] Optionally, the calculating the final target signature integrity verification message according to the private key of the mobile terminal, the first random number, the final target signature validity verification message, and the intermediate target signature integrity verification message includes:
[0035] The final target signature integrity verification message is calculated according to the fourth formula: s = (d 1 (s 1 +k 1 )-r)mod q, s is the final target signature integrity verification message, d 1 is the private key of the mobile terminal, k 1 is the first random number, r is the final target signature validity verification message, s 1 The target signature integrity verification message is intermediate, and q is the number of elements in the finite field of the elliptic curve.
[0036] Optionally, before generating the first random number, the method further includes:
[0037] The message to be signed is concatenated with the identity identifiers of the mobile terminal and the cooperation terminal to obtain a message to be verified;
[0038] Calculate the hash value of the message to be verified;
[0039] The hash value of the message to be verified and the login password set when the mobile terminal is registered with the collaboration terminal are sent to the collaboration terminal, so that the collaboration terminal queries the user database to compare whether the login password is correct.
[0040] Optionally, the method further includes:
[0041] Randomly generate a sub-private key of the mobile terminal;
[0042] Calculate the first part of the public key according to the sub-private key of the mobile terminal;
[0043] Sending the first part of the public key to the collaboration end, so that the collaboration end calculates a public key according to the first part of the public key and the sub-private key of the mobile end, and calculates a second part of the public key according to the sub-private key of the mobile end;
[0044] Receiving the second part of the public key sent by the collaboration end;
[0045] The public key is calculated based on the second part of the public key and the sub-private key of the mobile terminal.
[0046] A third aspect of the present application provides a collaborative signature device, which is applied to a collaborative end. The device includes:
[0047] A communication unit, configured to receive an intermediate elliptic curve point sent by a mobile terminal, wherein the intermediate elliptic curve point is calculated by the mobile terminal according to a first random number and an elliptic curve base point;
[0048] an elliptic curve point calculation unit, configured to calculate a final elliptic curve point according to the intermediate elliptic curve point, a second random number, a sub-private key of the collaboration end, and the elliptic curve base point;
[0049] A signature information calculation unit, used to calculate a final target signature validity verification message and an intermediate target signature integrity verification message according to the final elliptic curve point;
[0050] The communication unit is also used to send the final target signature validity verification message and the intermediate target signature integrity verification message to the mobile terminal, so that the mobile terminal determines the target signature based on the final target signature validity verification message and the intermediate target signature integrity verification message, and the target signature includes the final target signature validity verification message and the final target signature integrity verification message.
[0051] A fourth aspect of the present application provides a collaborative signature device, which is applied to a mobile terminal, and the device includes:
[0052] A random number generating unit, used to generate a first random number;
[0053] an elliptic curve point calculation unit, configured to calculate an intermediate elliptic curve point according to the first random number and an elliptic curve base point;
[0054] A communication unit, configured to send the intermediate elliptic curve point to the collaboration end;
[0055] The communication unit is further used to receive a final target signature validity verification message and an intermediate target signature integrity verification message sent by the mobile terminal, wherein the final target signature validity verification message and the intermediate target signature integrity verification message are calculated by the mobile terminal according to the intermediate elliptic curve point;
[0056] A signature information calculation unit, used to calculate a final target signature integrity verification message according to the private key of the mobile terminal, the first random number, the final target signature validity verification message and the intermediate target signature integrity verification message;
[0057] The signature determination unit is used to use the final target signature validity verification message and the final target signature integrity verification message as the target signature.
[0058] A fifth aspect of the embodiments of the present application provides an electronic device, including: a processor and a memory;
[0059] The processor is connected to the memory, wherein the memory is used to store a computer program, and the processor is used to call the computer program to execute the method in the first aspect or the second aspect of the embodiment of the present application.
[0060] A sixth aspect of an embodiment of the present application provides a computer-readable storage medium, which stores a computer program. The computer program includes program instructions. When the program instructions are executed by a processor, the method in the first aspect or the second aspect of the embodiment of the present application is executed.
[0061] In an embodiment of the present application, the mobile terminal calculates an intermediate elliptic curve point based on the first random number and the elliptic curve base point and sends it to the collaborative terminal; the collaborative terminal calculates a final elliptic curve point based on the intermediate elliptic curve point, the second random number, the sub-private key of the collaborative terminal, and the elliptic curve base point; the final target signature validity verification message and the intermediate target signature integrity verification message are calculated based on the final elliptic curve point and sent to the mobile terminal; the mobile terminal calculates the final target signature integrity verification message based on the private key of the mobile terminal, the first random number, the final target signature validity verification message, and the intermediate target signature integrity verification message, and uses the final target signature validity verification message and the final target signature integrity verification message as the target signature.
[0062] It can be seen that in the embodiment of the present application, the mobile terminal and the collaborative terminal each retain their own private key, and then collaborate to complete the target signature based on their own private keys. Since the mobile terminal and the collaborative terminal each hold a part of the private key, the theft of the private key of either end will not cause the overall target signature to be lost, thereby improving the ability to protect the private key and preventing information security risks caused by single point leakage. BRIEF DESCRIPTION OF THE DRAWINGS
[0063] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0064] Figure 1 An example system block diagram of collaborative signature provided by an embodiment of the present application is shown;
[0065] Figure 2 A schematic diagram of a collaborative signature method provided by an embodiment of the present application is shown;
[0066] Figure 3 A schematic diagram of a communication security verification method provided by an embodiment of the present application is shown;
[0067] Figure 4 A schematic diagram of a key splitting method provided by an embodiment of the present application is shown;
[0068] Figure 5 A schematic diagram of the structure of a collaborative signature device provided by an embodiment of the present application is shown;
[0069] Figure 6 A schematic diagram of the structure of a collaborative signature device provided by another embodiment of the present application is shown;
[0070] Figure 7 A schematic diagram of the structure of a computer device provided by an embodiment of the present application is shown. DETAILED DESCRIPTION
[0071] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. According to the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.
[0072] Please refer to Figure 1 , which shows an example system block diagram of a collaborative signature provided by an embodiment of the present application. The operating environment may include: a mobile terminal 10 and a collaborative terminal 20.
[0073] The mobile terminal 10 includes but is not limited to electronic devices such as mobile phones, computers, intelligent voice interaction devices, smart home appliances, vehicle-mounted terminals, game consoles, e-book readers, multimedia playback devices, wearable devices, etc. The client of the application program can be installed in the mobile terminal 10. The collaboration terminal 20 can be, for example, a server that provides digital signature collaboration services.
[0074] The mobile terminal 10 and the collaboration terminal 20 devices may communicate using any suitable network protocol 30, including network protocols that have not yet been developed on the date of filing this application. The network protocols may include, for example, TCP / IP protocol, UDP / IP protocol, HTTP protocol, HTTPS protocol, etc. Of course, the network protocols may also include, for example, RPC protocol (Remote Procedure Call Protocol) and REST protocol (Representational State Transfer) used on top of the above protocols.
[0075] It is understandable that each data item or each type of combined data item in the present application is essentially data obtained by combining and calculating different types of parameters, which is different from the source data directly sent or received. The application of this type of data in the data interaction process can effectively prevent the data from being intercepted during the transmission process and then obtaining or deducing the source data. In addition, in one or more embodiments of the present application, each type of data expressed by a parameter expression is actually the result data calculated by applying the parameter expression. What is transmitted during the interaction process is also the numerical data corresponding to the numerical value, not the expression itself.
[0076] Please refer to Figure 2 , which shows a schematic diagram of the process of a collaborative signature method provided by an embodiment of the present application. The method can be applied to a computer device, which refers to an electronic device with data calculation and processing capabilities. For example, the execution subject of each step can be Figure 1 The mobile terminal 10 and the cooperation terminal 20 devices are shown. The method may include the following steps:
[0077] Step 201: The mobile terminal 10 generates a first random number.
[0078] Step 202: The mobile terminal 10 calculates an intermediate elliptic curve point according to the first random number and the elliptic curve base point.
[0079] Specifically, the calculating the intermediate elliptic curve point according to the first random number and the elliptic curve base point includes:
[0080] The intermediate elliptic curve point is calculated according to the fifth formula, which is: 1 =k 1 [*]G, where Q 1 is the middle elliptic curve point, k 1 is the first random number, and G is the elliptic curve base point.
[0081] Among them, the elliptic curve base point is a point on the elliptic curve and is the basis for building the elliptic curve cryptosystem.
[0082] Step 203: The mobile terminal 10 sends the intermediate elliptic curve point to the cooperation terminal.
[0083] Step 204: The collaboration end 20 calculates a final elliptic curve point according to the intermediate elliptic curve point, the second random number, the sub-private key of the collaboration end, and the elliptic curve base point.
[0084] Among them, the first random number k 1 and the second random number k 2 It can be a pseudo-random number or a true random number. Pseudo-random numbers are generated by deterministic algorithms; true random numbers are obtained through physical processes, such as quantum mechanical phenomena or environmental noise.
[0085] Specifically, the calculating the final elliptic curve point according to the intermediate elliptic curve point, the second random number, the sub-private key of the collaboration end, and the elliptic curve base point includes:
[0086] generating a second random number;
[0087] The final elliptic curve point is calculated according to the first formula, wherein the first formula is: Q = (d 2 +k 2 )[*]G+d 2 -1 [*]Q 1 , Q is the final elliptic curve point, k 2 is the second random number, d 2 It is the sub-private key of the collaboration end.
[0088] Step 205: The collaboration end 20 calculates the final target signature validity verification message and the intermediate target signature integrity verification message according to the final elliptic curve point.
[0089] Among them, the signature usually consists of two parts, one part is used to verify the validity of the signature, usually represented by r, and the other part is used to verify the integrity of the signature, usually represented by s. The final part is what needs to be determined in the end, and is used as the target signature r and s; the intermediate part is of a transitional nature, just to determine the final intermediate value.
[0090] Specifically, the calculating the final target signature validity verification message and the intermediate target signature integrity verification message according to the final elliptic curve point includes:
[0091] Calculate the final target signature validity verification message according to the horizontal coordinate of the final elliptic curve point and the hash value of the message to be verified, the hash value of the message to be verified is sent by the mobile terminal to the collaboration terminal, and the message to be verified is obtained by the mobile terminal concatenating the message to be signed with the identity identifiers of the mobile terminal and the collaboration terminal;
[0092] An intermediate target signature integrity verification message is calculated based on the sub-private key of the collaboration end and the final target signature validity verification message.
[0093] Exemplarily, the calculating the final target signature validity verification message according to the abscissa of the final elliptic curve point and the hash value of the message to be verified includes:
[0094] The final target signature validity verification message is calculated according to the second formula, where the second formula is: r = (x 1 +e)mod q, r is the final target signature validity verification message, x 1is the horizontal coordinate of the final elliptic curve point, e is the hash value of the message to be verified, and q is the number of elements in the finite field of the elliptic curve.
[0095] Exemplarily, the calculating of the intermediate target signature integrity verification message according to the sub-private key of the collaboration end and the final target signature validity verification message includes:
[0096] The intermediate target signature integrity verification message is calculated according to the third formula, and the third formula is: 1 =d 2 (r+d 2 +k 2 )mod q,s 1 Signature integrity verification message for intermediate targets.
[0097] Step 206: The collaboration terminal 20 sends the final target signature validity verification message and the intermediate target signature integrity verification message to the mobile terminal.
[0098] Step 207: The mobile terminal 10 calculates the final target signature integrity verification message according to the private key of the mobile terminal, the first random number, the final target signature validity verification message and the intermediate target signature integrity verification message.
[0099] Specifically, the calculating the final target signature integrity verification message according to the private key of the mobile terminal, the first random number, the final target signature validity verification message and the intermediate target signature integrity verification message includes:
[0100] The final target signature integrity verification message is calculated according to the fourth formula: s = (d 1 (s 1 +k 1 )-r)mod q, s is the final target signature integrity verification message.
[0101] Step 208: The mobile terminal 10 uses the final target signature validity verification message and the final target signature integrity verification message as the target signature.
[0102] In an embodiment of the present application, the mobile terminal calculates an intermediate elliptic curve point based on the first random number and the elliptic curve base point and sends it to the collaborative terminal; the collaborative terminal calculates a final elliptic curve point based on the intermediate elliptic curve point, the second random number, the sub-private key of the collaborative terminal, and the elliptic curve base point; the final target signature validity verification message and the intermediate target signature integrity verification message are calculated based on the final elliptic curve point and sent to the mobile terminal; the mobile terminal calculates the final target signature integrity verification message based on the private key of the mobile terminal, the first random number, the final target signature validity verification message, and the intermediate target signature integrity verification message, and uses the final target signature validity verification message and the final target signature integrity verification message as the target signature.
[0103] It can be seen that in the embodiment of the present application, the mobile terminal and the collaborative terminal each retain their own private key, and then collaborate to complete the target signature based on their own private keys. Since the mobile terminal and the collaborative terminal each hold a part of the private key, the theft of the private key of either end will not cause the overall target signature to be lost, thereby improving the ability to protect the private key and preventing information security risks caused by single point leakage.
[0104] Furthermore, before the mobile terminal 10 sends the intermediate elliptic curve point to the cooperative terminal, information verification may be performed to ensure the security of communication. Figure 3 , which shows a flow chart of a communication security verification method provided by an embodiment of the present application. The method can be applied to a computer device, which refers to an electronic device with data calculation and processing capabilities. For example, the execution subject of each step can be Figure 1 The mobile terminal 10 and the cooperation terminal 20 devices are shown. The method may include the following steps:
[0105] Step 301: The mobile terminal 10 concatenates the message to be signed with the identity identifiers of the mobile terminal and the cooperation terminal to obtain a message to be verified.
[0106] Step 302: The mobile terminal 10 calculates the hash value of the message to be verified.
[0107] Step 303: The mobile terminal 10 sends the hash value of the message to be verified and the login password set when the mobile terminal registers with the collaboration terminal to the collaboration terminal.
[0108] Step 304: The collaboration terminal 20 queries the user database to check whether the login password is correct.
[0109] Step 305: If the login password is correct, the collaboration terminal 20 sends a comparison success message to the mobile terminal.
[0110] It should be noted that the mobile terminal 10 may send the hash value of the message to be verified and the login password set when the mobile terminal registers with the collaboration terminal as two messages separately to the collaboration terminal, or may concatenate the hash value of the message to be verified and the login password set when the mobile terminal registers with the collaboration terminal into one message and send it to the collaboration terminal, which is not limited here.
[0111] It can be seen that in the embodiment of the present application, the mobile terminal and the collaborative terminal first compare the login password before performing the collaborative signature, which can improve the security of the collaborative signature; at the same time, the hash value of the message to be verified and the login password are sent simultaneously on the mobile terminal, and the hash value of the message to be verified can be directly used for subsequent collaborative signatures, reducing the number of information interactions, thereby improving the speed of collaborative signatures.
[0112] For further information, please refer to Figure 4 , which shows a schematic diagram of the process of a key splitting method provided by an embodiment of the present application. The method can be applied to a computer device, which refers to an electronic device with data calculation and processing capabilities. For example, the execution subject of each step can be Figure 1 The mobile terminal 10 and the cooperation terminal 20 devices are shown. The method may include the following steps:
[0113] Step 401: The mobile terminal 10 randomly generates a sub-private key of the mobile terminal.
[0114] Step 402: The mobile terminal 10 calculates the first part of the public key according to the mobile terminal's sub-private key.
[0115] Step 403: The mobile terminal 10 sends the first part of the public key to the collaboration terminal.
[0116] Step 404: The collaboration end 20 randomly generates a sub-private key of the collaboration end.
[0117] Step 405: The collaboration end 20 calculates a public key according to the first part of the public key and the sub-private key of the collaboration end, and calculates a second part of the public key according to the sub-private key of the collaboration end.
[0118] Step 406: The collaboration terminal 20 sends the second part of the public key to the mobile terminal.
[0119] Step 407: The mobile terminal 10 calculates the public key according to the second part of the public key and the mobile terminal's sub-private key.
[0120] Specifically, the calculating the first part of the public key according to the sub-private key of the mobile terminal includes:
[0121] The intermediate elliptic curve point is calculated according to the sixth formula, which is: 1 =d1 -1 [*]G, P 1 The first part of the public key.
[0122] Similarly, the step of calculating the second part of the public key according to the sub-private key of the collaboration end includes:
[0123] The second part of the public key is calculated according to the seventh formula, and the seventh formula is: 2 =d 2 -1 [*]G, P 2 The second part of the public key.
[0124] Specifically, the calculating the public key according to the first part of the public key and the pre-child private key of the collaboration end includes:
[0125] The public key is calculated according to the eighth formula, which is: P = d 2 -1 [*]P 1 -G.
[0126] Similarly, calculating the public key according to the second part of the public key and the sub-private key of the mobile terminal includes:
[0127] The public key is calculated according to the ninth formula, and the ninth formula is: P = d 1 -1 [*]P 2 -G.
[0128] It can be seen that in the embodiment of the present application, the mobile terminal and the collaborative terminal each randomly generate their own sub-private key, and then calculate their respective partial public keys based on the sub-private key, and send the partial public key to the other party. The other party can then calculate the same public key based on the other party's partial public key and its own sub-private key, thereby realizing the splitting of the key and improving the security protection of the key.
[0129] Figure 5 The schematic diagram of the structure of a collaborative signature device provided by an embodiment of the present application is shown. The device is applied to a collaborative end and includes:
[0130] The communication unit 501 is configured to receive an intermediate elliptic curve point sent by a mobile terminal, where the intermediate elliptic curve point is calculated by the mobile terminal according to a first random number and an elliptic curve base point;
[0131] An elliptic curve point calculation unit 502, configured to calculate a final elliptic curve point according to the intermediate elliptic curve point, a second random number, a sub-private key of the collaboration end, and the elliptic curve base point;
[0132] A signature information calculation unit 503, configured to calculate a final target signature validity verification message and an intermediate target signature integrity verification message according to the final elliptic curve point;
[0133] The communication unit 501 is also used to send the final target signature validity verification message and the intermediate target signature integrity verification message to the mobile terminal, so that the mobile terminal determines the target signature based on the final target signature validity verification message and the intermediate target signature integrity verification message, and the target signature includes the final target signature validity verification message and the final target signature integrity verification message.
[0134] Figure 6 A schematic diagram of the structure of a collaborative signature device provided by another embodiment of the present application is shown. The device is applied to a mobile terminal and includes:
[0135] A random number generating unit 601, configured to generate a first random number;
[0136] An elliptic curve point calculation unit 602, configured to calculate an intermediate elliptic curve point according to the first random number and an elliptic curve base point;
[0137] A communication unit 603, configured to send the intermediate elliptic curve point to the collaboration end;
[0138] The communication unit 603 is further configured to receive a final target signature validity verification message and an intermediate target signature integrity verification message sent by the mobile terminal, wherein the final target signature validity verification message and the intermediate target signature integrity verification message are calculated by the mobile terminal according to the intermediate elliptic curve point;
[0139] The signature information calculation unit 604 is used to calculate the final target signature integrity verification message according to the private key of the mobile terminal, the first random number, the final target signature validity verification message and the intermediate target signature integrity verification message;
[0140] The signature determination unit 605 is configured to use the final target signature validity verification message and the final target signature integrity verification message as the target signature.
[0141] Figure 7 A schematic diagram of the structure of a computer device provided by an embodiment of the present application is shown, including a memory and a processor, the memory stores a computer program, and the processor implements the functions of a computer system of the collaborative signature method in any of the above-mentioned implementation modes when executing the computer program.
[0142] The embodiments of the present application also provide a computer-readable storage medium on which a computer program is stored. When the computer program is executed by a computer, the computer executes the functions of the computer system of the collaborative signature method in any of the above embodiments.
[0143] The embodiments of the present application also provide a computer program product comprising instructions, which, when executed by a computer, enables the computer to perform the functions of the computer system of the collaborative signature method in any of the above embodiments.
[0144] It should be understood that the specific examples in this application are only intended to help those skilled in the art to better understand the implementation methods of this application, rather than to limit the scope of the present invention.
[0145] It can be understood that in the various implementations of the present application, the size of the serial number of each process does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the implementation methods of the present application.
[0146] It can be understood that the various embodiments described in this application can be implemented individually or in combination, and the embodiments of this application are not limited to this.
[0147] Unless otherwise stated, all technical and scientific terms used in the embodiments of the present application have the same meaning as those generally understood by those skilled in the art of the technical field of the present application. The terms used in the present application are only for the purpose of describing specific embodiments and are not intended to limit the scope of the present application. The term "and / or" used in the present application includes any and all combinations of one or more related listed items. The singular forms of "a kind of", "above" and "the" used in the embodiments of the present application and the appended claims are also intended to include plural forms, unless the context clearly indicates other meanings.
[0148] It can be understood that the processor of the embodiment of the present application can be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method implementation can be completed by the hardware integrated logic circuit or software instructions in the processor. The above processor can be a general processor, a digital signal processor (DigitalSignal Processor, DSP), an application-specific integrated circuit (Application Specific Integrated Circuit, ASIC), a field programmable gate array (Field Programmable Gate Array, FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components. The methods, steps and logic block diagrams disclosed in the embodiment of the present application can be implemented or executed. The general processor can be a microprocessor or the processor can also be any conventional processor, etc. The steps of the method disclosed in the embodiment of the present application can be directly embodied as a hardware decoding processor to perform, or the hardware and software modules in the decoding processor are combined and executed. The software module can be located in a mature storage medium in the field such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory or an electrically erasable programmable memory, a register, etc. The storage medium is located in the memory, and the processor reads the information in the memory and completes the steps of the above method in combination with its hardware.
[0149] It is understood that the memory in the embodiments of the present application may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memory. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (programmable ROM, PROM), an erasable programmable read-only memory (erasable PROM, EPROM), an electrically erasable programmable read-only memory (EEPROM) or a flash memory. The volatile memory may be a random access memory (RAM). It should be noted that the memory of the systems and methods described herein is intended to include, but is not limited to, these and any other suitable types of memory.
[0150] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0151] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method implementation methods and will not be repeated here.
[0152] In the several embodiments provided in the present application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device implementation described above is only schematic. For example, the division of units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0153] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.
[0154] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0155] If the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. According to this understanding, the technical solution of the present application, or the part that contributes to the prior art or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium, including several instructions for a computer device (which can be a personal computer, server, or network device, etc.) to perform all or part of the steps of each implementation method of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM), random access memory (RAM), disk or optical disk, etc., various media that can store program codes.
[0156] The above are only specific embodiments of the present application, but the protection scope of the present invention is not limited thereto. Any person skilled in the art who is familiar with the present technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present invention shall be subject to the protection scope of the claims.
Claims
1. A collaborative signature method, characterized in that: Applied to the collaboration end, the method includes: Receiving an intermediate elliptic curve point sent by a mobile terminal, where the intermediate elliptic curve point is calculated by the mobile terminal according to a first random number and an elliptic curve base point; Calculate a final elliptic curve point according to the intermediate elliptic curve point, the second random number, the sub-private key of the collaboration end, and the elliptic curve base point; Calculate the final target signature validity verification message and the intermediate target signature integrity verification message according to the final elliptic curve point; The final target signature validity verification message and the intermediate target signature integrity verification message are sent to the mobile terminal, so that the mobile terminal determines the target signature based on the final target signature validity verification message and the intermediate target signature integrity verification message, and the target signature includes the final target signature validity verification message and the final target signature integrity verification message.
2. The method according to claim 1, characterized in that The calculating the final elliptic curve point according to the intermediate elliptic curve point, the second random number, the sub-private key of the collaboration end, and the elliptic curve base point includes: The final elliptic curve point is calculated according to the first formula, which is: Q = (d2 + k2) [*] G + d2 -1 [*]Q1, Q is the final elliptic curve point, Q1 is the intermediate elliptic curve point, k2 is the second random number, d2 is the sub-private key of the collaboration end, and G is the elliptic curve base point.
3. The method according to claim 2, characterized in that The calculating, according to the final elliptic curve point, a final target signature validity verification message and an intermediate target signature integrity verification message comprises: Calculate the final target signature validity verification message according to the horizontal coordinate of the final elliptic curve point and the hash value of the message to be verified, the hash value of the message to be verified is sent by the mobile terminal to the collaboration terminal, and the message to be verified is obtained by the mobile terminal concatenating the message to be signed with the identity identifiers of the mobile terminal and the collaboration terminal; An intermediate target signature integrity verification message is calculated based on the sub-private key of the collaboration end and the final target signature validity verification message.
4. The method according to claim 3, characterized in that The calculating the final target signature validity verification message according to the abscissa of the final elliptic curve point and the hash value of the message to be verified includes: The final target signature validity verification message is calculated according to the second formula, wherein the second formula is: r=(x1+e)modq, r is the final target signature validity verification message, x1 is the horizontal coordinate of the final elliptic curve point, e is the hash value of the message to be verified, and q is the number of elements in the finite field of the elliptic curve.
5. The method according to claim 4, characterized in that The calculating of the intermediate target signature integrity verification message according to the sub-private key of the collaboration end and the final target signature validity verification message includes: The intermediate target signature integrity verification message is calculated according to the third formula, wherein the third formula is: s1=d2(r+d2+k2) mod q, where s1 is the intermediate target signature integrity verification message.
6. The method according to claim 5, characterized in that The method further comprises: Receiving a first part of a public key sent by the mobile terminal, where the first part of the public key is calculated by the mobile terminal according to the sub-private key of the mobile terminal; Randomly generate a sub-private key of the collaboration end; Calculating a public key according to the first part of the public key and the sub-private key of the collaboration end, and calculating a second part of the public key according to the sub-private key of the collaboration end; The second part of the public key is sent to the mobile terminal, so that the mobile terminal calculates the public key according to the second part of the public key and the sub-private key of the mobile terminal.
7. The method according to any one of claims 1 to 6, characterized in that: Before receiving the intermediate elliptic curve point sent by the mobile terminal, the method further includes: receiving a login password sent by the mobile terminal, where the login password is set when the mobile terminal registers with the collaboration terminal; Query the user database to check whether the login password is correct; If the login password is correct, a comparison success message is sent to the mobile terminal.
8. A collaborative signature method, characterized in that: Applied to a mobile terminal, the method includes: generating a first random number; Calculate an intermediate elliptic curve point according to the first random number and the elliptic curve base point; Sending the intermediate elliptic curve point to the cooperating end; Receiving a final target signature validity verification message and an intermediate target signature integrity verification message sent by the mobile terminal, wherein the final target signature validity verification message and the intermediate target signature integrity verification message are calculated by the mobile terminal according to the intermediate elliptic curve point; Calculate a final target signature integrity verification message according to the private key of the mobile terminal, the first random number, the final target signature validity verification message and the intermediate target signature integrity verification message; The final target signature validity verification message and the final target signature integrity verification message are used as the target signature.
9. The method according to claim 8, characterized in that The calculating the final target signature integrity verification message according to the private key of the mobile terminal, the first random number, the final target signature validity verification message and the intermediate target signature integrity verification message includes: The final target signature integrity verification message is calculated according to the fourth formula, and the fourth formula is: s=(d1(s1+k1)-r)mod q, s is the final target signature integrity verification message, d1 is the private key of the mobile terminal, k1 is the first random number, r is the final target signature validity verification message, s1 is the intermediate target signature integrity verification message, and q is the number of elements in the elliptic curve finite field.
10. The method according to claim 9, characterized in that Before generating the first random number, the method further includes: The message to be signed is concatenated with the identity identifiers of the mobile terminal and the cooperation terminal to obtain a message to be verified; Calculate the hash value of the message to be verified; The hash value of the message to be verified and the login password set when the mobile terminal is registered with the collaboration terminal are sent to the collaboration terminal, so that the collaboration terminal queries the user database to compare whether the login password is correct.
11. The method according to any one of claims 8 to 10, characterized in that: The method further comprises: Randomly generate a sub-private key of the mobile terminal; Calculate the first part of the public key according to the sub-private key of the mobile terminal; Sending the first part of the public key to the collaboration end, so that the collaboration end calculates a public key according to the first part of the public key and the sub-private key of the mobile end, and calculates a second part of the public key according to the sub-private key of the mobile end; Receiving the second part of the public key sent by the collaboration end; The public key is calculated based on the second part of the public key and the sub-private key of the mobile terminal.
12. A collaborative signature device, characterized in that: Applied to a collaboration end, the device comprises: A communication unit, configured to receive an intermediate elliptic curve point sent by a mobile terminal, wherein the intermediate elliptic curve point is calculated by the mobile terminal according to a first random number and an elliptic curve base point; an elliptic curve point calculation unit, configured to calculate a final elliptic curve point according to the intermediate elliptic curve point, a second random number, a sub-private key of the collaboration end, and the elliptic curve base point; A signature information calculation unit, used to calculate a final target signature validity verification message and an intermediate target signature integrity verification message according to the final elliptic curve point; The communication unit is also used to send the final target signature validity verification message and the intermediate target signature integrity verification message to the mobile terminal, so that the mobile terminal determines the target signature based on the final target signature validity verification message and the intermediate target signature integrity verification message, and the target signature includes the final target signature validity verification message and the final target signature integrity verification message.
13. A collaborative signature device, characterized in that: Applied to a mobile terminal, the device comprises: A random number generating unit, used to generate a first random number; an elliptic curve point calculation unit, configured to calculate an intermediate elliptic curve point according to the first random number and an elliptic curve base point; A communication unit, configured to send the intermediate elliptic curve point to the collaboration end; The communication unit is further used to receive a final target signature validity verification message and an intermediate target signature integrity verification message sent by the mobile terminal, wherein the final target signature validity verification message and the intermediate target signature integrity verification message are calculated by the mobile terminal according to the intermediate elliptic curve point; A signature information calculation unit, used to calculate a final target signature integrity verification message according to the private key of the mobile terminal, the first random number, the final target signature validity verification message and the intermediate target signature integrity verification message; The signature determination unit is used to use the final target signature validity verification message and the final target signature integrity verification message as the target signature.
14. An electronic device, characterized in that: include: Processor and memory; The processor is connected to a memory, wherein the memory is used to store a computer program, and the processor is used to call the computer program to execute the method according to any one of claims 1-7 or 8-11.
15. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, wherein the computer program includes program instructions, and when the program instructions are executed by a processor, the method according to any one of claims 1-6 or 7-9 is executed.
Citation Information
Patent Citations
Cooperative signature method, device and system based on elliptic curve
CN113158258A
SM2 cryptographic algorithm collaborative signature and decryption method for protecting user privacy
CN114186251A
Blind collaborative signature method for protecting user privacy
CN114205081A