Cooperative signature method and related device

Through the collaborative signature method, the mobile terminal and the collaborative terminal each retain sub-private keys, and through elliptic curve point calculation and signature information verification, the problem of single point leakage of private keys in traditional digital signature solutions is solved, improving information security.

CN120223318AActive Publication Date: 2025-06-27ORIGIN QUANTUM COMPUTING TECH (HEFEI) CO LTD

Patent Information

Application Number
CN202510243957.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-03
Publication Date
2025-06-27
Estimated Expiration
2045-03-03

AI Technical Summary

Technical Problem

In traditional digital signature schemes, the private key is completely held by a single entity, and there is a risk of single point of leakage, resulting in information security risks.

Method used

Using the collaborative signature method, the mobile terminal and the collaborative terminal each retain their own sub-private keys, and through elliptic curve point calculation and signature information verification, the target signature is completed in a coordinated manner.

Benefits of technology

Improve the protection capability of private keys, prevent information security risks caused by single point of leakage, and ensure the security and integrity of target signatures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120223318A_ABST
    Figure CN120223318A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a cooperative signature method and a related device. A mobile terminal calculates a middle elliptic curve point according to a first random number, a sub-private key of the mobile terminal, a public key and an elliptic curve base point and sends the middle elliptic curve point to a cooperative terminal; the cooperation end calculates a final elliptic curve point according to the intermediate elliptic curve point, the second random number, a sub-private key of the cooperation end, a public key and an elliptic curve base point, calculates a final target signature validity verification message and an intermediate target signature integrity verification message according to the final elliptic curve point, and sends the information to the mobile end; and the mobile terminal calculates a final target signature integrity verification message according to the private key of the mobile terminal, the first random number, the final target signature validity verification message and the intermediate target signature integrity verification message, and takes the final target signature validity verification message and the final target signature integrity verification message as a target signature. By adopting the embodiment of the invention, the protection capability of the private key can be improved, and the information security risk caused by single-point leakage can be prevented.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of digital signatures, and in particular, to a collaborative signature method and related devices. Background Art

[0002] A digital signature is an electronic signature used to verify the authenticity and integrity of digital information. A digital signature is one of the important cryptographic primitive elements, and can provide functions similar to a handwritten signature in a digital form, such as identity authentication, non-repudiation, anti-tampering, etc. It has important applications in scenarios such as e-commerce, e-government, and blockchain services. There are various technical routes for the design of digital signature schemes, such as constructing signature schemes based on number theory difficult problems such as prime factor decomposition and solving discrete logarithms. In traditional digital signature schemes, the private key is completely held and used by a single entity. Once the security measures of the private key holder are not strict, there is a risk of single-point leakage of information. Summary of the Invention

[0003] Embodiments of the present application provide a collaborative signature method and related devices, which can improve the protection ability of the private key and prevent information security risks caused by single-point leakage.

[0004] In a first aspect of the embodiments of the present application, a collaborative signature method is provided, which is applied to a collaborative end. The method includes:

[0005] Receiving an intermediate elliptic curve point sent by a mobile end, where the intermediate elliptic curve point is calculated by the mobile end according to a first random number, a sub-private key of the mobile end, a public key, and an elliptic curve base point;

[0006] Calculating a final elliptic curve point according to the intermediate elliptic curve point, a second random number, a sub-private key of the collaborative end, the public key, and the elliptic curve base point;

[0007] Calculating a final target signature validity verification message and an intermediate target signature integrity verification message according to the final elliptic curve point;

[0008] Sending the final target signature validity verification message and the intermediate target signature integrity verification message to the mobile end, so that the mobile end determines a target signature according to the final target signature validity verification message and the intermediate target signature integrity verification message, where the target signature includes the final target signature validity verification message and the final target signature integrity verification message.

[0009] Optionally, the calculating a final elliptic curve point according to the intermediate elliptic curve point, a second random number, a sub-private key of the collaborative end, the public key, and the elliptic curve base point includes:

[0010] Calculate the final elliptic curve point according to the first formula, where the first formula is: Q = d2k2[*](P + G) + Q1, where Q is the final elliptic curve point, Q1 is the intermediate elliptic curve point, k2 is the second random number, d2 is the sub-private key of the cooperative end, P is the public key, and G is the elliptic curve base point.

[0011] Optionally, calculating the final target signature validity verification message and the intermediate target signature integrity verification message according to the final elliptic curve point includes:

[0012] Calculate the final target signature validity verification message according to the abscissa of the final elliptic curve point and the hash value of the message to be verified. The hash value of the message to be verified is sent by the mobile terminal to the cooperative end, and the message to be verified is obtained by the mobile terminal by splicing the message to be signed with the identity identifiers of the mobile terminal and the cooperative end;

[0013] Calculate the intermediate target signature integrity verification message according to the sub-private key of the cooperative end and the final target signature validity verification message.

[0014] Optionally, calculating the final target signature validity verification message according to the abscissa of the final elliptic curve point and the hash value of the message to be verified includes:

[0015] Calculate the final target signature validity verification message according to the second formula, where the second formula is: r = (x1 + e) mod q, where r is the final target signature validity verification message, x1 is the abscissa of the final elliptic curve point, e is the hash value of the message to be verified, and q is the number of elements in the elliptic curve finite field.

[0016] Optionally, calculating the intermediate target signature integrity verification message according to the sub-private key of the cooperative end and the final target signature validity verification message includes:

[0017] Calculate the intermediate target signature integrity verification message according to the third formula, where the third formula is: s1 = d2(r + k2) mod q, where s1 is the intermediate target signature integrity verification message.

[0018] Optionally, the method further includes:

[0019] Receive the first part of the public key sent by the mobile terminal, where the first part of the public key is calculated by the mobile terminal according to the pre-sub-private key of the mobile terminal;

[0020] Calculate the public key according to the first part of the public key and the pre-sub-private key of the cooperative end, and calculate the second part of the public key according to the pre-sub-private key of the cooperative end;

[0021] Send the second part of the public key to the mobile device so that the mobile device calculates the public key according to the second part of the public key and the pre-sub private key of the mobile device.

[0022] Optionally, the method further includes:

[0023] Receive a first ciphertext sent by the mobile device, where the first ciphertext is obtained by encrypting the pre-sub private key of the mobile device by the mobile device;

[0024] Randomly generate a sub private key of the collaboration end;

[0025] Calculate a second ciphertext according to the sub private key of the collaboration end and the first ciphertext;

[0026] Send the second ciphertext to the mobile device so that the mobile device decrypts the second ciphertext to obtain the sub private key of the mobile device.

[0027] Optionally, before receiving the intermediate elliptic curve point sent by the mobile device, the method further includes:

[0028] Receive a login password sent by the mobile device, where the login password is set when the mobile device registers with the collaboration end;

[0029] Query the user database to compare whether the login password is correct;

[0030] If the login password is correct, send a comparison success message to the mobile device.

[0031] A second aspect of the embodiments of the present application provides a collaborative signature method, which is applied to a mobile device. The method includes:

[0032] Generate a first random number;

[0033] Calculate an intermediate elliptic curve point according to the first random number, the sub private key of the mobile device, the public key, and the elliptic curve base point;

[0034] Send the intermediate elliptic curve point to the collaboration end;

[0035] Receive the final target signature validity verification message and the intermediate target signature integrity verification message sent by the mobile device. The final target signature validity verification message and the intermediate target signature integrity verification message are calculated by the mobile device according to the intermediate elliptic curve point;

[0036] Calculate the final target signature integrity verification message according to the private key of the mobile device, the first random number, the final target signature validity verification message, and the intermediate target signature integrity verification message;

[0037] Use the final target signature validity verification message and the final target signature integrity verification message as the target signature.

[0038] Optionally, the calculating the final target signature integrity verification message according to the private key of the mobile device, the first random number, the final target signature validity verification message, and the intermediate target signature integrity verification message includes:

[0039] Calculate the final target signature integrity verification message according to the fourth formula, where the fourth formula is: s = (d1(r + k1)+s1 - r) mod q, s is the final target signature integrity verification message, d1 is the private key of the mobile device, k1 is the first random number, r is the final target signature validity verification message, s1 is the intermediate target signature integrity verification message, and q is the number of elements in the finite field of the elliptic curve.

[0040] Optionally, before generating the first random number, the method further includes:

[0041] Concatenate the message to be signed with the identity identifiers of the mobile device and the collaborating device to obtain the message to be verified;

[0042] Calculate the hash value of the message to be verified;

[0043] Send the hash value of the message to be verified and the login password set when the mobile device registers with the collaborating device to the collaborating device, so that the collaborating device queries the user database to compare whether the login password is correct.

[0044] Optionally, the calculating the intermediate elliptic curve point according to the first random number, the sub-private key of the mobile device, the public key, and the elliptic curve base point includes:

[0045] Calculate the intermediate elliptic curve point according to the fifth formula, where the fifth formula is: Q1 = d1k1[*](P + G), Q1 is the intermediate elliptic curve point, k1 is the first random number, d1 is the sub-private key of the mobile device, P is the public key, and G is the elliptic curve base point.

[0046] Optionally, the method further includes:

[0047] Randomly generate a pre-sub-private key for the mobile device;

[0048] Calculate the first part of the public key according to the pre-sub-private key of the mobile device;

[0049] Send the first part of the public key to the collaborating device, so that the collaborating device calculates the public key according to the first part of the public key and the pre-sub-private key of the mobile device;

[0050] Receive the second part of the public key sent by the collaborating end, where the second part of the public key is calculated by the collaborating end based on the pre-sub private key of the collaborating end;

[0051] Calculate the public key based on the second part of the public key and the pre-sub private key of the mobile end.

[0052] Optionally, the method further includes:

[0053] Encrypt the pre-sub private key of the mobile end to obtain a first ciphertext;

[0054] Send the first ciphertext to the collaborating end so that the collaborating end calculates a second ciphertext based on the first ciphertext and the sub private key of the collaborating end;

[0055] Receive the second ciphertext sent by the collaborating end;

[0056] Decrypt the second ciphertext to obtain the sub private key of the mobile end.

[0057] The third aspect of the embodiments of the present application provides a collaborative signature device, which is applied to the collaborating end. The device includes:

[0058] A communication unit, configured to receive an intermediate elliptic curve point sent by the mobile end, where the intermediate elliptic curve point is calculated by the mobile end based on a first random number, the sub private key of the mobile end, the public key, and the elliptic curve base point;

[0059] An elliptic curve point calculation unit, configured to calculate a final elliptic curve point based on the intermediate elliptic curve point, a second random number, the sub private key of the collaborating end, the public key, and the elliptic curve base point;

[0060] A signature information calculation unit, configured to calculate a final target signature validity verification message and an intermediate target signature integrity verification message based on the final elliptic curve point;

[0061] The communication unit is further configured to send the final target signature validity verification message and the intermediate target signature integrity verification message to the mobile end so that the mobile end determines a target signature based on the final target signature validity verification message and the intermediate target signature integrity verification message, where the target signature includes the final target signature validity verification message and the final target signature integrity verification message.

[0062] The fourth aspect of the embodiments of the present application provides a collaborative signature device, which is applied to the mobile end. The device includes:

[0063] A random number generation unit, configured to generate a first random number;

[0064] An elliptic curve point calculation unit, configured to calculate an intermediate elliptic curve point according to the first random number, the sub-private key of the mobile device, the public key, and the elliptic curve base point;

[0065] A communication unit, configured to send the intermediate elliptic curve point to a collaborating end;

[0066] The communication unit is further configured to receive the final target signature validity verification message and the intermediate target signature integrity verification message sent by the mobile device, where the final target signature validity verification message and the intermediate target signature integrity verification message are calculated by the mobile device according to the intermediate elliptic curve point;

[0067] A signature information calculation unit, configured to calculate a final target signature integrity verification message according to the private key of the mobile device, the first random number, the final target signature validity verification message, and the intermediate target signature integrity verification message;

[0068] A signature determination unit, configured to use the final target signature validity verification message and the final target signature integrity verification message as the target signature.

[0069] A fifth aspect of the embodiments of the present application provides an electronic device, including: a processor and a memory;

[0070] The processor is connected to the memory, where the memory is used to store a computer program, and the processor is used to call the computer program to execute the method in the first aspect or the second aspect in the embodiments of the present application.

[0071] A sixth aspect of the embodiments of the present application provides a computer-readable storage medium, where the computer-readable storage medium stores a computer program, and the computer program includes program instructions, and when the program instructions are executed by a processor, the method in the first aspect or the second aspect in the embodiments of the present application is executed.

[0072] In the embodiments of the present application, the mobile device calculates an intermediate elliptic curve point according to the first random number, the sub-private key of the mobile device, the public key, and the elliptic curve base point and sends it to the collaborating end; the collaborating end calculates a final elliptic curve point according to the intermediate elliptic curve point, the second random number, the sub-private key of the collaborating end, the public key, and the elliptic curve base point, and calculates a final target signature validity verification message and an intermediate target signature integrity verification message according to the final elliptic curve point and sends them to the mobile device; the mobile device calculates a final target signature integrity verification message according to the private key of the mobile device, the first random number, the final target signature validity verification message, and the intermediate target signature integrity verification message, and uses the final target signature validity verification message and the final target signature integrity verification message as the target signature.

[0073] It can be seen that in the embodiments of the present application, the mobile terminal and the collaborative terminal each keep their own private keys, and then complete the target signature through cooperation according to their own private keys. Since the private keys are respectively held by the mobile terminal and the collaborative terminal, even if the private key of any one end is stolen, it will not cause the overall target signature to be untrusted, thereby improving the protection ability of the private key and preventing information security risks caused by single-point leakage. BRIEF DESCRIPTION OF THE DRAWINGS

[0074] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0075] Figure 1 FIG. shows a schematic block diagram of an example system for collaborative signature provided by an embodiment of the present application;

[0076] Figure 2 FIG. shows a schematic flowchart of a collaborative signature method provided by an embodiment of the present application;

[0077] Figure 3 FIG. shows a schematic flowchart of a communication security verification method provided by an embodiment of the present application;

[0078] Figure 4 FIG. shows a schematic flowchart of a public key splitting method provided by an embodiment of the present application;

[0079] Figure 5 FIG. shows a schematic flowchart of a private key splitting method provided by an embodiment of the present application;

[0080] Figure 6 FIG. shows a schematic structural diagram of a collaborative signature device provided by an embodiment of the present application;

[0081] Figure 7 FIG. shows a schematic structural diagram of a collaborative signature device provided by another embodiment of the present application;

[0082] Figure 8 FIG. shows a schematic structural diagram of a computer device provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0083] The following will clearly and completely describe the technical solutions in the embodiments of the present application with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. According to the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present application.

[0084] Please refer to Figure 1 , which shows a schematic block diagram of an example system for collaborative signature provided by an embodiment of the present application. The operating environment may include: a mobile terminal 10 and a collaborative terminal 20.

[0085] The mobile terminal 10 includes, but is not limited to, electronic devices such as mobile phones, computers, intelligent voice interaction devices, intelligent home appliances, vehicle-mounted terminals, game consoles, e-book readers, multimedia playback devices, and wearable devices. A client of an application program may be installed in the mobile terminal 10. The collaborative terminal 20 may be, for example, a server that provides digital signature collaboration services.

[0086] Any suitable network protocol 30 may be used for communication between the mobile terminal 10 and the collaborative terminal 20 devices, including network protocols that have not been developed as of the filing date of the present application. The network protocol may include, for example, TCP / IP protocol, UDP / IP protocol, HTTP protocol, HTTPS protocol, etc. Of course, the network protocol may also include, for example, the RPC protocol (Remote Procedure Call Protocol) and the REST protocol (Representational State Transfer) used on top of the above protocols.

[0087] It can be understood that each data item or various combined data items in the present application are essentially data obtained by combining and calculating different types of parameters, which are different from the source data directly sent or received. The application of such data in the data interaction process can effectively prevent the source data from being intercepted and obtained or deduced during the transmission process. Additionally, in one or more embodiments of the present application, various data expressed in parameter expressions are actually the result data calculated by applying the parameter expressions. It is also the numerical data corresponding to the numerical value that is transmitted during the interaction process, rather than the expression itself.

[0088] Please refer to Figure 2 , which shows a schematic flowchart of a collaborative signature method provided by an embodiment of the present application. This method can be applied to a computer device, and the above computer device refers to an electronic device with data calculation and processing capabilities. For example, the execution entity of each step can be Figure 1 the mobile terminal 10 and the collaborative terminal 20 devices shown. This method may include the following steps:

[0089] Step 201: The mobile device 10 generates a first random number.

[0090] Step 202: The mobile device 10 calculates an intermediate elliptic curve point according to the first random number, the sub-private key of the mobile device, the public key, and the elliptic curve base point.

[0091] Specifically, the calculating of the intermediate elliptic curve point according to the first random number, the sub-private key of the mobile device, the public key, and the elliptic curve base point includes:

[0092] Calculating the intermediate elliptic curve point according to the fifth formula, where the fifth formula is: Q1 = d1k1[*](P + G), Q1 is the intermediate elliptic curve point, k1 is the first random number, d1 is the sub-private key of the mobile device, P is the public key, and G is the elliptic curve base point.

[0093] Among them, the elliptic curve base point is a point on the elliptic curve and is the basis for constructing the elliptic curve cryptosystem.

[0094] Step 203: The mobile device 10 sends the intermediate elliptic curve point to the collaborating device.

[0095] Step 204: The collaborating device 20 calculates the final elliptic curve point according to the intermediate elliptic curve point, the second random number, the sub-private key of the collaborating device, the public key, and the elliptic curve base point.

[0096] Among them, the first random number k1 and the second random number k2 can be pseudo-random numbers or true random numbers. The pseudo-random numbers are generated by a deterministic algorithm; the true random numbers are obtained through physical processes, such as quantum mechanical phenomena or environmental noise, etc.

[0097] Specifically, the calculating of the final elliptic curve point according to the intermediate elliptic curve point, the second random number, the sub-private key of the collaborating device, the public key, and the elliptic curve base point includes:

[0098] Calculating the final elliptic curve point according to the first formula, where the first formula is: Q = d2k2[*](P + G)+Q1, Q is the final elliptic curve point, k2 is the second random number, and d2 is the sub-private key of the collaborating device.

[0099] Step 205: The collaborating device 20 calculates the final target signature validity verification message and the intermediate target signature integrity verification message according to the final elliptic curve point.

[0100] Among them, a signature usually consists of two parts. One part is used to verify the validity of the signature, usually represented by r, and the other part is used to verify the integrity of the signature, usually represented by s. The final ones are the r and s that ultimately need to be determined for the target signature; the intermediate ones are of a transitional nature and are only used to determine the final intermediate values.

[0101] Specifically, calculating the final target signature validity verification message and the intermediate target signature integrity verification message based on the final elliptic curve point includes:

[0102] Calculating the final target signature validity verification message according to the abscissa of the final elliptic curve point and the hash value of the message to be verified, where the hash value of the message to be verified is sent by the mobile terminal to the collaboration terminal, and the message to be verified is obtained by the mobile terminal by splicing the message to be signed with the identity identifiers of the mobile terminal and the collaboration terminal;

[0103] Calculating the intermediate target signature integrity verification message according to the sub-private key of the collaboration terminal and the final target signature validity verification message.

[0104] Exemplarily, calculating the final target signature validity verification message according to the abscissa of the final elliptic curve point and the hash value of the message to be verified includes:

[0105] Calculating the final target signature validity verification message according to the second formula, where the second formula is: r = (x1 + e) mod q, r is the final target signature validity verification message, x1 is the abscissa of the final elliptic curve point, e is the hash value of the message to be verified, and q is the number of elements in the finite field of the elliptic curve.

[0106] Exemplarily, calculating the intermediate target signature integrity verification message according to the sub-private key of the collaboration terminal and the final target signature validity verification message includes:

[0107] Calculating the intermediate target signature integrity verification message according to the third formula, where the third formula is: s1 = d2(r + k2) mod q, and s1 is the intermediate target signature integrity verification message.

[0108] Step 206: The collaboration terminal 20 sends the final target signature validity verification message and the intermediate target signature integrity verification message to the mobile terminal.

[0109] Step 207: The mobile terminal 10 calculates the final target signature integrity verification message according to the private key of the mobile terminal, the first random number, the final target signature validity verification message, and the intermediate target signature integrity verification message.

[0110] Specifically, calculating the final target signature integrity verification message according to the private key of the mobile terminal, the first random number, the final target signature validity verification message, and the intermediate target signature integrity verification message includes:

[0111] Calculate the final target signature integrity verification message according to the fourth formula, where the fourth formula is: s = (d1(r + k1) + s1 - r) mod q, and s is the final target signature integrity verification message.

[0112] Step 208: The mobile device 10 uses the final target signature validity verification message and the final target signature integrity verification message as the target signature.

[0113] In the embodiment of the present application, the mobile device calculates an intermediate elliptic curve point based on the first random number, the sub-private key of the mobile device, the public key, and the elliptic curve base point, and sends it to the cooperative device; the cooperative device calculates the final elliptic curve point based on the intermediate elliptic curve point, the second random number, the sub-private key of the cooperative device, the public key, and the elliptic curve base point, and calculates the final target signature validity verification message and the intermediate target signature integrity verification message based on the final elliptic curve point and sends them to the mobile device; the mobile device calculates the final target signature integrity verification message based on the private key of the mobile device, the first random number, the final target signature validity verification message, and the intermediate target signature integrity verification message, and uses the final target signature validity verification message and the final target signature integrity verification message as the target signature.

[0114] It can be seen that in the embodiment of the present application, the mobile device and the cooperative device each keep their own private keys, and then cooperate to complete the target signature according to their own private keys. Since each of the mobile device and the cooperative device holds a part of the private key, the theft of the private key of any one end will not cause the overall target signature to be invalid, thereby improving the protection ability of the private key and preventing information security risks caused by single-point leakage.

[0115] Further, before the mobile device 10 sends the intermediate elliptic curve point to the cooperative device, information verification can be performed first to ensure the security of communication. Please refer to Figure 3 , which shows a schematic flow chart of a communication security verification method provided by an embodiment of the present application. This method can be applied to a computer device, and the above computer device refers to an electronic device with data calculation and processing capabilities. For example, the execution subject of each step can be Figure 1 the mobile device 10 and the cooperative device 20 shown. This method can include the following steps:

[0116] Step 301: The mobile device 10 splices the message to be signed with the identity identifiers of the mobile device and the cooperative device to obtain the message to be verified.

[0117] Step 302: The mobile device 10 calculates the hash value of the message to be verified.

[0118] Step 303: The mobile device 10 sends the hash value of the message to be verified and the login password set when the mobile device registers with the cooperative device to the cooperative device.

[0119] Step 304: The cooperation end 20 queries the user database to compare whether the login password is correct.

[0120] Step 305: If the login password is correct, the cooperation end 20 sends a comparison success message to the mobile end.

[0121] It should be noted that the mobile end 10 can send the hash value of the message to be verified and the login password set when the mobile end registers with the cooperation end as two separate pieces of information to the cooperation end, or can splice the hash value of the message to be verified and the login password set when the mobile end registers with the cooperation end into one piece of information and send it to the cooperation end, which is not limited here.

[0122] It can be seen that in the embodiment of the present application, before the mobile end and the cooperation end perform cooperative signature, they first compare through the login password, which can improve the security of the cooperative signature; at the same time, when the mobile end sends the hash value of the message to be verified and the login password at the same time, the hash value of the message to be verified can be directly used for subsequent cooperative signature, reducing the number of information interactions, thereby improving the speed of the cooperative signature.

[0123] Further, please refer to Figure 4 , which shows a schematic flowchart of a public key splitting method provided by an embodiment of the present application. This method can be applied to a computer device. The above computer device refers to an electronic device with data calculation and processing capabilities. For example, the execution subject of each step can be Figure 1 the mobile end 10 and the cooperation end 20 devices shown. This method can include the following steps:

[0124] Step 401: The mobile end 10 randomly generates a pre-sub private key of the mobile end.

[0125] Step 402: The mobile end 10 calculates a first part of the public key according to the pre-sub private key of the mobile end;

[0126] Step 403: The mobile end 10 sends the first part of the public key to the cooperation end.

[0127] Step 404: The cooperation end 20 randomly generates a pre-sub private key of the cooperation end.

[0128] Step 405: The cooperation end 20 calculates the public key according to the first part of the public key and the pre-sub private key of the cooperation end, and calculates a second part of the public key according to the pre-sub private key of the cooperation end;

[0129] Step 406: The cooperation end 20 sends the second part of the public key to the mobile end.

[0130] Step 407: The collaboration end 20 calculates the public key according to the second part of the public key and the pre-sub private key of the mobile end.

[0131] Among them, the pre-sub private key is not the formal sub private key.

[0132] Specifically, the calculating the first part of the public key according to the pre-sub private key of the mobile end includes:

[0133] Calculating the first part of the public key according to the sixth formula, and the sixth formula is: P1 = d 1 1 -1 [*]G, where P1 is the first part of the public key and d1 ′ is the pre-sub private key of the mobile end.

[0134] Similarly, the calculating the second part of the public key according to the pre-sub private key of the collaboration end includes:

[0135] Calculating the intermediate elliptic curve point according to the seventh formula, and the seventh formula is: P2 = d ′ 2 -1 [*]G, where P2 is the second part of the public key and d2 ′ is the pre-sub private key of the collaboration end.

[0136] Specifically, the calculating the public key according to the first part of the public key and the pre-sub private key of the collaboration end includes:

[0137] Calculating the public key according to the eighth formula, and the eighth formula is: P = d ′ 1 -1 [*]P2 - G.

[0138] It can be seen that in the embodiment of the present application, the mobile end and the collaboration end respectively randomly generate their own pre-sub private keys, and then calculate their respective partial public keys according to the sub private keys, send the partial public keys to each other, and the other party can calculate the same public key according to the partial public key of the other party and its own pre-sub private key, thus realizing the splitting of the public key and improving the security protection of the key.

[0139] Further, please refer to Figure 5 , which shows a schematic flowchart of the private key splitting method provided by an embodiment of the present application. This method can be applied to a computer device, and the above computer device refers to an electronic device with data calculation and processing capabilities. For example, the execution subject of each step can be Figure 1 the mobile end 10 and the collaboration end 20 devices shown. This method may include the following steps:

[0140] Step 501: The mobile end 10 encrypts the pre-sub private key of the mobile end to obtain the first ciphertext.

[0141] Step 502: The mobile device 10 sends the first ciphertext to the collaborating device.

[0142] Step 503: The collaborating device 20 randomly generates a sub-private key of the collaborating device.

[0143] Step 504: The collaborating device 20 calculates a second ciphertext based on the sub-private key of the collaborating device and the first ciphertext.

[0144] Step 505: The collaborating device 20 sends the second ciphertext to the mobile device.

[0145] Step 506: The mobile device 10 decrypts the second ciphertext to obtain the sub-private key of the mobile device.

[0146] Exemplarily, the encryption algorithm can be Enc pk , and the decryption algorithm can be Dec pk , so that the mobile device 10 encrypts the pre-sub-private key of the mobile device Enc pk (d1 ′ ), to obtain the first ciphertext c1; the collaborating device 20 calculates the second ciphertext c ′ 2 according to the sub-private key d2 of the collaborating device and the first ciphertext c1, and the calculation method can be c2 = d2 ⊙ c1, The mobile device 10 decrypts the second ciphertext to obtain the sub-private key of the mobile device Dec sk (c2 ′ ).

[0147] It can be seen that in the embodiment of the present application, the collaborating device randomly generates its own sub-private key, and calculates the second ciphertext according to the sub-private key of the collaborating device and the first ciphertext encrypted by the pre-sub-private key of the mobile device. The mobile device decrypts the second ciphertext to obtain its own sub-private key, thereby realizing the splitting of the private key and improving the security protection of the key.

[0148] Figure 6 Fig. shows a schematic structural diagram of a collaborative signature device provided by an embodiment of the present application. Applied to the collaborating device, the device includes:

[0149] A communication unit 601, configured to receive an intermediate elliptic curve point sent by the mobile device, where the intermediate elliptic curve point is calculated by the mobile device according to a first random number, the sub-private key of the mobile device, the public key, and the elliptic curve base point;

[0150] An elliptic curve point calculation unit 602, configured to calculate a final elliptic curve point according to the intermediate elliptic curve point, a second random number, the sub-private key of the collaborating device, the public key, and the elliptic curve base point;

[0151] The signature information calculation unit 603 is configured to calculate the final target signature validity verification message and the intermediate target signature integrity verification message according to the final elliptic curve point;

[0152] The communication unit 601 is further configured to send the final target signature validity verification message and the intermediate target signature integrity verification message to the mobile terminal, so that the mobile terminal determines the target signature according to the final target signature validity verification message and the intermediate target signature integrity verification message, where the target signature includes the final target signature validity verification message and the final target signature integrity verification message.

[0153] Figure 7 The structural schematic diagram of a collaborative signature device provided by an embodiment of the present application is shown. Applied to a mobile terminal, the device includes:

[0154] The random number generation unit 701 is configured to generate a first random number;

[0155] The elliptic curve point calculation unit 702 is configured to calculate an intermediate elliptic curve point according to the first random number, the sub-private key of the mobile terminal, the public key, and the elliptic curve base point;

[0156] The communication unit 703 is configured to send the intermediate elliptic curve point to the collaborative end;

[0157] The communication unit 703 is further configured to receive the final target signature validity verification message and the intermediate target signature integrity verification message sent by the mobile terminal, where the final target signature validity verification message and the intermediate target signature integrity verification message are calculated by the mobile terminal according to the intermediate elliptic curve point;

[0158] The signature information calculation unit 704 is configured to calculate the final target signature integrity verification message according to the private key of the mobile terminal, the first random number, the final target signature validity verification message, and the intermediate target signature integrity verification message;

[0159] The signature determination unit 705 is configured to use the final target signature validity verification message and the final target signature integrity verification message as the target signature.

[0160] Figure 8 The structural schematic diagram of a computer device provided by an embodiment of the present application is shown, including a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, it implements the functions of the computer system of the collaborative signature method in any of the above embodiments.

[0161] Embodiments of the present application also provide a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a computer, the computer performs the functions of the computer system for the collaborative signature method in any of the above embodiments.

[0162] Embodiments of the present application also provide a computer program product containing instructions. When the instructions are executed by a computer, the computer performs the functions of the computer system for the collaborative signature method in any of the above embodiments.

[0163] It can be understood that the specific examples in the present application are only to help those skilled in the art better understand the embodiments of the present application, rather than limiting the scope of the present invention.

[0164] It can be understood that in various embodiments of the present application, the magnitudes of the sequence numbers of the processes do not mean the order of execution. The order of execution of the processes should be determined by their functions and internal logics, and should not constitute any limitation to the implementation processes of the embodiments of the present application.

[0165] It can be understood that the various embodiments described in the present application can be implemented alone or in combination, and the embodiments of the present application do not limit this.

[0166] Unless otherwise specified, all technical and scientific terms used in the embodiments of the present application have the same meaning as commonly understood by those skilled in the technical field of the present application. The terms used in the present application are only for the purpose of describing specific embodiments, and are not intended to limit the scope of the present application. The term "and / or" used in the embodiments of the present application and the appended claims includes any and all combinations of one or more of the related listed items. The singular forms "a", "above", and "the" used in the embodiments of the present application and the appended claims are also intended to include the plural forms, unless the context clearly indicates otherwise.

[0167] It can be understood that the processor in the embodiments of the present application can be an integrated circuit chip with signal processing capabilities. In the implementation process, the steps of the above method embodiments can be completed by the integrated logic circuit in the hardware of the processor or instructions in the form of software. The above processor can be a general-purpose processor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. It can implement or execute the various methods, steps and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor, etc. The steps of the method disclosed in combination with the embodiments of the present application can be directly embodied as being executed and completed by the hardware decoding processor, or executed and completed by a combination of the hardware and software modules in the decoding processor. The software module can be located in a mature storage medium in the art such as random access memory, flash memory, read-only memory, programmable read-only memory or electrically erasable programmable memory, registers, etc. This storage medium is located in the memory, and the processor reads the information in the memory and combines its hardware to complete the steps of the above method.

[0168] It can be understood that the memory in the embodiments of the present application can be a volatile memory or a non-volatile memory, or can include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM) or a flash memory. The volatile memory can be a random access memory (RAM). It should be noted that the memory of the systems and methods described herein is intended to include, but is not limited to, these and any other suitable types of memory.

[0169] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or by a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.

[0170] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.

[0171] In several embodiments provided in the present application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling, direct coupling, or communication connection between each other can be through some interfaces. The indirect coupling or communication connection of devices or units can be in electrical, mechanical, or other forms.

[0172] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0173] In addition, in each embodiment of the present application, the functional units can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit.

[0174] If the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art or the part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in each embodiment of the present application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs that can store program codes.

[0175] The above is only the specific embodiment of the present application, but the protection scope of the present invention is not limited thereto. Any person skilled in the art can easily think of changes or substitutions within the technical scope disclosed in the present application and should be covered by the protection scope of the present application. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims.

Claims

1. A collaborative signature method, characterized in that: Applied to the collaboration end, the method includes: Receiving an intermediate elliptic curve point sent by a mobile terminal, where the intermediate elliptic curve point is calculated by the mobile terminal according to a first random number, a sub-private key of the mobile terminal, a public key, and an elliptic curve base point; Calculate a final elliptic curve point according to the intermediate elliptic curve point, a second random number, the sub-private key of the collaboration end, the public key, and the elliptic curve base point; Calculate the final target signature validity verification message and the intermediate target signature integrity verification message according to the final elliptic curve point; The final target signature validity verification message and the intermediate target signature integrity verification message are sent to the mobile terminal, so that the mobile terminal determines the target signature based on the final target signature validity verification message and the intermediate target signature integrity verification message, and the target signature includes the final target signature validity verification message and the final target signature integrity verification message.

2. The method according to claim 1, characterized in that The calculating a final elliptic curve point according to the intermediate elliptic curve point, the second random number, the sub-private key of the collaboration end, the public key and the elliptic curve base point comprises: The final elliptic curve point is calculated according to the first formula, which is: Q=d2k2[*](P+G)+Q1, where Q is the final elliptic curve point, Q1 is the intermediate elliptic curve point, k2 is the second random number, d2 is the sub-private key of the collaboration end, P is the public key, and G is the elliptic curve base point.

3. The method according to claim 2, characterized in that The calculating, according to the final elliptic curve point, a final target signature validity verification message and an intermediate target signature integrity verification message comprises: Calculate the final target signature validity verification message according to the horizontal coordinate of the final elliptic curve point and the hash value of the message to be verified, the hash value of the message to be verified is sent by the mobile terminal to the collaboration terminal, and the message to be verified is obtained by the mobile terminal concatenating the message to be signed with the identity identifiers of the mobile terminal and the collaboration terminal; An intermediate target signature integrity verification message is calculated based on the sub-private key of the collaboration end and the final target signature validity verification message.

4. The method according to claim 3, characterized in that The calculating the final target signature validity verification message according to the abscissa of the final elliptic curve point and the hash value of the message to be verified includes: The final target signature validity verification message is calculated according to the second formula, wherein the second formula is: r=(x1+e)modq, r is the final target signature validity verification message, x1 is the horizontal coordinate of the final elliptic curve point, e is the hash value of the message to be verified, and q is the number of elements in the finite field of the elliptic curve.

5. The method according to claim 4, characterized in that The calculating of the intermediate target signature integrity verification message according to the sub-private key of the collaboration end and the final target signature validity verification message includes: The intermediate target signature integrity verification message is calculated according to the third formula, wherein the third formula is: s1=d2(r+k2)mod q, where s1 is the intermediate target signature integrity verification message.

6. The method according to claim 5, characterized in that The method further comprises: Receiving a first part of a public key sent by the mobile terminal, where the first part of the public key is calculated by the mobile terminal according to a pre-child private key of the mobile terminal; Calculating a public key according to the first part of the public key and the pre-child private key of the collaboration end, and calculating a second part of the public key according to the pre-child private key of the collaboration end; The second part of the public key is sent to the mobile terminal, so that the mobile terminal calculates the public key according to the second part of the public key and the pre-child private key of the mobile terminal.

7. The method according to claim 6, characterized in that The method further comprises: Receiving a first ciphertext sent by the mobile terminal, where the first ciphertext is obtained by the mobile terminal encrypting the pre-child private key of the mobile terminal; Randomly generate a sub-private key of the collaboration end; Calculate a second ciphertext according to the sub-private key of the collaboration end and the first ciphertext; The second ciphertext is sent to the mobile terminal, so that the mobile terminal decrypts the second ciphertext to obtain the sub-private key of the mobile terminal.

8. The method according to any one of claims 1 to 7, characterized in that: Before receiving the intermediate elliptic curve point sent by the mobile terminal, the method further includes: receiving a login password sent by the mobile terminal, where the login password is set when the mobile terminal registers with the collaboration terminal; Query the user database to check whether the login password is correct; If the login password is correct, a comparison success message is sent to the mobile terminal.

9. A collaborative signature method, characterized in that: Applied to a mobile terminal, the method includes: generating a first random number; Calculate an intermediate elliptic curve point according to the first random number, the mobile terminal's sub-private key, the public key, and the elliptic curve base point; Sending the intermediate elliptic curve point to the cooperating end; Receiving a final target signature validity verification message and an intermediate target signature integrity verification message sent by the mobile terminal, wherein the final target signature validity verification message and the intermediate target signature integrity verification message are calculated by the mobile terminal according to the intermediate elliptic curve point; Calculate a final target signature integrity verification message according to the private key of the mobile terminal, the first random number, the final target signature validity verification message and the intermediate target signature integrity verification message; The final target signature validity verification message and the final target signature integrity verification message are used as the target signature.

10. The method according to claim 9, characterized in that The calculating the final target signature integrity verification message according to the private key of the mobile terminal, the first random number, the final target signature validity verification message and the intermediate target signature integrity verification message includes: The final target signature integrity verification message is calculated according to the fourth formula, and the fourth formula is: s=(d1(r+k1)+s1-r)mod q, s is the final target signature integrity verification message, d1 is the private key of the mobile terminal, k1 is the first random number, r is the final target signature validity verification message, s1 is the intermediate target signature integrity verification message, and q is the number of elements in the elliptic curve finite field.

11. The method according to claim 10, characterized in that Before generating the first random number, the method further includes: The message to be signed is concatenated with the identity identifiers of the mobile terminal and the cooperation terminal to obtain a message to be verified; Calculate the hash value of the message to be verified; The hash value of the message to be verified and the login password set when the mobile terminal is registered with the collaboration terminal are sent to the collaboration terminal, so that the collaboration terminal queries the user database to compare whether the login password is correct.

12. The method according to claim 10, characterized in that The calculating the intermediate elliptic curve point according to the first random number, the mobile terminal's sub-private key, the public key, and the elliptic curve base point includes: The intermediate elliptic curve point is calculated according to the fifth formula, and the fifth formula is: Q1=d1k1[*](P+G), Q1 is the intermediate elliptic curve point, k1 is the first random number, d1 is the sub-private key of the mobile terminal, P is the public key, and G is the elliptic curve base point.

13. The method according to any one of claims 9 to 12, characterized in that: The method further comprises: Randomly generate a pre-child private key for the mobile terminal; Calculate the first part of the public key according to the pre-child private key of the mobile terminal; Sending the first part of the public key to the collaboration end, so that the collaboration end calculates a public key according to the first part of the public key and the pre-child private key of the mobile end; Receiving a second part of the public key sent by the collaboration end, where the second part of the public key is calculated by the collaboration end according to the pre-child private key of the collaboration end; The public key is calculated based on the second part of the public key and the pre-child private key of the mobile terminal.

14. The method according to claim 13, characterized in that The method further comprises: Encrypting the pre-child private key of the mobile terminal to obtain a first ciphertext; Sending the first ciphertext to the collaboration end, so that the collaboration end calculates a second ciphertext according to the first ciphertext and the sub-private key of the collaboration end; Receiving a second ciphertext sent by the collaboration terminal; The second ciphertext is decrypted to obtain the sub-private key of the mobile terminal.

15. A collaborative signature device, characterized in that: Applied to a collaboration end, the device comprises: A communication unit, configured to receive an intermediate elliptic curve point sent by a mobile terminal, wherein the intermediate elliptic curve point is calculated by the mobile terminal according to a first random number, a sub-private key of the mobile terminal, a public key, and an elliptic curve base point; an elliptic curve point calculation unit, configured to calculate a final elliptic curve point according to the intermediate elliptic curve point, a second random number, a sub-private key of the collaboration end, the public key, and the elliptic curve base point; A signature information calculation unit, used to calculate a final target signature validity verification message and an intermediate target signature integrity verification message according to the final elliptic curve point; The communication unit is also used to send the final target signature validity verification message and the intermediate target signature integrity verification message to the mobile terminal, so that the mobile terminal determines the target signature based on the final target signature validity verification message and the intermediate target signature integrity verification message, and the target signature includes the final target signature validity verification message and the final target signature integrity verification message.

16. A collaborative signature device, characterized in that: Applied to a mobile terminal, the device comprises: A random number generating unit, used to generate a first random number; an elliptic curve point calculation unit, configured to calculate an intermediate elliptic curve point according to the first random number, the sub-private key of the mobile terminal, the public key and the elliptic curve base point; A communication unit, configured to send the intermediate elliptic curve point to the collaboration end; The communication unit is further used to receive a final target signature validity verification message and an intermediate target signature integrity verification message sent by the mobile terminal, wherein the final target signature validity verification message and the intermediate target signature integrity verification message are calculated by the mobile terminal according to the intermediate elliptic curve point; A signature information calculation unit, used to calculate a final target signature integrity verification message according to the private key of the mobile terminal, the first random number, the final target signature validity verification message and the intermediate target signature integrity verification message; The signature determination unit is used to use the final target signature validity verification message and the final target signature integrity verification message as the target signature.

17. An electronic device, characterized in that: include: Processor and memory; The processor is connected to a memory, wherein the memory is used to store a computer program, and the processor is used to call the computer program to execute the method according to any one of claims 1-8 or 9-14.

18. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, wherein the computer program includes program instructions, and when the program instructions are executed by a processor, the method according to any one of claims 1-8 or 9-14 is executed.

Citation Information

Patent Citations

  • Method for generating digital signature by cooperation of double parties

    CN107483212A

  • Signature method and device for generating SM2 algorithm through mutual coordination, and storage medium

    CN109245903A

  • SM2 cryptographic algorithm collaborative signature and decryption method for protecting user privacy

    CN114186251A

  • Collaborative blind signature method and system based on SM2 algorithm

    CN116346348A

  • Collaborative signature method and system based on SM2 cryptographic algorithm

    CN118473665A

Cited By

  • Cooperative signature method and related device

    CN120090806A