Collaborative signature method and system
Through the collaborative signature method, a variety of encryption algorithms and key segmentation technologies are used to solve the problem of easy leakage of private keys in traditional electronic signature methods, and the security and flexibility are improved, and cross-device signature and secure recovery are supported.
Patent Information
- Application Number
- CN202510389194.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-31
- Publication Date
- 2025-07-18
AI Technical Summary
Traditional electronic signature methods rely on a single device, and private keys are easily acquired by attackers, resulting in the signature losing its legal effect, and users can only sign on specific devices, which increases the cost of use and inconvenience.
The collaborative signature method is adopted, through the collaboration between the user and the server, the user's private key ciphertext is generated and stored using SM3, elliptic curve algorithm and SM4 algorithm, and a dynamic boot interface and chaotic function are used to generate cipher factors, and the signature is synthesized on the server to realize key segmentation and collaborative digital signature.
Improve the security and flexibility of signatures, prevent private key leakage and signature forgery, support signature operations on different devices, reduce user costs, and enhance user experience.
Smart Images

Figure CN120342623A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and particularly to a collaborative signature method and system. Background Art
[0002] With the acceleration of the digitalization process, electronic signatures have been widely used in many fields such as financial transactions, legal document signing, and medical record management. To ensure the security and legality of electronic signatures, a reliable signature verification mechanism must be adopted to prevent forgery and tampering. As an emerging technical means, the collaborative signature method can significantly improve the security and reliability of the signature process through the collaboration between the user side and the server side, combined with various encryption algorithms and key management strategies.
[0003] Traditional electronic signature methods usually rely on a single device to complete the entire signature process, which results in the private key on the single device being easily obtained by attackers. Once the private key is leaked, all signatures based on that private key will lose their legal effect. Summary of the Invention
[0004] The technical problem to be solved by this application is to provide a collaborative signature method and system that can enhance the security of signatures. The specific solutions are as follows:
[0005] A collaborative signature method includes:
[0006] When receiving a signature request from a signature user, start a target applet to obtain the identification of the signature user;
[0007] Query the memory bank of the target applet according to the identification;
[0008] When the memory bank stores the ciphertext of the user private key corresponding to the identification, output a prompt message; the prompt message is used to prompt the signature user to input a signing key;
[0009] When receiving the signing key input by the signature user, decrypt the ciphertext of the user private key according to the signing key input by the signature user and the SM4 algorithm to obtain the plaintext of the user private key;
[0010] Use the plaintext of the user private key to pre-sign the data to be signed to obtain a password factor;
[0011] Send the password factor to the signature server so that the signature server synthesizes and signs the password factor based on the corresponding service private key to obtain a synthesized factor;
[0012] Obtain a signature value according to the synthesized factor.
[0013] Optionally, the process of storing the ciphertext of the user's private key corresponding to the identification identifier in the memory bank includes:
[0014] Obtain the target factors of the signing user, where the target factors include user information, device information, and a random number;
[0015] Process the target factors using the SM3 algorithm and the elliptic curve algorithm to obtain the plaintext of the user's private key;
[0016] Encrypt the plaintext of the user's private key according to the signing key set by the signing user and the SM4 algorithm to obtain the ciphertext of the user's private key;
[0017] Associate and store the identification identifier of the signing user with the ciphertext of the user's private key in the memory bank.
[0018] Optionally, the process of processing the target factors using the SM3 algorithm and the elliptic curve algorithm to obtain the plaintext of the user's private key includes:
[0019] Calculate the target factors of the signing user using the SM3 algorithm to obtain the hash value corresponding to the target factors;
[0020] Calculate the hash value using the elliptic curve algorithm to obtain the plaintext of the user's private key.
[0021] Optionally, the process of pre-signing the data to be signed using the plaintext of the user's private key to obtain a password factor includes:
[0022] Generate a dynamic guidance interface through the applet and collect the user's touch trajectory to generate a random parameter;
[0023] Input the random parameter and the data to be signed into a chaotic function for confusion processing to generate extended data;
[0024] Perform a signature operation on the extended data using the plaintext of the user's key and the elliptic curve algorithm to obtain an intermediate value, and map the intermediate value to coordinate components;
[0025] Use the coordinate components as the password factor.
[0026] Optionally, the process of obtaining the signature value according to the composite factor includes:
[0027] Encode the password factor and the composite factor to obtain encoded data;
[0028] Perform a conversion process on the encoded data to obtain an initial signature value;
[0029] Generate a signature value according to the initial signature value, the current timestamp, and the certificate identification information.
[0030] A collaborative signature system, comprising:
[0031] A receiving unit, configured to start a target applet to obtain an identification identifier of the signature user when receiving a signature request from the signature user;
[0032] A query unit, configured to query a memory bank of the target applet according to the identification identifier;
[0033] An output unit, configured to output a prompt message when a user private key ciphertext corresponding to the identification identifier is stored in the memory bank; the prompt message is used to prompt the signature user to input a signing key;
[0034] A decryption unit, configured to decrypt the user private key ciphertext according to the signing key input by the signature user and the SM4 algorithm to obtain a user private key plaintext when receiving the signing key input by the signature user;
[0035] A pre-signature unit, configured to perform pre-signature on data to be signed by using the user private key plaintext to obtain a password factor;
[0036] A composite signature unit, configured to send the password factor to a signature server, so that the signature server performs composite signature on the password factor based on a corresponding service private key to obtain a composite factor;
[0037] An execution unit, configured to obtain a signature value according to the composite factor.
[0038] For the above system, optionally, the output unit includes:
[0039] An acquisition subunit, configured to acquire a target factor of the signature user, where the target factor includes user information, device information, and a random number;
[0040] A processing subunit, configured to process the target factor by using the SM3 algorithm and the elliptic curve algorithm to obtain a user private key plaintext;
[0041] A first encryption subunit, configured to encrypt the user private key plaintext according to the signing key set by the signature user and the SM4 algorithm to obtain a user private key ciphertext;
[0042] A storage subunit, configured to associate and store the identification identifier of the signature user and the user private key ciphertext in the memory bank.
[0043] For the above system, optionally, the acquisition subunit includes:
[0044] A first calculation module, configured to calculate a target factor of the signing user by using the SM3 algorithm to obtain a hash value corresponding to the target factor;
[0045] A second calculation module, configured to calculate the hash value by using an elliptic curve algorithm to obtain a plaintext of the user private key.
[0046] For the above system, optionally, the pre-signature unit includes:
[0047] An acquisition subunit, configured to generate a dynamic guidance interface through the applet and acquire a user touch trajectory to generate a random parameter;
[0048] A first generation subunit, configured to input the random parameter and the data to be signed into a chaotic function for confusion processing to generate extended data;
[0049] A first calculation subunit, configured to perform a signature operation on the extended data by using the plaintext of the user key and an elliptic curve algorithm to obtain an intermediate value, and map the intermediate value to coordinate components;
[0050] An execution subunit, configured to use the coordinate components as password factors.
[0051] For the above system, optionally, the execution unit includes:
[0052] An encoding subunit, configured to encode the components in the password factor and the synthesis factor to obtain encoded data;
[0053] A conversion subunit, configured to perform conversion processing on the encoded data to obtain an initial signature value;
[0054] A second generation subunit, configured to generate a signature value according to the initial signature value, the current timestamp, and the certificate identification information.
[0055] Based on the collaborative signature method and system provided by the present application embodiment above, when a signature request from a signature user is received, a target applet is started to obtain the identification identifier of the signature user; the memory bank of the target applet is queried according to the identification identifier; when the user private key ciphertext corresponding to the identification identifier is stored in the memory bank, a prompt message is output; the prompt message is used to prompt the signature user to input a signing key; when the signing key input by the signature user is received, the user private key ciphertext is decrypted according to the signing key input by the signature user and the SM4 algorithm to obtain the user private key plaintext; the user private key plaintext is used to pre-sign the data to be signed to obtain a password factor; the password factor is sent to a signature server, so that the signature server performs a combined signature on the password factor based on the corresponding service private key to obtain a combined factor; a signature value is obtained according to the combined factor. Applying the method provided by the embodiments of the present application can improve the security of signatures. Description of the Drawings
[0056] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained according to the provided drawings.
[0057] Figure 1 It is a flowchart of a collaborative signature method provided by the present application;
[0058] Figure 2 It is a flowchart of the process of storing the user private key ciphertext corresponding to the identification identifier in the memory bank provided by the present application;
[0059] Figure 3 It is a flowchart of the process of obtaining a password factor provided by the present application;
[0060] Figure 4 It is a flowchart of a collaborative signature method provided by the present application;
[0061] Figure 5 It is a schematic structural diagram of a collaborative signature system provided by the present application. Detailed Embodiments
[0062] The following will clearly and completely describe the technical solutions in the embodiments of the present application with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present application without creative efforts shall fall within the protection scope of the present application.
[0063] In the present application, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, such that a process, method, article or device comprising a series of elements not only includes those elements but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the phrase "comprising a..." does not exclude the presence of additional identical elements in the process, method, article or device comprising the element.
[0064] Traditional electronic signature methods usually rely on a single device to complete the entire signature process, which results in the private key on the single device being easily obtained by attackers. Once the private key is leaked, all signatures based on the private key will lose their legal effect. Moreover, users can only perform signature operations on specific devices, and they need to reconfigure the signature environment after changing devices, increasing the user's usage cost.
[0065] Based on this, the embodiments of the present invention provide a collaborative signature method applied to an electronic device. The method flowchart of the method is as Figure 1 shown and specifically includes:
[0066] S101: When receiving a signature request from a signature user, start a target applet to obtain the identification of the signature user.
[0067] In this embodiment, the target applet can be an applet in any application program platform pre-installed on the electronic device, and the electronic device is equipped with a TEE secure environment.
[0068] Optionally, the identification can be generated according to the user's name, ID number, face information, etc.
[0069] S102: Query the memory bank of the target applet according to the identification.
[0070] In this embodiment, the memory bank of the target applet can be used to store the identification of the user and the corresponding user private key ciphertext.
[0071] S103: When the user private key ciphertext corresponding to the identification is stored in the memory bank, output a prompt message; the prompt message is used to prompt the signature user to input the signing key.
[0072] In this embodiment, a prompt message can be output on the usage interface of the target mini-program. The prompt message can prompt the user to input a signing key in a specified area, and the signing key can be at least one of a password string, gesture information, etc. set by the user.
[0073] In an embodiment provided by the present application, based on the above solution, optionally, the process of storing the user private key ciphertext corresponding to the identification identifier into the memory bank is as Figure 2 shown and includes:
[0074] S201: Obtain the target factors of the signing user, where the target factors include user information, device information, and a random number.
[0075] In this embodiment, the user information, device information, and random number can be concatenated in a set manner to form the target factors.
[0076] S202: Process the target factors using the SM3 algorithm and the elliptic curve algorithm to obtain the plaintext of the user private key.
[0077] In an embodiment provided by the present application, based on the above solution, optionally, the process of processing the target factors using the SM3 algorithm and the elliptic curve algorithm to obtain the plaintext of the user private key includes:
[0078] Calculate the target factors of the signing user using the SM3 algorithm to obtain the hash value corresponding to the target factors;
[0079] Calculate the hash value using the elliptic curve algorithm to obtain the plaintext of the user private key.
[0080] In this embodiment, perform two SM3 iterative operations on the concatenated target factors:
[0081] H1 = SM3(target factors || 0x00)
[0082] H2 = SM3(H1 || 0x01)
[0083] where H1 is the hash value obtained by performing SM3 for the first time, and H2 is the hash value obtained by performing SM3 for the second time.
[0084] Optionally, use the 256-bit hash value H2 corresponding to the obtained target factors as the input parameter of the elliptic curve algorithm.
[0085] In this embodiment, the hash value H2 can be mapped to the elliptic curve private key d to obtain the plaintext of the user private key.
[0086] S203: Encrypt the plaintext of the user private key according to the signing secret key set by the signing user and the SM4 algorithm to obtain the ciphertext of the user private key.
[0087] In this embodiment, the obtained plaintext of the user private key is divided into several 128-bit data blocks (if the length is not an integer multiple of 128 bits, padding is performed so that the length of the padded data block is an integer multiple of 128 bits).
[0088] Optionally, use the signing secret key provided by the user as the key of the SM4 algorithm to encrypt each data block. Specifically, the data block can be transformed, and the same key but different sub-keys are used in each round. Finally, the encrypted data block is output. After encryption in all rounds, the ciphertext form of the user private key is obtained.
[0089] In some embodiments, first, use the password-based key derivation function (PBKDF2), combined with the device binding salt value obtained from the trusted execution environment (TEE), to expand the signing secret key set by the user into a 128-bit SM4 encryption key; then, based on the SM4 algorithm, use the initial vector (IV) generated by true random numbers to perform block encryption on the plaintext of the user private key, and pad the data during the encryption process to ensure block alignment; at the same time, adopt a hierarchical integrity protection strategy, generate a ciphertext verification code through the SM3 algorithm, and encapsulate the IV, ciphertext, and verification code into a security data packet according to a predefined structure; finally, use the sharding storage technology to split the ciphertext into a dual fragment of the cloud and the device side, and combine the electronic seal signature of the hardware security chip to build a protection system against physical extraction and tampering.
[0090] S204: Associatively store the identification identifier of the signing user and the ciphertext of the user private key in the memory bank.
[0091] S104: When receiving the signing secret key input by the signing user, decrypt the ciphertext of the user private key according to the signing secret key input by the signing user and the SM4 algorithm to obtain the plaintext of the user private key.
[0092] In this embodiment, a 128-bit SM4 decryption key can be generated using the PBKDF2-HMAC-SM3 key derivation algorithm based on the signing secret key input by the user and the device binding salt value pre-stored in the trusted execution environment (TEE). The salt value binds the device hardware through the physical unclonable function (PUF) of the security chip to ensure that the key derivation result is exactly the same as that in the encryption stage. Subsequently, the ciphertext packet structure is parsed to separate the initial vector (IV), the encrypted data body, and the HMAC-SM3 check code. The derived SM4 key is used to perform block decryption operations in CBC mode, decrypting each block of SM4 and XORing with the previous ciphertext block to restore the plaintext data. After decryption, the same hierarchical verification mechanism as in the encryption stage is adopted. The ciphertext check code is recalculated using the independently derived HMAC key and compared with the stored value to verify the integrity and authenticity of the data. Finally, the plaintext of the user private key in the SM2 standard is obtained.
[0093] S105: Pre-sign the data to be signed using the plaintext of the user private key to obtain a password factor.
[0094] In an embodiment provided by the present application, based on the above solution, optionally, the process of pre-signing the data to be signed using the plaintext of the user private key to obtain a password factor is as Figure 3 shown and includes:
[0095] S301: Generate a dynamic guidance interface through the applet, and collect the user's touch trajectory to generate a random parameter.
[0096] In this embodiment, by rendering a dynamic grid interface resistant to screenshotting, the spatio-temporal feature vector of the user's touch trajectory (including the coordinate sequence (xi, yi, ti), the pressure change entropy Hp, and the acceleration sensor noise) is collected at a sampling rate of 100 Hz, and a 256-bit random parameter R is generated by fusing using the SM3 algorithm, realizing the strong coupling of biological behavior characteristics and the device physical entropy source. xi is the horizontal axis coordinate, yi is the vertical axis coordinate, and ti is the time axis coordinate.
[0097] S302: Input the random parameter and the data to be signed into a chaotic function for confusion processing to generate extended data.
[0098] In this embodiment, a Logistic-Tent composite chaotic system is constructed. After the random parameter R and the data to be signed D are concatenated in the format of D′ = D || R, the extended data E is generated through 8 rounds of chaotic permutation iteration.
[0099] Optionally, the chaotic mapping equation is:
[0100] x n+1 = (μx n (1 - x n ) + λy n) mod 1
[0101] y n+1 = (r * min(y n , 1 - y n ) + γy n ) mod 1
[0102] where x n represents the first - dimensional state variable of the system at the n - th iteration (value range: [0, 1)), and y n is the second - dimensional state variable of the system at the n - th iteration; the hyperparameters are set as μ = 3.99, λ = 0.25, r = 1.92, γ = 0.31, so that the output data has the diffusion characteristics against quantum analysis.
[0103] S303: Use the cleartext of the user key and the elliptic curve algorithm to perform a signature operation on the extended data to obtain an intermediate value, and map the intermediate value to coordinate components.
[0104] In this embodiment, use the user's private key d A to execute the SM2 signature algorithm on the extended data E, and calculate the intermediate values (r, spart).
[0105] where r = (kG)x mod n; spart = [(1 + d A ) - 1(k - rd A )] mod n / 2, k is a temporary private key, G is the elliptic curve base point, and n is the elliptic curve order.
[0106] Map (r, spart) to the elliptic curve coordinate components P = (r mod p, spart mod p).
[0107] S304: Use the coordinate components as cryptographic factors.
[0108] In this embodiment, the elliptic curve coordinate components P are used as cryptographic factors.
[0109] S106: Send the cryptographic factors to the signature server, so that the signature server synthesizes and signs the cryptographic factors based on the corresponding service private key to obtain a synthetic factor.
[0110] In this embodiment, after receiving the cryptographic factors (including the pre - signed elliptic curve coordinate components P = (Px, Py)) transmitted by the client, the signature server generates a synthetic factor based on the SM2 algorithm through the following steps: The server calls the service private key d B stored in the hardware cryptographic machine and performs the elliptic curve point - multiplication operation Q = d B·P, where P is the coordinate point output by the client's pre-signature and satisfies P ∈ E(Fp), and E is the SM2 standard elliptic curve defined over the prime field Fp; extract the abscissa Qx of the operation result point Q, and perform modulo n addition operation (n is the order of the elliptic curve) on it and the pre-signature intermediate value spart to obtain the composite value sfinal = (spart + Qx) mod n; finally, encode the original pre-signature parameter r and sfinal into a composite factor according to the ASN.1 SEQUENCE structure, specifically as follows:
[0111] Synthesis-Factor::=SEQUENCE{r INTEGER,sfinal INTEGER}。
[0112] In this embodiment, after obtaining the composite factor, it is returned to the client through a secure channel.
[0113] S107: Obtain the signature value according to the composite factor.
[0114] In an embodiment provided by the present application, based on the above solution, optionally, the obtaining the signature value according to the composite factor includes:
[0115] Encode the cryptographic factor and the composite factor to obtain encoded data;
[0116] Perform conversion processing on the encoded data to obtain the initial signature value;
[0117] Generate the signature value according to the initial signature value, the current timestamp, and the certificate identification information.
[0118] In this embodiment, the cryptographic factor (including the elliptic curve coordinate components (r, spart)) generated by the client's pre-signature and the composite factor (r, sfinal) returned by the server are encoded into a composite data structure in ASN.1 DER format, and integrity protection is implemented on the encoded data based on the HMAC-SM3 check code derived from the session key; perform the SM3 hash operation on the composite data to generate the digest value H3, generate the deterministic signature parameter k, and generate the initial signature value (rinit, sinit) through the elliptic curve point multiplication operation; further call the timestamp service to obtain the timestamp TS, and extract the X.509 certificate identification CID, and construct a structure including the algorithm identification, timestamp, certificate identification, and hierarchical signature body according to the specification; finally, bind the structure to the original data digest through double SM3 iterative hashing, and output the signature value encoded in Base64Url.
[0119] A collaborative signature method provided by this application ensures a high level of security in the signature process by combining the collaboration between the client and the server and using multiple encryption algorithms (such as SM3, elliptic curve algorithm, and SM4), effectively preventing the risks of private key leakage and signature forgery. This method not only verifies the authenticity of the identity through online face verification when the user first uses it, but also further enhances security by using signing keys in subsequent operations. Through key splitting technology and collaborative digital signature technology, the client and the server independently generate and store key components, thus ensuring the authenticity and non-repudiation of the signature. In addition, this method also improves the flexibility and convenience of users, allowing users to perform signature operations on different devices and supporting a security recovery mechanism for key modification and loss, significantly enhancing the user experience. Therefore, the collaborative signature method proposed in this application not only ensures high security but also enhances the flexibility and user-friendliness of the system, having important practical application value.
[0120] See Figure 4 , which is a flowchart of a collaborative signature process provided by an embodiment of this application. When the user first uses it, they need to complete online face verification through their name and ID number to verify the authenticity of their identity. The applet then combines the user information, device information, and random number into a target factor, uses the SM3 algorithm and elliptic curve cryptography algorithm to generate the user's private key and the backend factor, and requests the backend to issue and encrypt and store the certificate. Then, the user is guided to preset a signing key, which is required to be at least 8 digits in length and contain numbers, uppercase and lowercase letters, and special characters. Then, this key is used as the encryption key to encrypt the plaintext of the user's private key through the SM4 symmetric encryption algorithm and bind it to the user's unique identification information and store it in the applet memory to ensure data security. If the memory is lost, the user needs to complete the above process again. The user memory module establishes an identification identifier by obtaining the user's unique openId combined with the real-name authentication information and stores it in the key-value form; when reading, the same method is used to decrypt the private key ciphertext for the pre-signature process without displaying or storing the plaintext. The user can choose to modify the key but cannot retrieve the forgotten key. When changing devices, the key needs to be reset. If the device is lost and the key is leaked, the user can request the server to cancel the relevant certificate through the system cancellation function. During the collaborative signature process, key splitting technology and collaborative digital signature technology are used, and the client and the server independently generate and store key components and cooperate to complete the complete signature during the signature process. The client first uses the private key to pre-sign the input text to obtain a password factor, sends it to the server to synthesize the signature, and then returns the result to the client to complete the final signature.
[0121] See Figure 5 , which is a schematic structural diagram of a collaborative signature method system provided by an embodiment of this application. The system includes:
[0122] A receiving unit 501, configured to start a target mini-program to obtain an identification identifier of the signing user when receiving a signature request of the signing user;
[0123] A query unit 502, configured to query a memory bank of the target mini-program according to the identification identifier;
[0124] An output unit 503, configured to output a prompt message when a user private key ciphertext corresponding to the identification identifier is stored in the memory bank; the prompt message is used to prompt the signing user to input a signing key;
[0125] A decryption unit 504, configured to decrypt the user private key ciphertext according to the signing key input by the signing user and the SM4 algorithm to obtain a user private key plaintext when receiving the signing key input by the signing user;
[0126] A pre-signature unit 505, configured to perform pre-signature on data to be signed by using the user private key plaintext to obtain a password factor;
[0127] A composite signature unit 506, configured to send the password factor to a signature server so that the signature server performs composite signature on the password factor based on a corresponding service private key to obtain a composite factor;
[0128] An execution unit 507, configured to obtain a signature value according to the composite factor.
[0129] In an embodiment provided by the present application, based on the above solution, optionally, the output unit 503 includes:
[0130] An acquisition subunit, configured to acquire a target factor of the signing user, where the target factor includes user information, device information, and a random number;
[0131] A processing subunit, configured to process the target factor by using the SM3 algorithm and the elliptic curve algorithm to obtain a user private key plaintext;
[0132] A first encryption subunit, configured to encrypt the user private key plaintext according to the signing key set by the signing user and the SM4 algorithm to obtain a user private key ciphertext;
[0133] A storage subunit, configured to associate and store the identification identifier of the signing user and the user private key ciphertext in the memory bank.
[0134] In an embodiment provided by the present application, based on the above solution, optionally, the acquisition subunit includes:
[0135] The first calculation module is used to calculate the target factor of the signing user by using the SM3 algorithm to obtain the hash value corresponding to the target factor;
[0136] The second calculation module is used to calculate the hash value by using the elliptic curve algorithm to obtain the plaintext of the user private key.
[0137] In an embodiment provided by the present application, based on the above solution, optionally, the pre-signature unit 505 includes:
[0138] The acquisition subunit is used to generate a dynamic guidance interface through the applet and collect the user touch trajectory to generate random parameters;
[0139] The first generation subunit is used to input the random parameters and the data to be signed into the chaotic function for confusion processing to generate extended data;
[0140] The first calculation subunit is used to perform a signature operation on the extended data by using the plaintext of the user key and the elliptic curve algorithm to obtain an intermediate value, and map the intermediate value to coordinate components;
[0141] The execution subunit is used to use the coordinate components as password factors.
[0142] In an embodiment provided by the present application, based on the above solution, optionally, the execution unit 507 includes:
[0143] The encoding subunit is used to encode the components in the password factor and the synthesis factor to obtain encoded data;
[0144] The conversion subunit is used to perform conversion processing on the encoded data to obtain an initial signature value;
[0145] The second generation subunit is used to generate a signature value according to the initial signature value, the current timestamp, and the certificate identification information.
[0146] It should be noted that the embodiments in this specification are all described in a progressive manner. Each embodiment focuses on the differences from other embodiments. The same or similar parts among the embodiments can be referred to each other.
[0147] Finally, it should also be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations.
[0148] For the convenience of description, when describing the above system, various units are described separately according to their functions. Of course, when implementing the present application, the functions of each unit can be implemented in the same or multiple software and / or hardware.
[0149] Through the description of the above embodiments, those skilled in the art can clearly understand that the present application can be implemented by means of software plus a necessary general hardware platform. Based on such an understanding, the technical solution of the present application, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in various embodiments or some parts of the embodiments of the present application.
[0150] The above has introduced in detail a collaborative signature method provided by the present application. Specific examples are used in this article to elaborate on the principle and implementation manner of the present application. The description of the above embodiments is only used to help understand the method and its core idea of the present application; at the same time, for those of ordinary skill in the art, according to the idea of the present application, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to the present application.
Claims
1. A collaborative signature method, characterized in that, Including: When receiving a signature request from a signed user, start the target applet to obtain the identification of the signed user; Query the memory bank of the target applet according to the identification; When the memory bank stores the ciphertext of the user private key corresponding to the identification, output a prompt message; The prompt message is used to prompt the signed user to input a signing key; When receiving the signing key input by the signed user, decrypt the ciphertext of the user private key according to the signing key input by the signed user and the SM4 algorithm to obtain the plaintext of the user private key; Use the plaintext of the user private key to pre-sign the data to be signed to obtain a password factor; Send the password factor to the signature server, so that the signature server synthesizes and signs the password factor based on the corresponding service private key to obtain a synthesized factor; Obtain a signature value according to the synthesized factor.
2. The method according to claim 1, wherein The process of storing the ciphertext of the user private key corresponding to the identification in the memory bank includes: Obtain the target factor of the signed user, where the target factor includes user information, device information, and a random number; Process the target factor using the SM3 algorithm and the elliptic curve algorithm to obtain the plaintext of the user private key; Encrypt the plaintext of the user private key according to the signing key set by the signed user and the SM4 algorithm to obtain the ciphertext of the user private key; Associate and store the identification of the signed user and the ciphertext of the user private key in the memory bank.
3. The method according to claim 2, wherein The process of processing the target factor using the SM3 algorithm and the elliptic curve algorithm to obtain the plaintext of the user private key includes: Calculate the target factor of the signed user using the SM3 algorithm to obtain the hash value corresponding to the target factor; Calculate the hash value using the elliptic curve algorithm to obtain the plaintext of the user private key.
4. The method according to claim 1, wherein The process of using the plaintext of the user private key to pre-sign the data to be signed to obtain a password factor includes: Generate a dynamic guidance interface through the applet, and collect the user touch trajectory to generate a random parameter; Input the random parameter and the data to be signed into a chaotic function for confusion processing to generate extended data; Use the plaintext of the user key and the elliptic curve algorithm to perform a signature operation on the extended data to obtain an intermediate value, and map the intermediate value to coordinate components; Use the coordinate components as the password factor.
5. The method according to claim 1, characterized in that, The process of obtaining a signature value according to the synthesized factor includes: Encode the password factor and the synthesized factor to obtain encoded data; Perform a conversion process on the encoded data to obtain an initial signature value; Generate a signature value according to the initial signature value, the current timestamp, and the certificate identification information.
6. A collaborative signature system, characterized in that, Including: A receiving unit, configured to start the target applet when receiving a signature request from a signed user, so as to obtain the identification of the signed user; A query unit, configured to query the memory bank of the target applet according to the identification; An output unit, configured to output a prompt message when the memory bank stores the ciphertext of the user private key corresponding to the identification; The prompt message is used to prompt the signed user to input a signing key; A decryption unit, configured to decrypt the user private key ciphertext according to the signing key input by the signing user and the SM4 algorithm when receiving the signing key input by the signing user, so as to obtain the user private key plaintext; A pre-signature unit, configured to perform pre-signature on the data to be signed by using the user private key plaintext, so as to obtain a password factor; A synthetic signature unit, configured to send the password factor to a signature server, so that the signature server performs synthetic signature on the password factor based on the corresponding service private key to obtain a synthetic factor; An execution unit, configured to obtain a signature value according to the synthetic factor.
7. The system according to claim 6, wherein The output unit includes: An acquisition subunit, configured to acquire a target factor of the signing user, where the target factor includes user information, device information, and a random number; A processing subunit, configured to process the target factor by using the SM3 algorithm and the elliptic curve algorithm to obtain the user private key plaintext; A first encryption subunit, configured to encrypt the user private key plaintext according to the signing key set by the signing user and the SM4 algorithm to obtain a user private key ciphertext; A storage subunit, configured to associate and store the identification identifier of the signing user with the user private key ciphertext in the memory bank.
8. The system according to claim 7, wherein The acquisition subunit includes: A first calculation module, configured to calculate the target factor of the signing user by using the SM3 algorithm to obtain a hash value corresponding to the target factor; A second calculation module, configured to calculate the hash value by using the elliptic curve algorithm to obtain the user private key plaintext.
9. The system according to claim 6, wherein The pre-signature unit includes: An acquisition subunit, configured to generate a dynamic guidance interface through the applet and acquire a user touch track to generate a random parameter; A first generation subunit, configured to input the random parameter and the data to be signed into a chaotic function for confusion processing to generate extended data; A first calculation subunit, configured to perform a signature operation on the extended data by using the user key plaintext and the elliptic curve algorithm to obtain an intermediate value, and map the intermediate value to coordinate components; An execution subunit, configured to use the coordinate components as the password factor.
10. The system according to claim 6, characterized in that, The execution unit includes: An encoding subunit, configured to encode the components in the password factor and the synthetic factor to obtain encoded data; A conversion subunit, configured to perform conversion processing on the encoded data to obtain an initial signature value; A second generation subunit, configured to generate a signature value according to the initial signature value, the current timestamp, and the certificate identification information.
Citation Information
Cited By
SM2 collaborative signature, encryption and decryption system and method fusing anti-quantum characteristics
CN121283626A