Electronic seal management method and system
By employing zero-trust architecture, multi-party secure computation, and quantum key distribution technology, the security vulnerabilities in key management, signature computation, and access control in electronic seal technology are resolved. This enables distributed storage of private keys, verifiable signatures, and dynamic access control, thereby enhancing the security and resistance to quantum attacks of the electronic seal system.
Patent Information
- Application Number
- CN202510984405.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-17
- Publication Date
- 2025-11-04
- Estimated Expiration
- 2045-07-17
AI Technical Summary
Existing electronic seal technology has security vulnerabilities in key management, signature calculation, and access control. Private keys are vulnerable to attack, signature calculations are unverifiable, and access control is static and easily bypassed. It cannot cope with complex security environments, and key transmission faces the risk of being cracked by quantum computing.
The system employs a zero-trust architecture for authentication, utilizes multi-party secure computation technology to divide the private key into several key shares and store them in different secure nodes, uses a threshold signature mechanism to collaboratively compute signatures, combines a trusted execution environment and hardware encryption modules to manage key access, and uses quantum key distribution technology to ensure secure key transmission.
It improves the security of key storage, enhances the credibility of signature data and its resistance to quantum attacks, realizes dynamic permission management and flexible access control, and ensures the long-term security of the electronic seal system.
Smart Images

Figure CN120528598B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of electronic digital data processing, and particularly relates to a management and control method and system of an electronic seal. BACKGROUND
[0002] The core of the electronic seal is the signature and authentication of the file or transaction, ensuring the integrity, non-repudiation and tamper resistance of the data. However, the current security management of the electronic seal faces many challenges, and the traditional method has security vulnerabilities in key storage, signature calculation, access control, data transmission, etc., which limits the security, verifiability, and attack resistance of the electronic seal.
[0003] As a form of electronic signature, the electronic seal has the same legal effect as the traditional seal, however, the existing electronic seal technology still faces some challenges in security, privacy protection and key management. Especially in the aspects of private key storage, calculation process and digital signature generation, it is easy to be attacked, tampered or leaked, which affects the credibility and security of the electronic seal.
[0004] The core of the electronic seal is the private key, and the security of the private key directly determines the credibility of the electronic seal signature. At present, the main electronic seal key management methods mainly include: local storage mode, server hosting mode, and key encryption storage based on cryptography. The existing key management methods either rely on single-point storage, which is vulnerable to attack, or centralized management, which faces the risk of internal attack, and cannot support efficient distributed management and signature calculation while ensuring the high security of the key.
[0005] In the signature process of the electronic seal, the traditional method mainly adopts local calculation or remote calculation, and the existing signature calculation method of the electronic seal lacks verifiability, that is, even if the signature calculation is performed in a trusted environment, the external verification party cannot directly verify whether the calculation process is complete, correct and tamper-free.
[0006] The use of the electronic seal usually depends on identity authentication, access control and other security strategies, but the existing access control mechanism has certain limitations, the access control mechanism of the existing electronic seal is too static to cope with complex security environments, lacks a dynamic authorization mechanism based on real-time risk analysis, and is easy to be bypassed by persistent threats. SUMMARY
[0007] To solve the above technical problems, a kind of electronic seal management method is proposed, comprising, based on the identity verification of seal use request of zero trust architecture;Electronic seal private key is divided into several key shares using secret sharing algorithm using multi-party secure computation technology, and each key share is stored in different security node;The digital signature of electronic seal is generated by threshold signature mechanism collaborative calculation according to multi-party secure computation protocol by each security node;Electronic seal key access is managed in trusted execution environment, and global signature calculation is executed in hardware encryption module;Zero-knowledge proof algorithm is used to generate verifiable computation proof data for digital signature calculation process;Quantum communication link is established and transmission key is generated using quantum key distribution technology, and key transmission is managed.
[0008] As a preferred scheme of the electronic seal management method, wherein: the identity verification of seal use request includes, when the user requests to use the electronic seal, obtaining the identity information of the user, comparing the identity information with the pre-stored identity data, and judging whether the identity verification result meets the access policy requirement;Based on the identity verification result, micro-segment access control policy is applied to the user request, the access permission of the user is set in layers based on the current device environment, network source, access time information and pre-set access control rules of the user, and the operation range of the user that can access the electronic seal is limited;After executing micro-segment access control policy, the access behavior, operation type, access history and access frequency of the user are dynamically monitored, and fine-grained access control policy is applied, when detecting that the user has abnormal access behavior or the access behavior does not match the historical behavior mode, execute permission adjustment measures, the adjustment measures include reducing access level, increasing secondary identity verification, limiting access time or blocking access request.
[0009] As a preferred scheme of the electronic seal management method, wherein: the division into several key shares includes, defining a finite field, defining an elliptic curve on the finite field , obtaining the private key of the electronic seal , selecting base point on the elliptic curve , and calculating the public key point
[0010] corresponding to the private key, the calculation formula is:
[0011] wherein, represents the private key of the electronic seal, represents the elliptic curve defined on the finite field, represents the base point on the elliptic curve, represents the public key point;
[0012] Construct a function of degree in a finite field. Secret shared polynomial , is represented as:
[0013] ,
[0014] in, Denotes coefficients randomly generated within a finite field. To recover the private key threshold, Represents the secret-sharing polynomial used for key splitting;
[0015] right Each security node is assigned a unique identifier. And calculate the key share of each security node. , is represented as:
[0016] ,
[0017] in, Indicates the first A unique identifier for each secure node. Indicates the first Key share of each secure node;
[0018] via secure transmission channel Each secure node distributes key shares And stored in a trusted execution environment, each key share storage structure includes a key share. Node identifier and verification information ;
[0019] When at least When a security node responds to a key recovery request, it collects key shares from the selected node. And calculate the private key using the Lagrange interpolation formula. , is represented as:
[0020] ,
[0021] ,
[0022] in, This indicates the recovered key point. This indicates that the key recovery conditions are met. A set of secure node indexes Represents the Lagrange interpolation coefficients. Indicates key share The security node identifier to which it belongs An identifier representing the current secure node;
[0023] At the key point After recovery, a discrete logarithm calculation on an elliptic curve is performed to recover the private key, denoted as:
[0024] ,
[0025] wherein, denotes the private key of the electronic seal after recovery, denotes the key point recovered by interpolation, denotes the base point of the elliptic curve.
[0026] As a preferred scheme of the electronic seal management method described in the present application, wherein: the generation of the digital signature of the electronic seal comprises, under the condition that the signature threshold requirement is met, based on the recovered private key performing signature calculation, using the recovered private key calculating a local signature on the message data to be signed, the calculation of the local signature comprises obtaining the message data to be signed, performing hash calculation on the message data to generate a hash value, and using performing encryption operation to generate a local signature; each security node performs signature verification on the calculated local signature, the signature verification comprises calculating the signature verification result of the local signature based on the public key share, and judging whether the local signature meets the signature requirement based on the preset signature strategy; for the verified local signature, the distributed signature synthesis protocol is used to calculate the aggregated signature, the calculation of the aggregated signature comprises receiving the verified local signature, calculating the weighted value of each local signature based on the set weight factor, and performing signature aggregation operation on the weighted local signature to generate an aggregated signature; at least t security nodes perform signature encapsulation on the aggregated signature, the signature encapsulation comprises performing signature format conversion on the aggregated signature based on the global public key, and adding the timestamp, signature metadata and signature unique identification information to generate a global signature; the global signature is verified, the verification comprises parsing the global signature, extracting the timestamp, signature metadata and signature unique identification information, and calculating the signature integrity check value based on the global public key, if the calculation result matches the preset signature verification parameter, it is confirmed that the signature is valid, otherwise the use of the signature data is refused, and the signature invalid event is recorded.
[0027] As a preferred scheme of the electronic seal management method, when the global signature calculation request arrives, the storage state of the recovered private key is retrieved according to the key access strategy, and the key unpacking operation is performed; after the key unpacking is completed, the recovered private key is loaded into the controlled calculation area, and the use of the recovered private key is set with time limit and environmental constraint; after the recovered private key is loaded into the controlled calculation area, the signature calculation task is scheduled to the hardware encryption module, and the scheduling includes assigning task identification, setting task priority, and attaching temporary use credentials of the recovered private key to the task; after the global signature data is generated, the global signature data is encapsulated, the encapsulated data is stored in the signature storage area of the trusted execution environment, and an index table is established based on the signature index identification; when a new global signature calculation request arrives, the signature index table is called for comparison, and if there is the same index identification, the corresponding global signature data is returned.
[0028] As a preferred scheme of the electronic seal management method, the generation of verifiable calculation proof data includes, after the global signature data is generated, obtaining the input data, calculation steps and final signature result of the global signature calculation, and converting the calculation process into a calculation instance of zero-knowledge proof; a zero-knowledge proof circuit is constructed based on the calculation instance, and proof data is generated according to the zero-knowledge proof circuit, the proof data including calculation proof and verification public key; when the verifier requests to verify the global signature data, the calculation proof storage area is called to obtain the calculation proof corresponding to the global signature data, the calculation proof is verified based on the verification public key, if the verification is passed, the validity of the global signature data is confirmed, otherwise the use of the global signature data is refused.
[0029] As a preferred scheme of the electronic seal management method, the establishment of quantum communication link and the generation of transmission key include, the establishment of quantum communication link with the target receiver, the quantum communication link is based on quantum key distribution protocol, and the photonic bit stream is transmitted between the sending end and the receiving end to generate shared key; based on the quantum bit measurement result, the transmission key is generated between the trusted execution environment and the target receiver; when the target receiver successfully receives the key, it is verified whether the shared key calculated by the receiver is consistent with the locally stored transmission key, if consistent, it is confirmed that the key transmission is successful, and the transmission record is stored, if inconsistent, the quantum key distribution process is triggered again, and the abnormal transmission event is recorded.
[0030] Another object of the present application is to provide an electronic seal management system, which solves the security risks in key management, signature calculation, access control and key transmission of existing electronic seal technology. Key management relies on single-point storage or centralized hosting, which is vulnerable to device loss, internal attacks or key leakage, and lacks distributed security protection. The signature calculation process is unverifiable, and the verifier cannot confirm whether the signature is generated truly, which poses risks of fake computing environment and tampered signature. The access control mechanism is static and difficult to adjust permissions dynamically according to user behavior and environment, which is vulnerable to identity impersonation and advanced attacks. Key transmission relies on traditional encryption, which faces the risk of quantum computing cracking and cannot ensure long-term security. Therefore, the existing methods still have technical limitations in key security, signature credibility, access flexibility and anti-quantum attack capability, which are difficult to meet the needs of high-security applications.
[0031] As a preferred scheme of the electronic seal management system, the system comprises an identity verification module for verifying the identity of a seal use request based on a zero-trust architecture; a key splitting module for splitting the private key of the electronic seal into a plurality of key shares using a secret sharing algorithm by adopting multi-party secure computation technology, and storing each key share in a different secure node; a signature calculation module for generating a digital signature of the electronic seal by each secure node through a threshold signature mechanism according to a multi-party secure computation protocol; a key management module for managing electronic seal key access in a trusted execution environment and performing global signature calculation in a hardware encryption module; a calculation proof module for generating corresponding verifiable calculation proof data for the digital signature calculation process using a zero-knowledge proof algorithm; and a key transmission module for establishing a quantum communication link and generating a transmission key using quantum key distribution technology to manage key transmission.
[0032] A computer device comprises a memory and a processor, the memory stores a computer program, and the processor implements the steps of the electronic seal management method when executing the computer program.
[0033] A computer readable storage medium stores a computer program, and the computer program implements the steps of the electronic seal management method when executed by a processor.
[0034] The beneficial effects of the present application are: by means of multi-party secure computation and secret sharing technology, the private key of the electronic seal is divided and stored in multiple secure nodes, so that any single node cannot independently recover the private key, thereby eliminating the risk of single key leakage and improving the security of key storage. By using zero-knowledge proof technology, a verifiable computation proof is generated without exposing the private key, so that an external verifier can directly verify the correctness of the signature calculation, thereby enhancing the credibility of the signature data. By means of a trusted execution environment, controlled access to the key is realized, and the use of the private key is allowed only when the security policy is met, and in combination with a dynamic access control policy, the key permissions are adjusted in real time according to user behavior, device environment and other factors, thereby improving the security and flexibility of the electronic seal. By using quantum key distribution technology to establish a secure communication link, it is ensured that the key cannot be eavesdropped or tampered with during transmission, thereby enhancing the anti-quantum attack capability and long-term security of the electronic seal system. BRIEF DESCRIPTION OF DRAWINGS
[0035] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings needed in the embodiment description will be briefly introduced as follows. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.
[0036] Figure 1 The overall flowchart of the electronic seal management method provided by an embodiment of the present application is shown in the figure. DETAILED DESCRIPTION
[0037] In order to make the above-mentioned purposes, features and advantages of the present application more apparent and easy to understand, the specific embodiments of the present application will be described in detail below with reference to the drawings in the specification. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor should be within the scope of protection of the present application.
[0038] Embodiment 1, refer to Figure 1 For the first embodiment of the present application, the embodiment provides an electronic seal management method, which comprises:
[0039] Step S1: identity verification of seal use request based on zero trust architecture.
[0040] In step S1, identity verification of seal use request comprises: when a user requests to use an electronic seal, obtaining identity information of the user, comparing the identity information with pre-stored identity data, and judging whether the identity verification result meets the access policy requirement;
[0041] The identity information includes password information, fingerprint information, face recognition information, device information, geographic location information and access time information, wherein the password information is verified by comparing the password input by the user with the hash value stored by the server, the fingerprint information and the face recognition information are verified by extracting the characteristic value through a biological recognition algorithm and matching the pre-stored biological feature template, the device information is verified by detecting the device identification code, the operating system version and the device fingerprint of the terminal device, the geographic location information is verified by comparing the base station positioning, GPS or Wi-Fi location data, and the access time information is verified by detecting whether the access time of the user meets the preset strategy, and based on the multi-factor identity verification mechanism, the identity information is weighted and calculated to generate an identity verification score, and if the identity verification score reaches a preset threshold, it is determined that the identity verification is passed, and the identity verification result is taken as an input parameter of a subsequent access control strategy.
[0042] Based on the identity verification result, a micro-segmented access control strategy is applied to the user request, the access permission of the user is set in layers based on the current device environment, network source, access time information and preset access control rules of the user, and the operation range of the electronic seal accessible by the user is limited, wherein the access permission includes signing permission, viewing permission and management permission, the signing permission allows the user to use the electronic seal for digital signature, the viewing permission allows the user to query the signature record but cannot perform the signature operation, and the management permission allows the user to adjust the use strategy of the electronic seal.
[0043] After the micro-segmented access control strategy is executed, the access behavior, operation type, access history and access frequency of the user are dynamically monitored, a fine-grained access control strategy is applied, and the use permission of the electronic seal of the user is adjusted in real time, wherein the access behavior monitoring includes detecting whether the user frequently initiates a signature request in a short time, whether the user attempts to access a function beyond the authorized range, and whether the user logs in using an abnormal device, the operation type analysis includes judging whether the current operation of the user is signature, authorization, query or revocation, the access history analysis includes comparing the historical access behavior mode of the user, the access frequency analysis includes calculating the access times and request interval time in a unit time, and when it is detected that the user has abnormal access behavior or the access behavior does not match the historical behavior mode, an adjustment measure is performed, and the adjustment measure includes reducing the access level, increasing the secondary identity verification, limiting the access time or blocking the access request.
[0044] Step S2: using multi-party secure computing technology, the private key of the electronic seal is divided into a plurality of key shares by using a secret sharing algorithm, and each key share is stored in a different secure node.
[0045] In step S2, the division into a plurality of key shares includes defining a finite field, defining an elliptic curve on the finite field Obtain the private key for the electronic seal. In elliptic curves Selecting a base point And calculate the public key point corresponding to the private key. The calculation formula is:
[0046] ,
[0047] in, The private key representing the electronic seal is an integer over a finite field; This represents an elliptic curve defined on a finite field. This represents the base point on the elliptic curve, and the order of the base point is . ,satisfy ( (for the point at infinity) Represents the public key point, and represents the private key. The mapping points on the elliptic curve serve as input for subsequent secret sharing;
[0048] Construct a function of degree in a finite field. Secret shared polynomial , is represented as:
[0049] ,
[0050] in, Denotes the coefficients randomly generated within a finite field, such that the private key... Cannot be directly accessed by a single node
[0051] Receive and obtain, To recover the private key threshold, it means that at least... Only by obtaining a share of the key can the private key be recovered; Represents the secret-sharing polynomial used for key splitting;
[0052] right Each security node is assigned a unique identifier. And calculate the key share of each security node. , is represented as:
[0053] ,
[0054] in, Indicates the first Each secure node has a unique identifier belonging to a finite field, and each node's... They are all different to ensure the uniqueness of key shares; For the first Key shares of each security node, table
[0055] Show private key The sub-key after polynomial calculation is only held by the node;
[0056] Distribute key shares to secure nodes through a secure transmission channel and store them in a trusted execution environment or hardware security module, each key share storage structure including a key share , a node identifier and verification information ; The integrity verification value of the key share is calculated by a hash function , which is used to verify whether the key share has been tampered with during key reconstruction.
[0057] When at least secure nodes respond to the key recovery request, collect key shares from selected nodes and calculate the private key using the Lagrange interpolation formula, which is represented as:
[0058] ,
[0059] ,
[0060] wherein represents the recovered key point, represents the set of secure node indices that meet the key recovery condition, represents the Lagrange interpolation coefficient, represents the secure node identifier to which the key share belongs, represents the identifier of the current secure node.
[0061] After the key point is recovered, perform discrete logarithm calculation on the elliptic curve to recover the private key, which is represented as:
[0062] ,
[0063] wherein represents the private key of the recovered electronic seal, represents the key point recovered by interpolation, represents the base point of the elliptic curve.
[0064] When the elliptic curve adopts a specific coordinate system (Edwards curve or Weierstrass form curve) and the base point has a reversible abscissa, the numerical calculation expansion formula can be used:
[0065] ,
[0066] wherein, denotes a key point denotes the x-coordinate on an elliptic curve, denotes a base point denotes the x-coordinate on an elliptic curve, denotes an elliptic curve base point the order, ensuring that the computation is performed within a finite group.
[0067] This method is only applicable to specific elliptic curve types, such as: Edwards curve (x-coordinate ratio can be directly calculated); Weierstrass form curve (need to ensure that the x-coordinate is a non-zero invertible element).
[0068] Step S3: Each security node generates a digital signature of the electronic seal through a threshold signature mechanism based on a multi-party secure computation protocol.
[0069] In step S3, generating a digital signature of the electronic seal includes, under the condition of meeting the signature threshold requirement, based on the recovered private key performing signature calculation, using the recovered private key to calculate a local signature on the message data to be signed, the calculation of the local signature includes obtaining the message data to be signed, performing hash calculation on the message data to generate a hash value, and using to perform encryption operation to generate a local signature;
[0070] Each security node performs signature verification on the calculated local signature, which includes calculating the signature verification result of the local signature based on the public key share, and judging whether the local signature meets the signature requirement based on the preset signature strategy;
[0071] For the verified local signature, use the distributed signature synthesis protocol to calculate the aggregated signature, which includes receiving the verified local signature, calculating the weighted value of each local signature based on the set weight factor, and performing signature aggregation operation on the weighted local signature to generate the aggregated signature;
[0072] At least t security nodes perform signature encapsulation on the aggregated signature, which includes performing signature format conversion on the aggregated signature based on the global public key, and adding time stamp, signature metadata and signature unique identification information to generate global signature;
[0073] Verify the global signature, which includes parsing the global signature, extracting the time stamp, signature metadata and signature unique identification information, and calculating the signature integrity check value based on the global public key, if the calculation result matches the preset signature verification parameter, the signature is valid, otherwise, the use of the signature data is rejected, and the signature invalid event is recorded.
[0074] In this embodiment, the signature calculation process requires at least t secure nodes to participate, which is set by the system and can be dynamically adjusted to ensure the security and availability of signature calculation. If the number of currently available secure nodes is less than t, the signature calculation request is rejected, and an error handling mechanism is triggered.
[0075] In this embodiment, a public key share verification mechanism is used to verify the local signature, ensuring that the signature data is generated by a legitimate secure node. By calculating the matching degree of the local signature σi and the corresponding public key share Pi, if the verification fails, the local signature is discarded, and the node is prohibited from participating in the subsequent signature synthesis process.
[0076] In this embodiment, the signature synthesis process uses a weight factor adjustment mechanism to ensure that the signature contributions of different secure nodes are reasonable. The setting of the weight factor is based on factors such as node identity level, historical signature success rate, and is applied in the signature calculation process to optimize the security and reliability of signature synthesis.
[0077] In an optional embodiment of the present application, the private key storage and calculation process of the electronic seal is integrated into a Trusted Execution Environment (TEE). This environment is a hardware-isolated secure area designed to ensure the security of sensitive data and computing processes. In TEE, the private key is stored in a secure area that integrates a hardware encryption module (such as TPM, HSM, etc.). These hardware encryption modules provide strong encryption protection, effectively preventing external attacks and unauthorized access.
[0078] Specifically, the private key of the electronic seal is stored in the secure area after being encrypted, and only legitimate applications authorized by the hardware encryption module can access these keys. In addition, all private key-related computing operations, including digital signature generation, are performed within TEE. TEE ensures that the private key is always in an encrypted state during storage and use through the isolation mechanism supported by hardware, and will not be exposed to the external environment.
[0079] When performing digital signature in this secure area, the digital signature algorithm (such as RSA, ECDSA, etc.) uses the private key for signature calculation. This calculation process is completely performed within TEE, thereby avoiding the risk of private key leakage. The hardware encryption module provides support for signature calculation, ensuring the confidentiality and integrity of data during calculation. With the help of the hardware encryption module, TEE can ensure that only legitimate operations can be performed within it, thereby further enhancing the security of the electronic seal.
[0080] The generation of proof data step uses a zero-knowledge proof algorithm to generate proof data corresponding to the digital signature calculation process completed in the trusted execution environment.
[0081] Specifically, the generated proof data is transmitted to the remote verification entity for verification through a communication channel processed by using an encryption algorithm.
[0082] Each node calculates a local signature according to its own key share and the message to be signed .
[0083] ,
[0084] wherein is the local signature of the th node, representing the signature of the message by the node. is the private key shard (key share) stored by the th node, which is the basis for generating the local signature. is the message to be signed, which is shared by all nodes, used to generate consistent signatures. The local signature of each node will be weighted according to the Lagrange interpolation coefficient to calculate the final global signature. The Lagrange interpolation coefficient is calculated through the identifiers (or key share positions) between nodes, ensuring the contribution of each node in the combination.
[0085] ,
[0086] wherein is the Lagrange interpolation coefficient of the th node, used to weight the local signature of the node. and are the identifiers (or key share positions) of node and node , respectively, and the formula ensures that the contribution weight of each node is calculated according to the positions of other nodes. is the set of nodes participating in signature generation, containing at least nodes.
[0087] Once at least nodes calculate the local signature , these local signatures will be weighted and summed according to the Lagrange interpolation coefficient to combine into the final global signature .
[0088] ,
[0089] wherein, is the final generated global signature, representing the message co-signed by t nodes. is the local signature generated by the i-th node, is the weight of the local signature, ensuring the contribution of each node to the final signature.
[0090] By means of weighted sum, the signatures of t nodes are merged into one valid digital signature, ensuring the security of multi-party collaboration. Finally, the generated global signature can be verified by the public key to ensure the validity of the signature and the integrity of the message.
[0091] ,
[0092] wherein, is the final signature generated by t nodes in collaboration. is the message to be verified, and the verification process will check whether the signature matches the message. is the corresponding public key (which can be a combination of multiple node public keys), used to verify the validity of the final signature.
[0093] Step S4: Manage electronic seal key access in a trusted execution environment and perform global signature calculation in a hardware encryption module.
[0094] In step S4, upon arrival of the global signature calculation request, the storage state of the recovered private key is retrieved according to the key access policy, and the key unsealing operation is performed. After the key unsealing is completed, the recovered private key is loaded into the controlled computing area, and time limit and environmental constraints are set for the use of the recovered private key;
[0095] After the recovered private key is loaded into the controlled computing area, the signature calculation task is dispatched to the hardware encryption module, which includes assigning task identification, setting task priority, and attaching temporary use credentials of the recovered private key to the task. After the hardware encryption module receives the signature calculation task, it performs signature calculation based on the recovered private key and generates the global signature data. After the signature calculation is completed, the temporary use credentials of the recovered private key are automatically cleared;
[0096] After the global signature data is generated, the global signature data is encapsulated, the encapsulation including adding a signature timestamp, a task identifier, and an environment parameter of signature calculation, and a unique signature index identifier is generated based on the encapsulated data, the encapsulated data is stored to a signature storage area of the trusted execution environment, and an index table is established based on the signature index identifier, when a new global signature calculation request arrives, the signature index table is called for comparison, if there is a same index identifier, corresponding global signature data is returned;
[0097] In the key management and global signature calculation process, the usage state of the recovery private key and the execution state of the global signature calculation are recorded, and an access behavior model is constructed based on the recorded data, the access behavior model being used to adjust the usage environment variable, storage state, and usage time limit of the recovery private key, and the trusted execution environment executes a key adjustment strategy according to the access behavior model and stores adjustment records.
[0098] The key access strategy is used to control the access permission of the recovery private key, so as to ensure that the private key is only used in a trusted environment and is strictly managed in security. The key access strategy is maintained by the trusted execution environment and includes access control rules, usage constraints, access verification processes, and exception handling mechanisms. The key access strategy includes a key access control list, which stores parameters such as subject identity information, operation type, access time window, and environment requirement that are allowed to access the key. The subject identity information in the access control list is used to identify users, devices, or processes that can access the private key, each subject corresponds to specific access permissions, the access permissions include only allowing reading the key, performing signature calculation, modifying the key state, and the like, and different subjects can have different permission levels. The access time window defines the valid use time of the private key, and the key access permission is automatically invalidated after the specified time is exceeded. The environment requirement specifies the constraint conditions for key access, including whether the request comes from a trusted network, whether it is running on an authorized device, whether it meets the preset physical security area, and the like, to ensure that the private key is only used in an environment that meets the security policy.
[0099] Step S5: A zero-knowledge proof algorithm is used to generate verifiable calculation proof data for the digital signature calculation process.
[0100] In step S5, generating the verifiable calculation proof data includes, after the global signature data is generated, obtaining input data, calculation steps, and final signature results of the global signature calculation, and converting the calculation process into a calculation instance of the zero-knowledge proof;
[0101] The calculation instance includes a hash value of the data to be signed, a controlled access record of the key, a signature calculation instruction, a signature calculation result, and an associated task identifier.
[0102] A zero-knowledge proof circuit is constructed based on a computing instance, the circuit defines constraint conditions of a signature computing process, including a controlled computing constraint of the recovered private key, an algorithm consistency constraint of the signature computation, and a correctness constraint of the signature result, and generates proof data according to the zero-knowledge proof circuit, the proof data including a computing proof and a verification public key;
[0103] The proof data is stored in a computing proof storage area of a trusted execution environment, and a mapping relationship is established with global signature data, the mapping relationship including an index identifier of the global signature data, an index identifier of the computing proof data, and an associated task identifier, to support subsequent verification.
[0104] When a verification party requests to verify the global signature data, the computing proof storage area is called to obtain the computing proof corresponding to the global signature data, and the computing proof is verified based on the verification public key, if the verification is passed, the validity of the global signature data is confirmed, otherwise the use of the global signature data is rejected.
[0105] Step S6: Establish a quantum communication link and generate a transmission key using quantum key distribution technology, and manage the key transmission.
[0106] In step S6, establishing a quantum communication link and generating a transmission key includes, after the global signature data generation and computing proof storage are completed, the trusted execution environment calling a quantum key distribution module to establish a quantum communication link with a target receiver, the quantum communication link being based on a quantum key distribution protocol to transmit a photon bit stream between a sending end and a receiving end to generate a shared key, the shared key being used to encrypt data interaction in the key transmission process.
[0107] Based on the quantum bit measurement result, a transmission key is generated between the trusted execution environment and the target receiver;
[0108] The transmission key is used to protect the secure transmission of the recovered private key, the global signature data, and the computing proof data, the transmission key being limited to this communication session only and being dynamically updated based on a key update mechanism.
[0109] In the key transmission process, the storage, use permission, and transmission process of the transmission key are managed, the management including setting a unique key identifier for each transmission key, defining the use permission and the effective time window of the key, and performing integrity verification on the key transmission process to ensure that the key has not been tampered with.
[0110] When the target receiver successfully receives the key, the shared key calculated by the receiver is verified to be consistent with the locally stored transmission key, if consistent, the key transmission is confirmed to be successful, and a transmission record is stored, if not consistent, the quantum key distribution process is retriggered, and an abnormal transmission event is recorded.
[0111] In an optional embodiment of the invention, homomorphic encryption techniques (such as the Paillier encryption algorithm or additive homomorphic encryption) are used to commit to each computational step in the signature process. Let a certain computational step... The median value is Then the homomorphic commitment value of this step It can be represented as:
[0112] ,
[0113] in: It is the first step in the signature calculation process. Intermediate values (such as random numbers, message hashes, etc.). It is a generator constructed based on the large number problem. It is the modulus. Indicates the intermediate value The promise is about to be fulfilled. Through encryption methods Convert to commitment value And ensure in subsequent steps It must not be leaked. Zero-knowledge proof algorithms (such as zk-SNARK) require the verifier to verify the correctness of a calculation based on the promise value and other proof data provided by the prover. In this model, the key step in generating a zero-knowledge proof is generating information about the proof. The commitment is to verify its correctness without revealing intermediate values. Any information.
[0114] Assumption It is the prover (signature generator). It is the verifier. For the first verifier in the signature calculation process... The prover needs to provide the verifier with the following:
[0115] The homomorphic commitment value of the intermediate calculation steps (by...) generate).
[0116] Challenge response value: The prover generates this response through calculation, and the verifier will verify based on this response value.
[0117] Through a zero-knowledge proof protocol, the verifier After multiple rounds of interaction, based on and challenge response The validity of the signature calculation process is verified. The specific calculation process is tested using the verification equation in the zero-knowledge proof protocol:
[0118] To enhance the reliability of the proof data, a multi-round challenge-response mechanism is adopted, assuming we use round challenge and response, the verifier will gradually propose challenges about each computing step, and the prover needs to give the corresponding response value in each round. The challenge of each round can be generated by the following equation:
[0119] ,
[0120] wherein: is the challenge value of the th round, is a hash function. is the commitment value in the computing process of the previous round. is the challenge input of the th verifier.
[0121] In each round, the prover needs to calculate the corresponding response , and the verification is performed through the commitment value and the response value:
[0122] After completing the multi-round challenge-response mechanism, the verifier confirms the validity of the entire signature computing process through the following verification process:
[0123] ,
[0124] wherein: is the commitment value of each computing step. is the corresponding challenge response.
[0125] If the verification is passed, the verifier can confirm the legality of the signature calculation without obtaining the detailed calculation process or sensitive data of the signature.
[0126] The quantum key distribution step includes establishing a quantum communication link according to the BB84 protocol, and generating a key for digital signature calculation and data transmission according to the quantum key distribution protocol using the quantum communication link.
[0127] Wherein, the quantum communication link is integrated with a key management module, which updates and manages the generated key according to a predetermined period.
[0128] Embodiment 2 is a second embodiment of the present application, which provides an electronic seal management system, comprising.
[0129] An identity verification module is configured to verify the identity of the seal use request based on a zero trust architecture.
[0130] The key splitting module is configured to split the private key of the electronic seal into a plurality of key shares by using a secret sharing algorithm based on multi-party secure computation technology, and store each key share in a different secure node;
[0131] The signature calculation module is configured to generate a digital signature of the electronic seal by threshold signature mechanism based on a multi-party secure computation protocol by each secure node;
[0132] The key management module is configured to manage the electronic seal key access in the trusted execution environment, and perform global signature calculation in the hardware encryption module;
[0133] The computation proof module is configured to generate corresponding verifiable computation proof data by using a zero-knowledge proof algorithm for the digital signature calculation process;
[0134] The key transmission module is configured to establish a quantum communication link and generate a transmission key by using quantum key distribution technology, and manage the key transmission.
[0135] It should be noted that the method of the embodiment solves the problems of private key leakage and insecure calculation process in the existing electronic seal technology. Specifically, the present application aims to securely store and calculate the private key by combining the trusted execution environment (TEE) with the hardware encryption module, ensuring that the private key of the electronic seal generation process will not be leaked or tampered with during the entire use process. The present application proposes a control method for electronic seal, which enables multiple secure nodes to maintain data privacy when working collaboratively, further improving the security and reliability of the electronic seal system.
[0136] By implementing private key storage and digital signature calculation in the trusted execution environment, combined with the encryption protection provided by the hardware encryption module, the security of the private key during storage and calculation is ensured, avoiding the risk of private key leakage and tampering. At the same time, the multi-party secure computation protocol is used for collaborative signature calculation, so that multiple secure nodes can complete the signature generation of the electronic seal without leaking the private key. Through the above technical means, the present application effectively improves the security of the electronic seal system, ensures the reliability and privacy of the digital signature calculation process, and provides a solid technical guarantee for the widespread application of electronic seal technology in practical applications.
[0137] Embodiment 3, which is different from the first two embodiments, is a third embodiment of the present application.
[0138] If the functions are implemented in the form of software function units and sold or used as independent products, they can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application or the part of the technical solutions that essentially contribute to the prior art or the part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes a plurality of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in the various embodiments of the present application. The aforementioned storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a magnetic disk or an optical disk, and various media that can store program codes.
[0139] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered a list of executable instructions for implementing logic functions, and can be specifically embodied in any computer-readable medium for use by an instruction execution system, apparatus, or device, such as a computer-based system, a system including a processor, or other system that can fetch the instructions from the instruction execution system, apparatus, or device and execute the instructions, or in conjunction with these instructions execution systems, apparatuses, or devices. For the purpose of this specification, "computer-readable medium" can be any device that can contain, store, communicate, propagate, or transport a program for use by an instruction execution system, apparatus, or device, or in conjunction with these instruction execution systems, apparatuses, or devices.
[0140] More specific examples (a non-exhaustive list) of the computer-readable medium include the following: an electrical connection having one or more wires (electrical devices), a portable computer diskette (magnetic devices), a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber device, and a portable compact disc read-only memory (CD ROM). In addition, the computer readable medium can even be paper or other suitable medium on which the program can be printed, as the program can be electronically obtained, for example, by optical scanning of the paper or other medium, followed by editing, interpreting, or otherwise processing, if necessary, in other suitable ways to be electronically obtained, and then stored in the computer memory.
[0141] It should be understood that portions of the present application can be implemented in hardware, software, firmware, or combinations thereof. In the above embodiments, multiple steps or methods can be implemented in software or firmware stored in memory and executed by a suitable instruction execution system. For example, if implemented in hardware, as in another embodiment, implementation can be with a combination of any of the following technologies, which are all well known in the art: discrete logic circuitry having logic gates for implementing logic functions upon an application of data signals, application specific integrated circuits having appropriate combinational logic gates, programmable gate arrays (PGA), field programmable gate arrays (FPGA), and the like.
[0142] It should be noted that the above examples are only used to illustrate the technical solutions of the present application but not limit the present application. Although the present application is described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present application can be modified or replaced equivalently without departing from the spirit and scope of the present application, and all of them should be covered in the scope of the claims of the present application.
Claims
1. A method for controlling electronic seals, characterized in that: include, Authentication of seal usage requests is based on a zero-trust architecture; The private key of the electronic seal is divided into several key shares using a secret sharing algorithm by employing multi-party secure computation technology, and each key share is stored in a different secure node. The digital signature of the electronic seal is generated collaboratively by each security node through a threshold signature mechanism in accordance with a multi-party secure computation protocol. Manage access to electronic seal keys in a trusted execution environment and perform global signature calculations in a hardware encryption module; The digital signature calculation process employs a zero-knowledge proof algorithm to generate verifiable computational proof data. Quantum key distribution technology is used to establish quantum communication links and generate transmission keys, and key transmission is managed. Homomorphic encryption is used to commit to each computational step in the signature process. Let a certain computational step c... i The median value is x i Then the homomorphic commitment value C of this step i Represented as: Where, x i This is the intermediate value at step i in the signature calculation process, g is the generator constructed based on the large number problem, n is the modulus, and Commit(x) is the intermediate value at step i in the signature calculation process. i ) indicates the intermediate value x i The promise, which will soon be x i Through encryption methods Convert to commitment value C i And ensure that x in subsequent steps i Not to be leaked; The authentication of the seal usage request includes: when a user requests to use an electronic seal, obtaining the user's identity information, comparing the identity information with pre-stored identity data, and determining whether the authentication result meets the access policy requirements. Based on the authentication result, a micro-segmentation access control policy is applied to the user request. Based on the user's current device environment, network source, access time information and preset access control rules, the user's access permissions are set in layers to limit the scope of electronic seal operations that the user can access. After implementing the micro-segmentation access control policy, the user's access behavior, operation type, access history and access frequency are dynamically monitored. Fine-grained access control policies are applied. When abnormal access behavior or access behavior that does not match the historical behavior pattern is detected, permission adjustment measures are implemented. The adjustment measures include reducing the access level, adding two-factor authentication, limiting access time or blocking access requests. The process of dividing the key into several key shares includes defining a finite field, defining an elliptic curve E over the finite field, obtaining the private key S of the electronic seal, selecting a base point G on the elliptic curve E, and calculating the public key point P0 corresponding to the private key. The calculation formula is as follows: P0 = S0·G Where S0 represents the private key of the electronic seal, G represents the base point on the elliptic curve, and P0 represents the public key point; Construct a secret shared polynomial f(x) of degree t-1 within a finite field, expressed as: Among them, a j Let f(x) represent the coefficients randomly generated within a finite field, t be the threshold for recovering the private key, and f(x) represent the secret-sharing polynomial used for key splitting. Assign a unique identifier x to each of the m secure nodes. i And calculate the key share Q of each security node. i , is represented as: Q i =f(x i ) Where, x i Q represents the unique identifier of the i-th secure node. i This represents the key share of the i-th security node; Key shares Q are distributed to n secure nodes via a secure transmission channel. i And stored in a trusted execution environment, each key share storage structure includes key share Q i Node identifier x i And check information V i ; When at least t security nodes respond to the key recovery request, the key share Q is collected from the selected nodes. i The private key S is calculated using the Lagrange interpolation formula, and is expressed as: Among them, P R Let I represent the recovered key point, and let λ represent the set of t secure node indices that satisfy the key recovery conditions. i x represents the Lagrange interpolation coefficients. k Key share Q k The security node identifier, x i An identifier representing the current secure node; At key point P R After recovery, perform discrete logarithm calculation on the elliptic curve to recover the private key, represented as: S R =log G P R Among them, S R P represents the private key of the restored electronic seal. R This represents the key point recovered through interpolation, and G represents the base point of the elliptic curve; The digital signature for generating the electronic seal includes, under the condition that the signature threshold requirement is met, being based on the recovery private key S. R Signature calculation is performed by at least t secure nodes using the recovery private key S. R Calculating a partial signature for the message data to be signed includes obtaining the message data to be signed, performing a hash calculation on the message data to generate a hash value, and using S... R Perform encryption operations to generate a partial signature; Each security node performs signature verification on the calculated partial signature. The signature verification includes calculating the verification result of the partial signature based on the public key share and determining whether the partial signature meets the signature requirements based on the preset signature strategy. For the verified partial signatures, a distributed signature synthesis protocol is used to calculate the aggregate signature. The calculation of the aggregate signature includes receiving the verified partial signatures, calculating the weighted value of each partial signature based on the set weight factor, and performing a signature aggregation operation on the weighted partial signatures to generate the aggregate signature. The aggregated signature is encapsulated by at least t secure nodes. The encapsulation includes performing a signature format conversion on the aggregated signature based on a global public key, and adding a timestamp, signature metadata, and signature unique identifier information to generate a global signature. The global signature is verified. The verification includes parsing the global signature, extracting the timestamp, signature metadata and signature unique identification information, and calculating the signature integrity check value based on the global public key. If the calculation result matches the preset signature verification parameters, the signature is confirmed to be valid. Otherwise, the use of the signature data is rejected and the signature invalid event is recorded. When a global signature computation request arrives, the storage state of the recovery private key is retrieved according to the key access policy, and the key decapsulation operation is performed. After the key decapsulation is completed, the recovery private key is loaded into the controlled computing area, and time limits and environmental constraints are set for the use of the recovery private key. After the recovered private key is loaded into the controlled computing area, the signature computing task is scheduled to the hardware encryption module. The scheduling includes assigning a task identifier, setting a task priority, and attaching a temporary credential for using the recovered private key to the task. After the global signature data is generated, it is encapsulated and stored in the signature storage area of the trusted execution environment. An index table is built based on the signature index identifier. When a new global signature calculation request arrives, the signature index table is called for comparison. If the same index identifier exists, the corresponding global signature data is returned.
2. The method for controlling electronic seals as described in claim 1, characterized in that: The generation of verifiable computational proof data includes, after the global signature data is generated, obtaining the input data, computation steps and final signature result of the global signature computation, and converting the computation process into a computational instance of zero-knowledge proof; A zero-knowledge proof circuit is constructed based on a computational instance, and proof data is generated based on the zero-knowledge proof circuit. The proof data includes computational proof and verification public key. When a verifier requests to verify global signature data, it calls the computation proof storage area to obtain the computation proof corresponding to the global signature data. It then verifies the computation proof based on the verification public key. If the verification passes, the validity of the global signature data is confirmed; otherwise, the use of the global signature data is rejected.
3. The method for controlling electronic seals as described in claim 2, characterized in that: The establishment of the quantum communication link and generation of the transmission key includes establishing a quantum communication link with the target receiver, wherein the quantum communication link is based on a quantum key distribution protocol and transmits a photonic bit stream between the sender and receiver to generate a shared key; Based on the quantum bit measurement results, a transmission key is generated between the trusted execution environment and the target receiver; Once the target receiver successfully receives the key, it verifies whether the shared key calculated by the receiver is consistent with the transmission key stored locally. If they are consistent, the key transmission is confirmed to be successful and the transmission record is stored. If they are inconsistent, the quantum key distribution process is retried and the abnormal transmission event is recorded.
4. A control system for electronic seals, employing the control method for electronic seals as described in any one of claims 1 to 3, characterized in that, include: The authentication module is used to authenticate seal usage requests based on a zero-trust architecture; The key splitting module is used to divide the private key of the electronic seal into several key shares using a secret sharing algorithm and employ multi-party secure computation technology, and store each key share separately on different secure nodes; The signature calculation module is used by each security node to collaboratively calculate and generate the digital signature of the electronic seal according to a multi-party secure calculation protocol and a threshold signature mechanism. The key management module is used to manage access to electronic seal keys in a trusted execution environment and to perform global signature calculations in the hardware encryption module. The computation proof module is used to generate verifiable computation proof data for the digital signature computation process using a zero-knowledge proof algorithm. The key transmission module is used to establish a quantum communication link and generate transmission keys using quantum key distribution technology, and to manage key transmission.
5. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the electronic seal control method according to any one of claims 1 to 3.
6. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the steps of the electronic seal control method according to any one of claims 1 to 3.
Citation Information
Patent Citations
Identity authentication methods, devices and system applied to quantum key distribution process
CN105991285A
Joint signature method and system
CN111865572A
Balanced SM9 digital signature multi-party adapter signature generation method and system
CN120238302A