Collaborative signature method and device, equipment and medium
By using hardware encryption machines, trusted execution environments, and distributed memory storage of private keys, the problem of key components being easily intercepted is solved, and the security authentication strength and cross-institutional trust of multi-party collaborative signatures are achieved.
Patent Information
- Application Number
- CN202510966239.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-14
- Publication Date
- 2025-09-12
- Estimated Expiration
- 2045-07-14
AI Technical Summary
In existing collaborative signature technologies, key components can be easily intercepted, resulting in the destruction of signature validity and the inability to achieve cross-institutional trust and security authentication.
The first private key is stored in a hardware encryption machine, the second private key is stored in a trusted execution environment (TEE), and the third private key is stored in memory. The signature original text is signed using the corresponding independently stored private keys based on different execution entities, and the complete signature is obtained by integration.
It improves the security authentication strength of the signature, reduces the risk of private key leakage, ensures that the signature is completed by multiple parties, and no party can deny the signing behavior alone. Attackers need to break into multiple systems to forge signatures, thus achieving cross-institutional trust.
Smart Images

Figure CN120639313A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of digital signature technology, and in particular to a collaborative signature method, device, equipment and medium. Background Art
[0002] With the advancement of digitalization, electronic signature technology has become a key enabler for ensuring the security and efficiency of online transactions, contract signing, and identity authentication. Among the many forms of electronic signature, collaborative signature, as a mechanism that allows multiple parties to participate, confirm, and complete a signature, is demonstrating increasing importance in finance, government affairs, supply chain management, electronic contracts, and other fields. It not only addresses the difficulty of a single signature in achieving multi-party consensus but also offers significant advantages in enhancing process transparency and accountability.
[0003] Currently, collaborative signature technology primarily verifies the authorization of all parties by generating a separate signature component for each participant and combining these signature components into a single valid signature. However, if the local security mechanism is compromised or the key components are intercepted during generation, transmission, or use, an attacker could forge signature components, thereby undermining the validity of the entire signature. Summary of the Invention
[0004] The present invention provides a collaborative signature method, apparatus, device and medium to address the defects in the prior art that key components can be easily intercepted, thereby destroying the validity of the signature, improve the security authentication strength of the collaborative signature, realize cross-institutional trust, and is suitable for multi-party collaboration scenarios.
[0005] The present invention provides a collaborative signature method, including: receiving a signature original sent by an application client forwarded by an application server, and obtaining a first signature value based on the signature original and a first private key previously stored in a hardware encryption machine; sending a first online fast identity authentication FIDO request to a biometric server, and receiving a second signature value and a third signature value sent by the biometric server; wherein the second signature value is obtained by the biometric client based on the received first FIDO message, the signature original sent by the application client and the second private key previously stored in a trusted execution environment TEE, and sent to the biometric server through the collaborative signature client, the third signature value is obtained by the collaborative signature client based on the received first FIDO message, the signature original sent by the application client and the third private key previously stored in the memory, and sent to the biometric server, the first FIDO message is the FIDO authentication policy generated by the biometric server based on the first FIDO request and sent to the biometric client and the collaborative signature client in the form of a message; according to the first signature value, the second signature value and the third signature value, a complete signature is obtained, and the complete signature is sent to the application server.
[0006] According to a collaborative signature method provided by the present invention, the first private key is symmetrically encrypted and stored by using a hardware encryption machine to encrypt the private key in the first key component. Before receiving the original signature, the first key component is generated by using a preset national secret algorithm based on the opening signature request sent by the application client forwarded by the application server; according to the original signature, combined with the first private key previously stored in the hardware encryption machine, a first signature value is obtained, including: decrypting the first private key stored in the hardware encryption machine through the hardware encryption machine to obtain a first decrypted private key; using the first decrypted private key to sign the original signature to obtain a first signature value.
[0007] According to a collaborative signature method provided by the present invention, the first FIDO message includes a FIDO authentication policy for limiting the use of a second private key for signing; the second signature value is obtained by the biometric client based on the first FIDO message, using the binding relationship between the second private key in the TEE and the corresponding biometric feature to perform biometric authentication, and based on the authentication being passed, signing the original signature text with the second private key; the second private key is obtained by the biometric client based on receiving the second FIDO message to perform biometric authentication, and based on the authentication being passed, using a preset national secret algorithm to generate a second key component, and binding the private key in the second key component to the corresponding biometric feature and storing it in a trusted execution environment; the second FIDO message is generated by the biometric server based on the second FIDO request to generate the corresponding FIDO authentication policy and sent in the form of a message, and the second FIDO message includes the FIDO authentication policy for limiting the storage of the second private key; the second FIDO request is generated and sent to the biometric server after storing the first private key.
[0008] According to a collaborative signature method provided by the present invention, the second signature value and the third signature value are verified by the biometric server using the previously stored second public key to receive the second signature value, and are sent after the verification is passed; the second public key is generated by the biometric client based on the second key component, and the second public key in the second key component is sent to the biometric server through the collaborative signature client.
[0009] According to a collaborative signature method provided by the present invention, the first FIDO message also includes a FIDO authentication policy for limiting the use of a third private key for signing; the third signature value is obtained by the collaborative signature client based on the first FIDO message, authenticating the user's personal identification PIN code, and based on the authentication being passed, obtaining a third decryption key according to the temporary key and the third private key in the memory, and signing the original signature text using the third decryption key; the third private key is generated by the collaborative signature client based on receiving the second FIDO message and using a preset national secret algorithm to generate a third key component according to the temporary key and the private key in the third key component and stored in the memory; the temporary key is generated by the collaborative signature client based on the second FIDO message using the hardware information and PIN code of the device to which the memory belongs; the second FIDO message is generated by the biometric server based on the second FIDO request and sent in the form of a message, and the second FIDO message includes a FIDO authentication policy for limiting the storage of the second private key; the second FIDO request is generated and sent to the biometric server after storing the first private key.
[0010] According to a collaborative signature method provided by the present invention, the third decryption key is obtained by the collaborative signature client deriving the temporary key using a preset key derivation algorithm, and decrypting the third private key in the memory in combination with a preset block encryption algorithm; the third private key is obtained by the collaborative signature client deriving the temporary key using a preset key derivation algorithm, and encrypting the private key in the third key component in combination with a preset block encryption algorithm.
[0011] According to a collaborative signature method provided by the present invention, after sending the complete signature to the application server, it also includes: receiving the complete signature and the original signature sent by the application server; verifying the complete signature according to the original signature and the complete public key to obtain a verification result; wherein, the complete public key is generated based on the previously stored first public key and the second public key and the third public key sent by the biometric server, the first public key is generated based on the open signature request sent by the application client forwarded by the application server, using a preset national secret algorithm, the second public key is used to represent the public key in the second key component corresponding to the second private key, the second public key is sent to the biometric server through the collaborative signature client after the biometric client stores the second private key in the TEE, the third public key is used to represent the public key in the third key component corresponding to the third private key, the third public key is sent to the biometric server after the collaborative signature client stores the third private key in the memory; the verification result is returned to the application server.
[0012] The present invention also provides a collaborative signature device, including: a signature module, which receives the signature original sent by the application client forwarded by the application server, and obtains a first signature value based on the signature original and the first private key previously stored in the hardware encryption machine; a signature receiving module, which sends a first online fast identity authentication FIDO request to the biometric server, and receives a second signature value and a third signature value sent by the biometric server; wherein the second signature value is obtained by the biometric client based on the received first FIDO message, the signature original sent by the application client and the second private key previously stored in the trusted execution environment TEE, and sent to the biometric server through the collaborative signature client, and the third signature value is obtained by the collaborative signature client based on the received first FIDO message, the signature original sent by the application client and the third private key previously stored in the memory, and sent to the biometric server, and the first FIDO message is the FIDO authentication policy generated by the biometric server based on the first FIDO request and sent to the biometric client and the collaborative signature client in the form of a message; a signature integration module, which obtains a complete signature based on the first signature value, the second signature value and the third signature value, and sends the complete signature to the application server.
[0013] The present invention also provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, any one of the collaborative signature methods described above is implemented.
[0014] The present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements any of the collaborative signature methods described above.
[0015] The present invention also provides a computer program product, comprising a computer program, wherein when the computer program is executed by a processor, the computer program implements any one of the collaborative signature methods described above.
[0016] The collaborative signature method, apparatus, device and medium provided by the present invention use a hardware encryption machine to pre-store the first private key to provide physical isolation and anti-tampering protection. Even if the system is invaded, the private key cannot be exported, thereby greatly reducing the risk of private key leakage. The security of private key storage is ensured to prevent the private key from being illegally accessed or exported. The second private key is stored in a trusted execution environment (TEE) through the biometric client to provide a more secure storage environment and an isolated security area for the second private key. Even if the operating system is compromised, the private key stored in the TEE is relatively safe. The collaborative signature client uses memory to store the third private key, making the private key partitioning and the like. Distributed storage in different devices / environments prevents a single entity from holding all private keys, reducing the risk of internal threats. Even if a certain link is compromised, the attacker still needs to obtain other private keys to complete the full signature, increasing the cost of attack. The original signature is signed based on different execution entities using the corresponding independently stored private keys to integrate and obtain a complete signature, ensuring that the signature is completed by multiple parties. No party can deny the signing behavior alone, ensuring the credibility of the signature result. The attacker needs to break into multiple independent systems at the same time to forge a signature, which greatly increases the difficulty of the attack, improves the security authentication strength of the collaborative signature, and realizes cross-institutional trust. It is suitable for multi-party collaboration scenarios. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] In order to more clearly illustrate the technical solutions in the present invention or the prior art, a brief introduction is given below to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0018] Figure 1 This is one of the flow charts of the collaborative signature method provided by the present invention; Figure 2 This is the second flow chart of the collaborative signature method provided by the present invention; Figure 3 This is the third flow chart of the collaborative signature method provided by the present invention; Figure 4 It is a schematic diagram of the structure of the collaborative signature device provided by the present invention; Figure 5 It is a structural schematic diagram of the electronic device provided by the present invention. DETAILED DESCRIPTION
[0019] To make the objectives, technical solutions, and advantages of the present invention more clear, the technical solutions of the present invention will be clearly and completely described below in conjunction with the accompanying drawings. Obviously, the embodiments described are only some of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.
[0020] Figure 1 This is a flow chart of the collaborative signature method provided by the present invention, such as Figure 1 As shown, the method includes: S11, receiving the original signature sent by the application client and forwarded by the application server, and obtaining a first signature value based on the original signature and a first private key previously stored in the hardware encryption machine; S12, sending a first online fast identity verification FIDO request to the biometric server, and receiving a second signature value and a third signature value sent by the biometric server; wherein, the second signature value is obtained by the biometric client based on the received first FIDO message, the original signature sent by the application client, and the second private key previously stored in the trusted execution environment TEE, and sent to the biometric server through the collaborative signature client, and the third signature value is obtained by the collaborative signature client based on the received first FIDO message, the original signature sent by the application client, and the third private key previously stored in the memory, and sent to the biometric server, and the first FIDO message is the FIDO authentication policy generated by the biometric server based on the first FIDO request and sent to the biometric client and the collaborative signature client in the form of a message respectively; S13: Obtain a complete signature based on the first signature value, the second signature value, and the third signature value, and send the complete signature to the application server.
[0021] It should be noted that the execution subject of this method is the collaborative signature server. The step numbers "S1N" in this manual do not represent the order of the collaborative signature method. Figure 2-Figure 3 The collaborative signature method of the present invention is described.
[0022] Step S11: receiving the original signature sent by the application client and forwarded by the application server, and obtaining a first signature value based on the original signature and a first private key previously stored in the hardware encryption machine.
[0023] In this embodiment, the first private key is symmetrically encrypted and stored by using a hardware encryption machine to encrypt the private key in the first key component. The first key component is generated using a preset national encryption algorithm based on the opening signature request sent by the application client forwarded by the application server before receiving the original signature.
[0024] It should be noted that the collaborative signature server generates the first key component based on the signature request to avoid long-term exposure of the private key in the system and reduce the risk of static attacks (such as cold start attacks and persistent memory analysis). The private key in the first key component is symmetrically encrypted and stored using a hardware encryption machine to ensure that the private key cannot be illegally copied or exported. Even if the hardware encryption machine is physically accessed, the attacker still needs to crack the symmetric key to obtain the private key, which increases the difficulty of the attack.
[0025] In other words, before the collaborative signature server receives the original signature sent by the application client and forwarded by the application server, the following procedures occur: the application client sends an open signature request to the application server; the application server sends the open signature request to the collaborative signature server; the collaborative signature server generates a first key component based on the received open signature request using a preset national secret algorithm, and uses a hardware encryption machine to symmetrically encrypt the private key in the first key component, so as to store the first private key obtained by symmetrical encryption in the hardware encryption machine, and store the first public key in the first key component in the collaborative signature server.
[0026] Furthermore, the first signature value is obtained based on the original signature text and a first private key previously stored in the hardware encryption machine. This includes: decrypting the first private key stored in the hardware encryption machine using the hardware encryption machine to obtain a first decrypted private key; and signing the original signature text using the first decrypted private key to obtain the first signature value. It should be noted that the private key decryption and signing operations are completed quickly within the controlled environment of the hardware encryption machine, reducing the time the private key is exposed to the system, thereby significantly improving the security of the signing process.
[0027] Step S12, sending a first online fast identity authentication FIDO request to the biometric server, and receiving a second signature value and a third signature value sent by the biometric server; wherein, the second signature value is obtained by the biometric client based on the received first FIDO message, the signature original sent by the application client and the second private key previously stored in the trusted execution environment TEE, and sent to the biometric server through the collaborative signature client, the third signature value is obtained by the collaborative signature client based on the received first FIDO message, the signature original sent by the application client and the third private key previously stored in the memory and sent to the biometric server, and the first FIDO message is the FIDO authentication policy generated by the biometric server based on the first FIDO request and sent to the biometric client and the collaborative signature client in the form of a message respectively.
[0028] It should be added that the signature original sent by the application client to the biometric client and the biometric client can be sent at the same time as the signature original sent to the collaborative signature server through the application server, or it can be sent before the biometric client and the biometric client sign the signature original. The specific settings can be based on actual design requirements and are not further limited here.
[0029] In addition, after the collaborative signature server obtains the first signature value, the collaborative signature server generates a first online fast identity authentication (Fast Identity Online, referred to as FIDO) request and sends it to the biometric server; the biometric server generates a FIDO authentication policy based on the first FIDO request, and obtains the first FIDO message in the form of a message, and sends the first FIDO message to the biometric client and the collaborative signature client respectively; the biometric client obtains the second signature value based on the received first FIDO message, the original signature and the second private key previously stored in the trusted execution environment TEE, and sends the second signature value to the collaborative signature client; the collaborative signature client obtains the third signature value based on the received first FIDO message, the original signature and the third private key previously stored in the memory, and sends the third signature value and the received second signature value to the biometric server.
[0030] Furthermore, the first FIDO request includes a challenge value, user identifier, authenticator requirements, security parameters, and application identifier. The challenge value is randomly generated data used to ensure the uniqueness of each authentication and prevent replay attacks. The user identifier uniquely identifies the requesting user, ensuring that the authentication is bound to a specific user. The authenticator requirements are used to limit whether biometrics or physical devices are supported. For example, biometric clients are required to support biometric authentication, including fingerprint and facial recognition, and collaborative signature clients are required to support physical devices such as personal identification numbers (PINs). Specific authenticator requirements can be set based on actual design requirements and are not further defined here. Security parameters are used to determine whether user interaction (such as pressing a fingerprint) or device binding (such as setting a PIN) is required. The application identifier identifies the application or service initiating the request, ensuring that the authentication policy is bound to the correct application. Through the above, the customization and security of the authentication policy are ensured, while meeting the needs of different scenarios.
[0031] In this embodiment, the first FIDO message includes a FIDO authentication policy that limits the use of the second private key for signing. The second signature value is obtained by the biometric client performing biometric authentication based on the first FIDO message, using the binding relationship between the second private key in the TEE and the corresponding biometric feature, and then signing the original signature using the second private key upon successful authentication. It should be noted that the biometric client must pass biometric authentication to activate the private key, preventing the private key from being used illegally, ensuring that the signing operation can only be completed by authorized users, and handing the transmission task to the co-signing client, reducing the risk of the biometric client being directly exposed to attack paths.
[0032] It should be added that after the biometric client generates the second signature value, it generates a first message based on the second signature value, and sends the first message and the second signature value to the collaborative signature client, so as to be sent to the biometric server through the collaborative signature client.
[0033] In addition, the second private key is the biometric authentication performed by the biometric client based on the reception of the second FIDO message, and based on the authentication being passed, the second key component is generated using the preset national secret algorithm, and the private key in the second key component is bound to the corresponding biometric feature and stored in the trusted execution environment; the second FIDO message is the biometric server generating the corresponding FIDO authentication policy based on the second FIDO request and sending it in the form of a message, and the second FIDO message includes a FIDO authentication policy for limiting the storage of the second private key; the second FIDO request is generated based on the storage of the first private key and sent to the biometric server.
[0034] It should be noted that the collaborative signature client sets stricter PIN code attempt limits (such as fewer attempts and longer lock time) based on the authentication policy defined in the first FIDO message, thereby increasing the difficulty of unauthorized access and use, effectively preventing brute force cracking, and encrypting the third private key and storing it in memory, thereby ensuring the security of the third private key while improving access speed and reducing hardware costs.
[0035] In addition, after the collaborative signature server stores the first private key obtained by symmetrical encryption in the hardware encryption machine, the collaborative signature server generates a second FIDO request and sends it to the biometric server. The biometric server generates a FIDO authentication policy based on the second FIDO request, obtains a second FIDO message in message form, and sends the second FIDO message to the biometric client and the collaborative signature client respectively. The biometric client performs biometric authentication based on the received second FIDO message and, upon successful authentication, generates a second key component using a preset national secret algorithm. The private key in the second key component is bound to the corresponding biometric feature and stored in the Trusted Execution Environment (TEE). It should be noted that the second FIDO request can refer to the first FIDO request mentioned above and will not be repeated here.
[0036] Furthermore, after storing the corresponding private key in the TEE, the biometric client also generates a first FIDO signature value based on the stored private key, and sends the first FIDO signature value and the second public key in the second key component to the collaborative signature client, so as to be sent to the biometric server through the collaborative signature client.
[0037] In this embodiment, the first FIDO message also includes a FIDO authentication policy for limiting the use of a third private key for signing; the third signature value is obtained by the collaborative signing client authenticating the user's personal identification PIN code based on the first FIDO message, and upon successful authentication, obtaining a third decryption key based on the temporary key and the third private key in the memory, and signing the original signature using the third decryption key. It should be noted that the collaborative signing client authenticates the PIN code based on the authentication policy defined in the first FIDO message, increasing the difficulty of unauthorized access and use, effectively preventing brute force cracking, and decrypting the third key using the temporary key to sign the original signature, thereby minimizing the time window in which the private key exists in plaintext in the memory and reducing the risk of private key leakage due to memory dumps or other memory attacks.
[0038] It should be noted that the PIN code can be set by the user in advance, and the temporary key can be referred to as described below and will not be repeated here. In addition, after the third signature value is generated, the collaborative signature client generates the third signature value, sends the third signature value, the first message, and the second signature value to the biometric server.
[0039] Furthermore, the third decryption key is obtained by the collaborative signature client deriving the temporary key using a preset key derivation algorithm and decrypting the third private key in the memory in combination with a preset block encryption algorithm.
[0040] In addition, the third private key is generated by the collaborative signature client based on receiving the second FIDO message and using the preset national secret algorithm to obtain and store it in the memory based on the temporary key and the private key in the third key component; the temporary key is generated by the collaborative signature client based on the second FIDO message using the hardware information and PIN code of the device to which the memory belongs.
[0041] It should be noted that the collaborative signature server generates a third key component based on the received second FIDO message using a preset national secret algorithm, and uses the hardware information and PIN code of the device to which the memory belongs to generate a temporary key, so as to obtain the third private key based on the temporary key and the private key in the third key component and store it in the memory.
[0042] Furthermore, the temporary key can also be generated based on the hardware information and PIN code of the device to which the memory belongs, combined with a random SALT value, using a preset key generation algorithm. For example, when the preset key generation algorithm adopts the national secret algorithm SM3, the temporary key Temp = SM3 (device hardware information + PIN + SALT value).
[0043] Furthermore, the third private key is obtained by the collaborative signing client deriving the temporary key using a preset key derivation algorithm and encrypting the private key in the third key component in combination with a preset block encryption algorithm.
[0044] It should be added that the preset key derivation algorithm can be selected according to actual design requirements, such as the key derivation function (SM2_KDF), etc., which is not further limited here; the temporary key Temp is derived to obtain the initial vector IV and the key key_sm4 used by the national encryption SM4 algorithm, expressed as (IV, key_sm4) = SM2_KDF(Temp), where IV can usually be a random or pseudo-random value used to enhance encryption security.
[0045] In addition, the preset block encryption algorithm can be selected according to actual design requirements, such as the ciphertext block chaining mode (SM4_CBC) based on the block cipher algorithm SM4, etc., which is not further limited here; the third private key is expressed as E(SKc)=SM4_CBC_Encrypt(IV, key_sm4, SKc), where SKc represents the private key in the third key component, and SM4_CBC_Encrypt represents the encryption operation of the SM4 algorithm in the CBC mode, and its function is to convert plaintext data into ciphertext data through the SM4 algorithm and the CBC mode.
[0046] In addition, after storing the corresponding private key in the memory, the collaborative signing client also sends the third public key in the third key component and the first and second public keys to the biometric service end.
[0047] In an optional embodiment, the second signature value and the third signature value are verified by the biometric server using the previously stored second public key to receive the second signature value, and are sent after the verification is passed; the second public key is generated by the biometric client based on the second key component, and the second public key in the second key component is sent to the biometric server through the collaborative signature client.
[0048] It should be noted that after the biometric server receives the second signature value and the third signature value, it uses the second public key to verify the second signature value, and based on the verification, sends the second signature value and the third signature value to the collaborative signature server, so that the collaborative signature server can obtain a complete signature based on the first signature value generated in advance and the received second signature value and third signature value.
[0049] It should be noted that the preset national secret algorithm used by the collaborative signature server to generate the first key component, the preset national secret algorithm used by the biometric client to generate the second key component, and the preset national secret algorithm used by the collaborative signature client to generate the third key component are the same algorithm.
[0050] Step S13: Obtain a complete signature based on the first signature value, the second signature value, and the third signature value, and send the complete signature to the application server.
[0051] In an optional embodiment, after sending the complete signature to the application server, it also includes: receiving the complete signature and the original signature sent by the application server; verifying the complete signature according to the original signature and the complete public key to obtain a verification result; wherein, the complete public key is generated based on the previously stored first public key and the second public key and the third public key sent by the biometric server, the first public key is generated based on the open signature request sent by the application client forwarded by the application server, using a preset national secret algorithm, the second public key is used to represent the public key in the second key component corresponding to the second private key, the second public key is sent to the biometric server through the collaborative signature client after the biometric client stores the second private key in the TEE, the third public key is used to represent the public key in the third key component corresponding to the third private key, the third public key is sent to the biometric server after the collaborative signature client stores the third private key in the memory; the verification result is returned to the application server.
[0052] In an alternative embodiment, reference Figure 2 Before the collaborative signature server receives the original signature sent by the application client forwarded by the application server, it includes: The application client sends a signature activation request to the application server; The application server sends the signature request to the collaborative signature server; The collaborative signature server, based on the open signature request, generates a first key component using a preset national secret algorithm, symmetrically encrypts and stores the private key in the first key component using a hardware encryption machine to obtain a first private key, stores the first public key in the first key component in the collaborative signature server, and generates and sends a second FIDO request to the biometrics server; The biometric server generates a corresponding FIDO authentication policy based on the second FIDO request and sends the policy to the biometric client and the collaborative signature client in the form of a message. The biometric client performs biometric authentication based on the second FIDO authentication method, generates a second key component using a preset national encryption algorithm upon successful authentication, binds the private key in the second key component to the corresponding biometric feature and stores the result in the TEE, generates a first FIDO signature value, and sends the first FIDO signature value and the second public key in the second key component to the co-signing client. The collaborative signing client generates a third key component based on the second FIDO message using a preset national secret algorithm, and generates a temporary key using the hardware information and PIN code of the device to which the memory belongs. The collaborative signing client obtains a third private key based on the temporary key and the private key in the third key component and stores the third private key in the memory, and sends the third public key in the third key component, the first FIDO signature value, and the second public key to the biometric identification server. The biometric identification server stores the second public key and sends the second public key and the third public key to the collaborative signature server; The collaborative signature server generates a complete public key based on the previously stored first public key and the received second public key and third public key for subsequent verification of the complete signature.
[0053] It should be added that the specific implementation details can be found in the above description and will not be elaborated here.
[0054] In an alternative embodiment, reference Figure 3 , the method comprising: The application client sends the original signature to the application server; The application server sends the original signature to the collaborative signature server; The collaborative signature server, based on the received original signature, uses the hardware encryption machine to decrypt the first private key stored in the hardware encryption machine, signs the original signature using the first decrypted private key obtained by decryption to obtain a first signature value, and sends a first FIDO request to the biometrics server; The biometric server generates a corresponding FIDO authentication policy based on the first FIDO request and sends the policy to the biometric client and the collaborative signature client in the form of a message. The biometric client performs biometric authentication based on the first FIDO message using the binding relationship between the second private key in the TEE and the corresponding biometric feature. If the authentication is successful, the client signs the original signature using the second private key to obtain a second signature value, generates the first message, and sends the second signature value and the first message to the collaborative signature client. The collaborative signature client authenticates the PIN code based on the first FIDO message, and upon successful authentication, obtains a third decryption key based on the temporary key and the third private key in the memory, signs the original signature using the third decryption key to obtain a third signature value, and sends the third signature value, the first message, and the second signature value to the biometric authentication server. The biometric identification server verifies the second signature value using the second public key, and upon successful verification, sends the second signature value and the third signature value to the collaborative signature server; The collaborative signature server obtains a complete signature based on the first signature value, the second signature value, and the third signature value, and sends the complete signature to the application server.
[0055] In an optional embodiment, after the collaborative signature server sends the complete signature to the application server, the application server can also initiate a signature verification process during subsequent business processing. Figure 3 , the method further comprises: The application server sends the complete signature and original signature text to the collaborative signature server; The collaborative signature server verifies the complete signature based on the original signature and the complete public key, obtains the verification result, and returns the verification result to the application server.
[0056] It should be added that the specific implementation details can be found in the above description and will not be elaborated here.
[0057] In summary, the embodiment of the present invention uses a hardware encryption machine to pre-store the first private key to provide physical isolation and anti-tampering protection. Even if the system is invaded, the private key cannot be exported, thereby greatly reducing the risk of private key leakage. It ensures the security of private key storage and prevents the private key from being illegally accessed or exported. The second private key is stored in a more secure storage environment using a trusted execution environment (TEE) through the biometric client to provide an isolated security area for the second private key. Even if the operating system is compromised, the private key stored in the TEE is relatively safe. The collaborative signature client uses the memory to store the third private key, so that the private keys are stored in different In the same device / environment, a single entity is prevented from holding all private keys, reducing the risk of internal threats. Even if a certain link is compromised, the attacker still needs to obtain other private keys to complete the full signature, increasing the cost of attack. The original signature is signed based on different execution entities using the corresponding independently stored private keys to integrate and obtain a complete signature, ensuring that the signature is completed by multiple parties. No party can deny the signing behavior alone, ensuring the credibility of the signature result. The attacker needs to break into multiple independent systems at the same time to forge a signature, which greatly increases the difficulty of the attack, improves the security authentication strength of the collaborative signature, and realizes cross-institutional trust. It is suitable for multi-party collaboration scenarios.
[0058] The collaborative signature device provided by the present invention is described below. The collaborative signature device described below and the collaborative signature method described above can be referenced to each other.
[0059] Figure 4 A schematic diagram of the structure of a collaborative signature device is shown, which includes: The signature module 41 receives the original signature sent by the application client and forwarded by the application server, and obtains a first signature value based on the original signature and the first private key previously stored in the hardware encryption machine; The signature receiving module 42 sends a first online fast identity verification FIDO request to the biometric server and receives a second signature value and a third signature value sent by the biometric server; wherein the second signature value is obtained by the biometric client based on the received first FIDO message, the original signature sent by the application client, and the second private key previously stored in the trusted execution environment TEE, and is sent to the biometric server via the collaborative signature client; the third signature value is obtained by the collaborative signature client based on the received first FIDO message, the original signature sent by the application client, and the third private key previously stored in the memory, and is sent to the biometric server; the first FIDO message is a FIDO authentication policy generated by the biometric server based on the first FIDO request and sent to the biometric client and the collaborative signature client in the form of a message; The signature integration module 43 obtains a complete signature according to the first signature value, the second signature value and the third signature value, and sends the complete signature to the application server.
[0060] It should be noted that the principle of the device embodiment of the present invention is the same as that of the above-mentioned method embodiment. Please refer to the above-mentioned method embodiment for details, and the more detailed explanation will not be repeated here.
[0061] Figure 5 An example of a physical structure diagram of an electronic device is shown below. Figure 5 As shown, the electronic device may include: a processor (processor) 510, a communication interface (Communications Interface) 520, a memory (memory) 530 and a communication bus 540, wherein the processor 510, the communication interface 520, and the memory 530 communicate with each other through the communication bus 540. The processor 510 can call the logic instructions in the memory 530 to execute the collaborative signature method, which includes: receiving the signature original sent by the application client forwarded by the application server, and obtaining a first signature value based on the signature original and the first private key previously stored in the hardware encryption machine; sending a first online fast identity authentication FIDO request to the biometric server, and receiving a second signature value and a third signature value sent by the biometric server; wherein the second signature value is obtained by the biometric client based on the received first FIDO message, the signature original sent by the application client and the second private key previously stored in the trusted execution environment TEE, and sent to the biometric server through the collaborative signature client, and the third signature value is obtained by the collaborative signature client based on the received first FIDO message, the signature original sent by the application client and the third private key previously stored in the memory, and sent to the biometric server; the first FIDO message is the FIDO authentication policy generated by the biometric server based on the first FIDO request and sent to the biometric client and the collaborative signature client in the form of a message; according to the first signature value, the second signature value and the third signature value, a complete signature is obtained, and the complete signature is sent to the application server.
[0062] Furthermore, the logic instructions in the aforementioned memory 530 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the portion that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as a USB flash drive, a mobile hard drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.
[0063] On the other hand, the present invention also provides a computer program product, which includes a computer program. The computer program can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the collaborative signature method provided by the above methods, which includes: receiving a signature original sent by an application client forwarded by an application server, and obtaining a first signature value based on the signature original and a first private key previously stored in a hardware encryption machine; sending a first online fast identity verification FIDO request to a biometric identification server, and receiving a second signature value and a third signature value sent by the biometric identification server; wherein the second signature value is the signature value obtained by the biometric identification client based on the received first signature value. The third signature value is obtained by the collaborative signature client based on the received first FIDO message, the original signature sent by the application client and the third private key previously stored in the trusted execution environment TEE and sent to the biometric server. The first FIDO message is the FIDO authentication policy generated by the biometric server based on the first FIDO request and sent to the biometric client and the collaborative signature client in the form of a message; the complete signature is obtained based on the first signature value, the second signature value and the third signature value, and the complete signature is sent to the application server.
[0064] On the other hand, the present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which is implemented by a processor to execute the collaborative signature method provided by the above methods, the method comprising: receiving a signature original sent by an application client forwarded by an application server, and obtaining a first signature value based on the signature original and a first private key previously stored in a hardware encryption machine; sending a first online fast identity verification FIDO request to a biometric identification server, and receiving a second signature value and a third signature value sent by the biometric identification server; wherein the second signature value is the biometric identification client based on the received first FIDO message and the first private key sent by the application client. The third signature value is obtained by the collaborative signature client based on the received first FIDO message, the signature original text sent by the application client and the third private key previously stored in the memory and sent to the biometric server. The first FIDO message is the FIDO authentication policy generated by the biometric server based on the first FIDO request and sent to the biometric client and the collaborative signature client in the form of a message; the complete signature is obtained according to the first signature value, the second signature value and the third signature value, and the complete signature is sent to the application server.
[0065] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, i.e., they may be located in one location or distributed across multiple network units. Some or all of the modules may be selected based on actual needs to achieve the objectives of the present embodiment. Persons of ordinary skill in the art will be able to understand and implement the present invention without inventive effort.
[0066] Through the above description of the embodiments, those skilled in the art will clearly understand that each embodiment can be implemented using software plus a necessary general-purpose hardware platform, or of course, hardware. Based on this understanding, the essence of the above technical solution, or the portion that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a magnetic disk, or an optical disk, and includes a number of instructions for causing a computer device (such as a personal computer, server, or network device) to execute the methods described in each embodiment or certain portions of the embodiments.
[0067] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present invention.
Claims
1. A collaborative signature method, characterized in that: include: Receive the original signature text sent by the application client and forwarded by the application server, and obtain a first signature value based on the original signature text and a first private key previously stored in the hardware encryption machine; Sending a first online fast identity verification FIDO request to the biometric server, and receiving a second signature value and a third signature value sent by the biometric server; wherein, the second signature value is obtained by the biometric client based on the received first FIDO message, the original signature sent by the application client, and the second private key previously stored in the trusted execution environment TEE, and sent to the biometric server through the collaborative signature client; the third signature value is obtained by the collaborative signature client based on the received first FIDO message, the original signature sent by the application client, and the third private key previously stored in the memory, and sent to the biometric server; the first FIDO message is the FIDO authentication policy generated by the biometric server based on the first FIDO request and sent to the biometric client and the collaborative signature client in the form of a message; A complete signature is obtained according to the first signature value, the second signature value, and the third signature value, and the complete signature is sent to the application server.
2. The collaborative signature method according to claim 1, characterized in that: The first private key is generated by symmetrically encrypting the private key in the first key component using the hardware encryption machine and storing it. The first key component is generated using a preset national encryption algorithm based on the open signature request sent by the application client and forwarded by the application server before receiving the original signature. According to the original signature, combined with the first private key previously stored in the hardware encryption machine, a first signature value is obtained, including: Decrypting the first private key stored in the hardware encryption machine through the hardware encryption machine to obtain a first decrypted private key; The first decryption private key is used to sign the signature original to obtain a first signature value.
3. The collaborative signature method according to claim 1, characterized in that: The first FIDO message includes a FIDO authentication policy for limiting the use of the second private key for signing; The second signature value is obtained by the biometric client performing biometric authentication based on the first FIDO message using the binding relationship between the second private key in the TEE and the corresponding biometric feature, and signing the signature original text using the second private key upon successful authentication; The second private key is generated by the biometric client based on receiving the second FIDO message for biometric authentication, and upon successful authentication, using a preset national secret algorithm to generate a second key component, and binding the private key in the second key component to the corresponding biometric feature and storing the result in the trusted execution environment; The second FIDO message is generated by the biometric identification server based on the second FIDO request and corresponds to the FIDO authentication policy and sent in the form of a message, wherein the second FIDO message includes a FIDO authentication policy for limiting the storage of the second private key; The second FIDO request is generated based on storing the first private key and sent to the biometric service end.
4. The collaborative signature method according to claim 3, characterized in that: The second signature value and the third signature value are sent by the biometric identification server after verifying the received second signature value using the previously stored second public key; The second public key is generated by the biometric client based on the second public key in the second key component and sent to the biometric server through the collaborative signature client.
5. The collaborative signature method according to claim 1, characterized in that: The first FIDO message further includes a FIDO authentication policy for limiting the use of the third private key for signing; The third signature value is obtained by the collaborative signing client authenticating the user's personal identification PIN code based on the first FIDO message, and upon successful authentication, obtaining a third decryption key based on the temporary key and the third private key in the memory, and signing the original signature using the third decryption key; The third private key is generated by the collaborative signing client based on receiving the second FIDO message and using a preset national secret algorithm, so as to be obtained according to the temporary key and the private key in the third key component and stored in the memory; The temporary key is generated by the collaborative signature client based on the second FIDO message using the hardware information of the device to which the memory belongs and the PIN code; The second FIDO message is generated by the biometric identification server based on the second FIDO request and corresponds to the FIDO authentication policy and sent in the form of a message, wherein the second FIDO message includes a FIDO authentication policy for limiting the storage of the second private key; The second FIDO request is generated based on storing the first private key and sent to the biometric service end.
6. The collaborative signature method according to claim 5, characterized in that: The third decryption key is obtained by the collaborative signing client deriving the temporary key using a preset key derivation algorithm and decrypting the third private key in the memory in combination with a preset block encryption algorithm; The third private key is obtained by the collaborative signature client deriving the temporary key using the preset key derivation algorithm and encrypting the private key in the third key component in combination with the preset block encryption algorithm.
7. The collaborative signature method according to claim 1, characterized in that: After sending the complete signature to the application server, the method further includes: Receive the complete signature and original signature sent by the application server; The complete signature is verified according to the original signature and the complete public key to obtain a verification result; wherein, the complete public key is generated based on the previously stored first public key and the second and third public keys sent by the biometric server, the first public key is generated based on the open signature request sent by the application client forwarded by the application server using a preset national secret algorithm, the second public key is used to represent the public key in the second key component corresponding to the second private key, the second public key is sent to the biometric server through the collaborative signature client after the biometric client stores the second private key in the TEE, and the third public key is used to represent the public key in the third key component corresponding to the third private key, the third public key is sent to the biometric server by the collaborative signature client after the collaborative signature client stores the third private key in the memory; The verification result is returned to the application server.
8. A collaborative signature device, characterized in that: include: The signature module receives the original signature sent by the application client and forwarded by the application server, and obtains a first signature value based on the original signature and a first private key previously stored in the hardware encryption machine; A signature receiving module sends a first online fast identity verification FIDO request to the biometric server, and receives a second signature value and a third signature value sent by the biometric server; wherein, the second signature value is obtained by the biometric client based on the received first FIDO message, the original signature sent by the application client, and the second private key previously stored in the trusted execution environment TEE, and is sent to the biometric server through the collaborative signature client; the third signature value is obtained by the collaborative signature client based on the received first FIDO message, the original signature sent by the application client, and the third private key previously stored in the memory, and is sent to the biometric server; the first FIDO message is the FIDO authentication policy generated by the biometric server based on the first FIDO request and sent to the biometric client and the collaborative signature client in the form of a message; The signature integration module obtains a complete signature according to the first signature value, the second signature value and the third signature value, and sends the complete signature to the application server.
9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that: When the processor executes the computer program, the collaborative signature method according to any one of claims 1 to 7 is implemented.
10. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the collaborative signature method according to any one of claims 1 to 7 is implemented.
Citation Information
Patent Citations
Key management method and system
CN111464301A
Secure communication method and system based on software password module
CN111614637A
Multi-party collaborative group signature method, device and system based on SM2 algorithm, and medium
CN112118113A
Method for realizing multipoint cooperative security signature in terminal environment
CN116760552A
Collaborative signature security opening method and system based on client device matching
CN117749384A
Cited By
Transaction signature method and device, electronic equipment and storage medium
CN121864333A
Dynamic token authentication method and device, and computer readable storage medium
CN122394812A
Dynamic token authentication method and device, and computer readable storage medium
CN122394812B