Collaborative signature method, apparatus, device and medium

By using hardware encryption machines, trusted execution environments, and distributed storage of private keys in memory, the problem of key components being easily intercepted is solved, and the security authentication strength of multi-party collaborative signatures and cross-institutional trust are achieved.

CN120639313BActive Publication Date: 2026-04-10CHINA FINANCIAL CERTIFICATION AUTHORITY
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA FINANCIAL CERTIFICATION AUTHORITY
Filing Date
2025-07-14
Publication Date
2026-04-10

AI Technical Summary

Technical Problem

In existing collaborative signature technologies, the key component is easily intercepted, which leads to the destruction of signature validity and makes it impossible to achieve cross-institutional trust and secure authentication.

Method used

The first private key is stored in a hardware encryption machine, the second private key is stored in a Trusted Execution Environment (TEE), and the third private key is stored in memory. The original text is signed by different execution entities using their respective independently stored private keys, and the complete signature is obtained by integrating them.

Benefits of technology

It enhances the security and authentication strength of signatures, ensuring that signatures are completed jointly by multiple parties and cannot be denied by any single party. Attackers would need to compromise multiple independent systems to forge signatures, thus achieving cross-institutional trust.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120639313B_ABST
    Figure CN120639313B_ABST
Patent Text Reader

Abstract

The application provides a kind of collaborative signature method, device, equipment and medium, method includes: receiving the signature original forwarded by application server, and get first signature value in combination with first private key stored in hardware encryption machine in advance;First FIDO request is sent to biological recognition server, and the second signature value and the third signature value sent by biological recognition server are received, the second signature value is obtained based on the first FIDO message, signature original and second private key stored in trusted execution environment in advance by biological recognition client and sent to biological recognition server through collaborative signature client, the third signature value is obtained based on the first FIDO message, signature original and third private key stored in memory in advance by collaborative signature client and sent to biological recognition server;According to first signature value, second signature value and third signature value, complete signature is obtained and sent to application server.The application improves the security authentication strength of collaborative signature.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of digital signature, in particular to a collaborative signature method, device, equipment and medium. BACKGROUND

[0002] With the promotion of digitalization, electronic signature technology has become a key support for security and efficiency in online transactions, contract signing, identity authentication, etc. Among many electronic signature forms, collaborative signature, as a mechanism that allows multiple parties to participate, confirm and complete the signature, has shown increasing value in the fields of finance, government affairs, supply chain management, electronic contracts, etc. It not only solves the problem that single signature cannot meet the multi-party consensus scenario, but also has significant advantages in improving process transparency and enhancing traceability.

[0003] Currently, collaborative signature technology mainly generates an independent signature component for each participant, and combines these signature components into a single valid signature, thereby verifying the authorization of all participants. However, if the local security mechanism is compromised, or the key component is intercepted during generation, transmission or use, the attacker may forge the signature component, thereby destroying the validity of the entire signature. SUMMARY

[0004] The present application provides a collaborative signature method, device, equipment and medium to solve the defect that key components are easily intercepted and the validity of the signature is destroyed in the prior art, improve the security authentication strength of collaborative signature, realize cross-institution trust, and be suitable for multi-party collaboration scenarios.

[0005] The present application provides a collaborative signature method, comprising: receiving a signature original text sent by an application client forwarded by an application server, and obtaining a first signature value according to the signature original text and a first private key previously stored in a hardware encryption machine; sending a first online fast identity verification (FIDO) request to a biometric recognition server, and receiving a second signature value and a third signature value sent by the biometric recognition server; wherein the second signature value is obtained by a biometric recognition client based on a received first FIDO message, the signature original text sent by the application client and a second private key previously stored in a trusted execution environment (TEE), and is sent to the biometric recognition server through a collaborative signature client, the third signature value is obtained by the collaborative signature client based on the received first FIDO message, the signature original text sent by the application client and a third private key previously stored in the memory, and is sent to the biometric recognition server, the first FIDO message is a FIDO authentication strategy generated by the biometric recognition server based on the first FIDO request, and is sent to the biometric recognition client and the collaborative signature client in the form of a message; obtaining a complete signature according to the first signature value, the second signature value and the third signature value, and sending the complete signature to the application server.

[0006] According to the cooperative signature method provided by the application, the first private key is symmetrically encrypted by using a hardware encryption machine for the private key in the first key component and is stored, the first key component is generated based on an application client sending an opening signature request forwarded by an application server before receiving a signature original text, and the first signature value is obtained based on the signature original text and the first private key stored in the hardware encryption machine, including: decrypting the first private key stored in the hardware encryption machine by using the hardware encryption machine to obtain a first decrypted private key; and signing the signature original text by using the first decrypted private key to obtain the first signature value.

[0007] According to the cooperative signature method provided by the application, the first FIDO message includes a FIDO authentication strategy for limiting signature by using the second private key; the second signature value is obtained by using the second private key in the TEE to perform biometric recognition authentication based on the binding relationship between the first FIDO message and the corresponding biometric feature, and based on the authentication passing, signing the signature original text by using the second private key; the second private key is obtained by using the preset national secret algorithm to generate the second key component based on the biometric recognition client performing biometric recognition authentication based on receiving the second FIDO message, and based on the authentication passing, binding the private key in the second key component with the corresponding biometric feature and storing the private key in the trusted execution environment; the second FIDO message is generated by the biometric service end based on the second FIDO request, and the corresponding FIDO authentication strategy is sent in the form of a message, and the second FIDO message includes a FIDO authentication strategy for limiting storage of the second private key; and the second FIDO request is generated and sent to the biometric service end after storing the first private key.

[0008] According to the cooperative signature method provided by the application, the second signature value and the third signature value are sent by the biometric service end after verifying the received second signature value by using the previously stored second public key, and based on the verification passing; the second public key is sent by the biometric client to the biometric service end by using the second key component after generating the second key component, and the second public key in the second key component is sent by the biometric client to the biometric service end by using the cooperative signature client.

[0009] According to the collaborative signature method provided by the application, the first FIDO message further comprises a FIDO authentication policy for limiting signature by the third private key; the third signature value is obtained by the collaborative signature client based on the first FIDO message, authenticating the user personal identification PIN code, and based on the authentication passing, obtaining the third decryption key according to the temporary key and the third private key in the memory, and then signing the signature text by the third decryption key; the third private key is obtained by the collaborative signature client based on the received second FIDO message, generating the third key component by using the preset national secret algorithm, and then obtaining and storing in the memory according to the temporary key and the private key in the third key component; the temporary key is generated by the collaborative signature client based on the second FIDO message, using the hardware information of the device to which the memory belongs and the PIN code; the second FIDO message is generated by the biometric recognition server based on the second FIDO request, corresponding FIDO authentication policy and in the form of a message, and the second FIDO message comprises a FIDO authentication policy for limiting the storage of the second private key; and the second FIDO request is generated and sent to the biometric recognition server after the first private key is stored.

[0010] According to the collaborative signature method provided by the application, the third decryption key is obtained by the collaborative signature client by deriving the temporary key by using the preset key derivation algorithm, and then decrypting the third private key in the memory by using the preset group encryption algorithm; and the third private key is obtained by the collaborative signature client by deriving the temporary key by using the preset key derivation algorithm, and then encrypting the private key in the third key component by using the preset group encryption algorithm.

[0011] According to the collaborative signature method provided by the application, after the complete signature is sent to the application server, the method further comprises: receiving the complete signature and the signature text sent by the application server; verifying the complete signature according to the signature text and the complete public key to obtain a verification result; wherein the complete public key is generated according to the first public key stored in advance and the second public key and the third public key sent by the biometric recognition server, the first public key is generated by using the preset national secret algorithm based on the opening signature request sent by the application client forwarded by the application server, the second public key is used to represent the public key corresponding to the second private key in the second key component, the second public key is sent to the biometric recognition server by the biometric recognition client after the second private key is stored in the TEE, and the third public key is used to represent the public key corresponding to the third private key in the third key component, the third public key is sent to the biometric recognition server by the collaborative signature client after the third private key is stored in the memory; and the verification result is returned to the application server.

[0012] The application further provides a cooperative signature device, comprising: a signature module, which receives a signature original sent by an application client forwarded by an application server, and obtains a first signature value according to the signature original and a first private key previously stored in a hardware encryption machine; a signature receiving module, which sends a first online fast identity verification (FIDO) request to a biometric recognition server, and receives a second signature value and a third signature value sent by the biometric recognition server; wherein the second signature value is obtained by a biometric recognition client based on a received first FIDO message, the signature original sent by the application client and a second private key previously stored in a trusted execution environment (TEE), and is sent to the biometric recognition server through a cooperative signature client; the third signature value is obtained by the cooperative signature client based on the received first FIDO message, the signature original sent by the application client and a third private key previously stored in a memory, and is sent to the biometric recognition server; the first FIDO message is a FIDO authentication strategy generated by the biometric recognition server based on the first FIDO request, and is sent to the biometric recognition client and the cooperative signature client in the form of a message; and a signature integration module, which obtains a complete signature according to the first signature value, the second signature value and the third signature value, and sends the complete signature to the application server.

[0013] The application further provides an electronic device, comprising a memory, a processor and a computer program stored in the memory and executable on the processor, wherein the processor implements the cooperative signature method according to any one of the above when executing the computer program.

[0014] The application further provides a non-transitory computer readable storage medium, which stores a computer program, wherein the computer program is executed by a processor to implement the cooperative signature method according to any one of the above.

[0015] The application further provides a computer program product, comprising a computer program, wherein the computer program is executed by a processor to implement the cooperative signature method according to any one of the above.

[0016] The application provides a cooperative signature method, device, equipment and medium, the first private key is stored in advance by using a hardware encryption machine, physical isolation and tamper-proof protection are provided, even if the system is invaded, the private key cannot be exported, thereby greatly reducing the risk of private key leakage, ensuring the security of private key storage, preventing private key from being illegally accessed or exported, the second private key is stored by using a trusted execution environment (TEE) of a biological identification client, a safer storage environment is provided, an isolated safe area is provided for the second private key, even if the operating system is attacked, the private key stored in the TEE is relatively safe, and the third private key is stored by using memory by the cooperative signature client, so that the private key is stored in different devices / environments, avoiding that a single entity masters all private keys, reducing the internal threat risk, even if a certain link is attacked, the attacker still needs to obtain other private keys to complete the complete signature, the attack cost is improved, and the signature text is signed based on the corresponding independently stored private keys of different execution subjects respectively, so that the complete signature is obtained by integration, the signature is completed by multiple parties, any party cannot deny the signature behavior alone, the credibility of the signature result is ensured, the attacker needs to attack multiple independent systems at the same time to forge the signature, thereby greatly increasing the attack difficulty, improving the security authentication strength of the cooperative signature, realizing cross-institution trust, and being suitable for a multi-party cooperation scene. BRIEF DESCRIPTION OF DRAWINGS

[0017] In order to more clearly illustrate the technical solutions in the application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiments or the prior art description. Obviously, the drawings in the following description are some embodiments of the application, and for those skilled in the art, other drawings can also be obtained without creative labor.

[0018] Figure 1 is one of the flowcharts of the cooperative signature method provided by the application;

[0019] Figure 2 is the second flowchart of the cooperative signature method provided by the application;

[0020] Figure 3 is the third flowchart of the cooperative signature method provided by the application;

[0021] Figure 4 is a structural schematic diagram of the cooperative signature device provided by the application;

[0022] Figure 5 is a structural schematic diagram of the electronic device provided by the application. DETAILED DESCRIPTION

[0023] In order to make the objects, technical solutions and advantages of the present application clearer, the technical solutions in the present application will be described clearly and completely below in combination with the drawings in the present application. Obviously, the described embodiments are only some of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative work fall within the protection scope of the present application.

[0024] Figure 1 is a flowchart of the collaborative signature method provided by the present application, as shown in Figure 1 , the method comprises:

[0025] S11, receiving the signature original sent by the application client forwarded by the application server, and obtaining a first signature value according to the signature original and in combination with the first private key stored in the hardware encryption machine in advance;

[0026] S12, sending a first online fast identity verification (FIDO) request to the biometric recognition server, and receiving a second signature value and a third signature value sent by the biometric recognition server; wherein the second signature value is obtained by the biometric recognition client based on the received first FIDO message, the signature original sent by the application client and the second private key stored in the trusted execution environment (TEE) in advance, and sent to the biometric recognition server through the collaborative signature client, the third signature value is obtained by the collaborative signature client based on the received first FIDO message, the signature original sent by the application client and the third private key stored in the memory in advance, and sent to the biometric recognition server, and the first FIDO message is the FIDO authentication strategy generated by the biometric recognition server based on the first FIDO request and sent to the biometric recognition client and the collaborative signature client in the form of a message;

[0027] S13, obtaining a complete signature according to the first signature value, the second signature value and the third signature value, and sending the complete signature to the application server.

[0028] It should be noted that the execution subject of the present method is the collaborative signature server, and the step number "S1N" in the present specification does not represent the sequence of the collaborative signature method. The collaborative signature method of the present application will be described in detail below. Figures 2-3

[0029] Step S11, receiving the signature original sent by the application client forwarded by the application server, and obtaining a first signature value according to the signature original and in combination with the first private key stored in the hardware encryption machine in advance.

[0030] ​In the embodiment, the first private key is symmetrically encrypted and stored by the hardware encryption machine, and the first key component is generated by a preset national encryption algorithm based on the opening signature request sent by the application client forwarded by the application server before receiving the signature original text.

[0031] It should be noted that the collaborative signature server generates the first key component based on the opening signature request to avoid exposing the private key in the system for a long time, reduce the risk of static attacks (such as cold boot attack and persistent memory analysis), and symmetrically encrypt and store the private key in the first key component by the hardware encryption machine to ensure that the private key cannot be illegally copied or exported. Even if the hardware encryption machine is physically accessed, the attacker still needs to crack the symmetric key to obtain the private key, which increases the difficulty of attack.

[0032] In other words, before the collaborative signature server receives the signature original text sent by the application client forwarded by the application server, the application client sends an opening signature request to the application server; the application server sends the opening signature request to the collaborative signature server; the collaborative signature server generates a first key component based on the received opening signature request by using a preset national encryption algorithm, and symmetrically encrypts the private key in the first key component by using the hardware encryption machine to store the first private key obtained by symmetric encryption in the hardware encryption machine and store the first public key in the first key component in the collaborative signature server.

[0033] In addition, according to the signature original text, the first private key stored in the hardware encryption machine is combined to obtain the first signature value, which includes: decrypting the first private key stored in the hardware encryption machine by the hardware encryption machine to obtain a first decrypted private key; and signing the signature original text by using the first decrypted private key to obtain the first signature value. It should be noted that the private key decryption and signature operation is quickly completed in the controlled environment of the hardware encryption machine to reduce the time of exposing the private key in the system, thereby significantly improving the security of the signature process.

[0034] In step S12, a first online fast identity verification (FIDO) request is sent to the biometric recognition server, and a second signature value and a third signature value sent by the biometric recognition server are received; the second signature value is obtained by the biometric recognition client based on the received first FIDO message, the signature original text sent by the application client, and the second private key stored in the trusted execution environment (TEE) in advance, and is sent to the biometric recognition server through the collaborative signature client; the third signature value is obtained by the collaborative signature client based on the received first FIDO message, the signature original text sent by the application client, and the third private key stored in the memory in advance, and is sent to the biometric recognition server; and the first FIDO message is a FIDO authentication strategy generated by the biometric recognition server based on the first FIDO request and sent to the biometric recognition client and the collaborative signature client in the form of a message.

[0035] It should be noted that the application client sends to the biometric client and the biometric client The original text of the signature can be sent at the same time as the original text of the signature sent to the collaborative signature server through the application server, or can be sent before the biometric client and the biometric client sign the original text of the signature. The specific design requirements can be set, and this place is not further limited.

[0036] In addition, after the collaborative signature server obtains the first signature value, the collaborative signature server generates a first Fast Identity Online (FIDO for short) request and sends it to the biometric service server; the biometric service server generates a FIDO authentication policy based on the first FIDO request, and obtains a first FIDO message in the form of a message, and sends the first FIDO message to the biometric client and the collaborative signature client respectively; the biometric client obtains a second signature value based on the received first FIDO message, the signature original text and the second private key stored in the trusted execution environment TEE in advance, and sends the second signature value to the collaborative signature client; the collaborative signature client obtains a third signature value based on the received first FIDO message, the signature original text and the third private key stored in the memory in advance, and sends the third signature value and the received second signature value to the biometric service server.

[0037] Further, the first FIDO request includes a challenge value, a user identifier, an authenticator requirement, a security parameter and an application identifier, wherein: the challenge value is randomly generated data, used to ensure the uniqueness of each authentication and prevent replay attacks; the user identifier is used to uniquely identify the requesting user and ensure that the authentication is bound to a specific user; the authenticator requirement is used to limit whether to support biometric or physical devices, such as requiring the biometric client to support biometric authentication, including fingerprint, face and other recognition, and requiring the collaborative signature client to support physical devices such as personal identification number (PIN for short), The specific authenticator requirement can be set according to the actual design requirements, and this place is not further limited; the security parameter is used to limit whether the user needs to interact (such as pressing the fingerprint), whether the device needs to be bound (such as setting the PIN code), etc.; the application identifier is used to identify the application or service that initiates the request, and to ensure that the authentication policy is bound to the correct application. Through the above content, to ensure the customization and security of the authentication policy, while meeting the needs of different scenarios.

[0038] In the embodiment, the first FIDO message includes a FIDO authentication policy for defining the signature with the second private key; the second signature value is obtained by the biometric client based on the first FIDO message, performing biometric authentication with the binding relationship between the second private key in the TEE and the corresponding biometric feature, and based on the authentication passing, signing the signature text with the second private key. It should be noted that the biometric client needs to be activated by biometric authentication to avoid illegal use of the private key, ensure that the signature operation can only be completed by the authorized user, and transfer the transmission task to the co-signing client to reduce the risk of exposing the biometric client directly to the attack path.

[0039] It should be noted that after the biometric client generates the second signature value, the first message is generated based on the second signature value, and the first message and the second signature value are sent to the co-signing client to be sent to the biometric server through the co-signing client.

[0040] In addition, the second private key is based on the biometric client receiving the second FIDO message to perform biometric authentication, and based on the authentication passing, generating the second key component with the preset national secret algorithm, and binding the private key in the second key component with the corresponding biometric feature and storing it in the trusted execution environment; the second FIDO message is generated by the biometric server based on the second FIDO request to generate the corresponding FIDO authentication policy and send it in the form of a message, and the second FIDO message includes a FIDO authentication policy for defining the storage of the second private key; the second FIDO request is generated and sent to the biometric server after storing the first private key.

[0041] It should be noted that the co-signing client sets more stringent PIN code attempt limits (such as fewer attempt times, longer lock time) based on the authentication policy defined by the first FIDO message to increase the difficulty of unauthorized access and use, effectively prevent brute force cracking, and encrypt the third private key in the memory, which ensures the security of the third private key while improving access speed and reducing hardware cost.

[0042] In addition, after the co-signing server stores the first private key obtained by symmetric encryption into the hardware encryption machine, the co-signing server generates a second FIDO request and sends it to the biometric recognition server; the biometric recognition server generates a FIDO authentication strategy based on the second FIDO request, and obtains a second FIDO message in the form of a message, and sends the second FIDO message to the biometric recognition client and the co-signing client respectively; the biometric recognition client performs biometric recognition based on the received second FIDO message, and based on the authentication passing, generates a second key component using a preset national secret algorithm, and binds the private key in the second key component with the corresponding biometric feature and stores it in a trusted execution environment (Trusted Execution Environment, referred to as TEE). It should be noted that the second FIDO request can refer to the first FIDO request described above, which will not be repeated here.

[0043] Further, after the biometric recognition client stores the corresponding private key in the TEE, it also generates a first FIDO signature value based on the stored private key, and sends the first FIDO signature value and the second public key in the second key component to the co-signing client, to be sent to the biometric recognition server through the co-signing client.

[0044] In this embodiment, the first FIDO message also includes a FIDO authentication strategy signed with a third private key; the third signature value is obtained by the co-signing client based on the first FIDO message, authenticating the user's personal identification PIN code, and based on the authentication passing, obtaining a third decryption key from the temporary key and the third private key in the memory, to sign the signature text with the third decryption key. It should be noted that the co-signing client authenticates the PIN code based on the authentication strategy defined by the first FIDO message, which improves the difficulty of unauthorized access and use, effectively prevents brute force cracking, and decrypts the third key using the temporary key to sign the signature text, thereby minimizing the time window of the private key existing in the memory in plaintext form, reducing the risk of private key leakage due to memory dump or other memory attacks.

[0045] It should be noted that the PIN code can be set by the user in advance, and the temporary key can be referred to in the following description, which will not be repeated here. In addition, after generating the third signature value, the co-signing client sends the third signature value, the first message and the second signature value to the biometric recognition server.

[0046] Further, the third decryption key is obtained by the co-signing client deriving the temporary key using a preset key derivation algorithm, and decrypting the third private key in the memory using a preset group encryption algorithm.

[0047] In addition, the third private key is generated by the co-signing client based on the received second FIDO message, using a preset national secret algorithm to generate a third key component, and based on the temporary key and the private key in the third key component to obtain and store in the memory.

[0048] It should be noted that the co-signing server generates a third key component based on the received second FIDO message, using a preset national secret algorithm, and generates a temporary key using the hardware information and PIN code of the device to which the memory belongs, to obtain a third private key based on the temporary key and the private key in the third key component and store it in the memory.

[0049] Further, the temporary key can also be generated based on the hardware information and PIN code of the device to which the memory belongs, in combination with a random SALT salt value, using a preset key generation algorithm, such as when the preset key generation algorithm uses the national secret algorithm SM3, the temporary key Temp = SM3 (device hardware information + PIN + SALT salt value).

[0050] Further, the third private key is derived by the co-signing client using a preset key derivation algorithm on the temporary key, and combined with a preset group encryption algorithm to encrypt the private key in the third key component.

[0051] It should be noted that the preset key derivation algorithm can be selected according to actual design requirements, such as a key derivation function (Key Derivation Function, abbreviated as SM2_KDF), etc., which is not further limited here; the temporary key Temp is derived to obtain an initial vector IV and a key key_sm4 used by the national secret SM4 algorithm, represented as (IV, key_sm4) =SM2_KDF(Temp), IV can usually be a random or pseudo-random value used to enhance the security of encryption.

[0052] In addition, the preset group encryption algorithm can be selected according to actual design requirements, such as the cipher block chaining mode (SM4_CBC) based on the group cipher algorithm SM4, etc., which is not further limited here; the third private key is represented as E(SKc)=SM4_CBC_Encrypt(IV, key_sm4, SKc), where SKc represents the private key in the third key component, and SM4_CBC_Encrypt represents the encryption operation of the SM4 algorithm in the CBC mode, which is to convert plaintext data into ciphertext data through the SM4 algorithm and the CBC mode.

[0053] Further, the collaborative signature client sends the third public key in the third key component to the biometric server together with the first and second public keys after storing the corresponding private key in the memory.

[0054] In an optional embodiment, the second signature value and the third signature value are sent by the biometric server after verifying the received second signature value with the second public key stored in advance, and the second public key is sent by the biometric client to the biometric server through the collaborative signature client after generating the second key component.

[0055] It should be noted that the biometric server verifies the second signature value with the second public key after receiving the second signature value and the third signature value, and sends the second signature value and the third signature value to the collaborative signature server based on the verification, so that the collaborative signature server obtains the complete signature based on the first signature value generated in advance, combined with the received second signature value and third signature value.

[0056] It should be noted that the preset national cryptographic algorithm used by the collaborative signature server to generate the first key component, the preset national cryptographic algorithm used by the biometric client to generate the second key component, and the preset national cryptographic algorithm used by the collaborative signature client to generate the third key component are the same algorithm.

[0057] Step S13, obtaining a complete signature according to the first signature value, the second signature value and the third signature value, and sending the complete signature to the application server.

[0058] In an optional embodiment, after sending the complete signature to the application server, it further includes: receiving the complete signature and the signature original text sent by the application server; verifying the complete signature according to the signature original text and the complete public key to obtain a verification result; wherein the complete public key is generated according to the first public key stored in advance and the second public key and the third public key sent by the biometric server, the first public key is generated based on the application client sending the start signature request forwarded by the application server in advance using the preset national cryptographic algorithm, the second public key is used to represent the public key corresponding to the second private key in the second key component, the second public key is sent by the biometric client to the biometric server through the collaborative signature client after storing the second private key in the TEE, and the third public key is used to represent the public key corresponding to the third private key in the third key component, the third public key is sent by the collaborative signature client to the biometric server after storing the third private key in the memory; and returning the verification result to the application server.

[0059] In an optional embodiment, with reference to Figure 2 Before the collaborative signature server receives the signature original text sent by the application client forwarded by the application server, it includes:

[0060] The application client sends an opening signature request to the application server;

[0061] The application server sends the opening signature request to the collaborative signature server;

[0062] The collaborative signature server generates a first key component based on the opening signature request using a preset national encryption algorithm, and uses a hardware encryption machine to symmetrically encrypt and store the private key in the first key component to obtain a first private key, and stores a first public key in the first key component to the collaborative signature server, and generates a second FIDO request and sends it to the biometric recognition server;

[0063] The biometric recognition server generates a corresponding FIDO authentication strategy based on the second FIDO request and sends it to the biometric recognition client and the collaborative signature client in the form of a message;

[0064] The biometric recognition client performs biometric recognition based on the second FIDO, and based on the authentication passing, generates a second key component using a preset national encryption algorithm, and binds the private key in the second key component with the corresponding biometric recognition feature and stores it in the TEE, and generates a first FIDO signature value, and sends the first FIDO signature value and a second public key in the second key component to the collaborative signature client;

[0065] The collaborative signature client generates a third key component based on the second FIDO message using a preset national encryption algorithm, and generates a temporary key using the hardware information of the memory belonging device and the PIN code, to obtain a third private key based on the temporary key and the private key in the third key component and store it in the memory, and send the third public key in the third key component, the first FIDO signature value and the second public key to the biometric recognition server;

[0066] The biometric recognition server stores the second public key and sends the second public key and the third public key to the collaborative signature server;

[0067] The collaborative signature server generates a complete public key based on the previously stored first public key and the received second public key and third public key for subsequent verification of the complete signature.

[0068] It should be noted that the specific implementation details can be referred to the above description, which will not be described in detail here.

[0069] In an optional embodiment, referring to Figure 3 The method comprises:

[0070] The application client sends a signature original text to the application server;

[0071] The application server sends the signature original text to the collaborative signature server;

[0072] The co-signature server decrypts the first private key stored in the hardware encryption machine based on the received signature original text by using the hardware encryption machine, and signs the signature original text by using the first decrypted private key obtained by decryption to obtain a first signature value, and sends a first FIDO request to the biometric recognition server;

[0073] The biometric recognition server generates a corresponding FIDO authentication strategy based on the first FIDO request and sends the FIDO authentication strategy in a message form to the biometric recognition client and the co-signature client respectively;

[0074] The biometric recognition client performs biometric recognition authentication by using the binding relationship between the second private key in the TEE and the corresponding biometric feature based on the first FIDO message, and performs signature on the signature original text by using the second private key to obtain a second signature value based on the authentication passing, and generates a first message, and sends the second signature value and the first message to the co-signature client;

[0075] The co-signature client performs authentication on the PIN code based on the first FIDO message, and obtains a third decryption key based on the temporary key and the third private key in the memory based on the authentication passing, performs signature on the signature original text by using the third decryption key to obtain a third signature value, and sends the third signature value, the first message and the second signature value to the biometric recognition server;

[0076] The biometric recognition server verifies the second signature value by using the second public key, and sends the second signature value and the third signature value to the co-signature server based on the verification passing.

[0077] The co-signature server obtains a complete signature based on the first signature value, the second signature value and the third signature value, and sends the complete signature to the application server.

[0078] In an optional embodiment, after the co-signature server sends the complete signature to the application server, the application server can also initiate a signature verification process in subsequent business processing. Specifically, continuing to refer to Figure 3 The method further comprises:

[0079] The application server sends the complete signature and the signature original text to the co-signature server.

[0080] The co-signature server verifies the complete signature based on the signature original text and the complete public key to obtain a verification result, and returns the verification result to the application server.

[0081] It should be noted that the specific implementation details can be referred to the description above, and will not be described in detail here.

[0082] In summary, the embodiment of the present application pre-stores the first private key by using the hardware encryption machine to provide physical isolation and tamper-proof protection, so that the private key cannot be exported even if the system is invaded, thereby greatly reducing the risk of private key leakage, ensuring the security of private key storage, preventing illegal access or export of the private key, storing the second private key by the biometric identification client using the trusted execution environment (TEE) to provide a safer storage environment and provide an isolated secure area for the second private key, so that the private key stored in the TEE is relatively safe even if the operating system is attacked, and storing the third private key by the collaborative signature client using the memory, so that the private key is stored in different devices / environments, avoiding a single entity from holding all the private keys, reducing the risk of internal threats, even if a certain link is attacked, the attacker still needs to obtain other private keys to complete the complete signature, thereby increasing the attack cost, and signing the signature text based on different execution subjects using the corresponding independently stored private keys to integrate the complete signature, ensuring that the signature is completed by multiple parties, and no one can deny the signature behavior, thereby ensuring the credibility of the signature result, and the attacker needs to attack multiple independent systems to forge the signature, thereby greatly increasing the difficulty of attack, improving the security authentication strength of the collaborative signature, realizing cross-institution trust, and being applicable to multi-party collaboration scenarios.

[0083] The collaborative signature device provided by the present application is described below, and the collaborative signature device described below can be referred to in correspondence with the collaborative signature method described above.

[0084] Figure 4 A structural schematic diagram of a collaborative signature device is shown, and the device comprises:

[0085] The signature module 41 receives the signature text sent by the application client forwarded by the application server, and obtains a first signature value according to the signature text and the first private key pre-stored in the hardware encryption machine;

[0086] The signature receiving module 42 sends a first online fast identity verification (FIDO) request to the biometric identification server and receives the second signature value and the third signature value sent by the biometric identification server; the second signature value is obtained by the biometric identification client based on the received first FIDO message, the signature text sent by the application client, and the second private key pre-stored in the trusted execution environment (TEE) and sent to the biometric identification server through the collaborative signature client, the third signature value is obtained by the collaborative signature client based on the received first FIDO message, the signature text sent by the application client, and the third private key pre-stored in the memory and sent to the biometric identification server, and the first FIDO message is the FIDO authentication strategy generated by the biometric identification server based on the first FIDO request and sent to the biometric identification client and the collaborative signature client in the form of a message;

[0087] The signature integration module 43 obtains a complete signature according to the first signature value, the second signature value and the third signature value, and sends the complete signature to the application server.

[0088] It should be noted that the device principle of the embodiment of the present application is the same as the principle of the method embodiment described above, and specific reference can be made to the method embodiment described above. Here, more detailed explanation is not repeated.

[0089] Figure 5 An example of an electronic device entity structure schematic diagram is shown in Figure 5 As shown, the electronic device can include a processor 510, a communications interface 520, a memory 530 and a communications bus 540, wherein the processor 510, the communications interface 520 and the memory 530 complete mutual communication through the communications bus 540. The processor 510 can invoke the logical instructions in the memory 530 to execute the cooperative signature method, which includes receiving the signature original sent by the application client forwarded by the application server, and obtaining the first signature value according to the signature original and the first private key stored in the hardware encryption machine in advance; sending the first online fast identity verification FIDO request to the biometric recognition server, and receiving the second signature value and the third signature value sent by the biometric recognition server; wherein the second signature value is obtained by the biometric recognition client based on the received first FIDO message, the signature original sent by the application client and the second private key stored in the trusted execution environment TEE in advance, and sent to the biometric recognition server through the cooperative signature client, the third signature value is obtained by the cooperative signature client based on the received first FIDO message, the signature original sent by the application client and the third private key stored in the memory in advance, and sent to the biometric recognition server, the first FIDO message is the FIDO authentication strategy generated by the biometric recognition server based on the first FIDO request, which is sent to the biometric recognition client and the cooperative signature client in the form of a message; obtaining the complete signature according to the first signature value, the second signature value and the third signature value, and sending the complete signature to the application server.

[0090] In addition, the logic instructions in the memory 530 described above can be implemented in the form of a software function unit and sold or used as an independent product, which can be stored in a computer readable storage medium. Based on such understanding, the technical solutions of the present application essentially or the part that contributes to the prior art or part of the technical solutions can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a plurality of instructions to make a computer device (which can be a personal computer, a server, or a network device, etc.) execute all or part of the steps of the methods described in various embodiments of the present application. The foregoing storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a magnetic disk or an optical disk, and various media that can store program codes.

[0091] In another aspect, the present application also provides a computer program product, which comprises a computer program, the computer program can be stored on a non-transitory computer readable storage medium, and the computer program can be executed by a processor, so that the computer can execute the collaborative signature method provided by the above-mentioned methods, which comprises: receiving the signature original sent by the application client forwarded by the application server, and obtaining the first signature value according to the signature original and the first private key stored in the hardware encryption machine in advance; sending the first online fast identity verification (FIDO) request to the biometric recognition server, and receiving the second signature value and the third signature value sent by the biometric recognition server; wherein the second signature value is obtained by the biometric recognition client based on the received first FIDO message, the signature original sent by the application client and the second private key stored in the trusted execution environment (TEE) in advance, and sent to the biometric recognition server through the collaborative signature client, the third signature value is obtained by the collaborative signature client based on the received first FIDO message, the signature original sent by the application client and the third private key stored in the memory in advance, and sent to the biometric recognition server, the first FIDO message is the FIDO authentication strategy generated by the biometric recognition server based on the first FIDO request and sent to the biometric recognition client and the collaborative signature client in the form of a message; obtaining the complete signature according to the first signature value, the second signature value and the third signature value, and sending the complete signature to the application server.

[0092] In yet another aspect, the present application also provides a non-transitory computer readable storage medium having stored thereon a computer program, which, when executed by a processor, implements the collaborative signature method provided by the above method, and the method comprises: receiving the signature original sent by the application client forwarded by the application server, and obtaining a first signature value according to the signature original and in combination with a first private key stored in the hardware encryption machine in advance; sending a first online fast identity verification (FIDO) request to the biometric recognition server, and receiving a second signature value and a third signature value sent by the biometric recognition server; the second signature value is obtained by the biometric recognition client based on the received first FIDO message, the signature original sent by the application client and a second private key stored in the trusted execution environment (TEE) in advance, and sent to the biometric recognition server through the collaborative signature client, the third signature value is obtained by the collaborative signature client based on the received first FIDO message, the signature original sent by the application client and a third private key stored in the memory in advance, and sent to the biometric recognition server, and the first FIDO message is a FIDO authentication strategy generated by the biometric recognition server based on the first FIDO request and sent to the biometric recognition client and the collaborative signature client in the form of a message; obtaining a complete signature according to the first signature value, the second signature value and the third signature value, and sending the complete signature to the application server.

[0093] The device embodiments described above are only schematic, wherein the units illustrated as separate components may or may not be physically separate, and the components illustrated as units may or may not be physical units, i.e., may be located in one place, or may be distributed on a plurality of network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the present embodiment. Those skilled in the art can understand and implement without creative labor.

[0094] From the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be realized by means of software plus necessary universal hardware platforms, and of course can also be realized by hardware. Based on such understanding, the above technical solutions, essentially or in other words, the part that contributes to the prior art can be embodied in the form of a software product, which can be stored in a computer readable storage medium, such as a ROM / RAM, a magnetic disk, an optical disk, etc., and includes a plurality of instructions to make a computer device (which can be a personal computer, a server, or a network device, etc.) execute the methods described in each embodiment or some parts of the embodiments.

[0095] It should be pointed out finally that the above embodiments are only used to illustrate the technical solutions of the present application, but not to limit the same; and although the present application has been described in detail with reference to the foregoing embodiments, it should be appreciated by those skilled in the art that the technical solutions recorded in the foregoing embodiments can be modified, or some technical features thereof can be replaced equivalently; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application.

Claims

1. A method of co-signing, characterized by, The application comprises the following steps: receiving the signature plaintext sent by the application client forwarded by the application server, and obtaining a first signature value according to the signature plaintext and the first private key stored in the hardware encryption machine in advance; sending a first online fast identity verification (FIDO) request to the biometric recognition server, and receiving a second signature value and a third signature value sent by the biometric recognition server; the second signature value is obtained by the biometric recognition client based on the received first FIDO message, the signature plaintext sent by the application client, and the second private key stored in the trusted execution environment (TEE) in advance, and is sent to the biometric recognition server through the collaborative signature client; the third signature value is obtained by the collaborative signature client based on the received first FIDO message, the signature plaintext sent by the application client, and the third private key stored in the memory in advance, and is sent to the biometric recognition server; the first FIDO message is the FIDO authentication strategy generated by the biometric recognition server based on the first FIDO request, and is sent to the biometric recognition client and the collaborative signature client in the form of a message; obtaining a complete signature according to the first signature value, the second signature value, and the third signature value, and sending the complete signature to the application server.

2. The method of collaborative signing of claim 1, wherein, The first private key is symmetrically encrypted by the hardware encryption machine, and the first key component is generated based on the start signature request sent by the application client forwarded by the application server before the signature plaintext is received. According to the signature plaintext, the first private key stored in the hardware encryption machine in advance is combined to obtain a first signature value, which comprises the following steps: decrypting the first private key stored in the hardware encryption machine through the hardware encryption machine to obtain a first decrypted private key; using the first decrypted private key to sign the signature plaintext to obtain a first signature value. The first FIDO message includes a FIDO authentication strategy signed by the second private key; 3. The method of collaborative signing of claim 1, wherein, The second signature value is obtained by the biometric recognition client based on the first FIDO message, using the second private key in the TEE to perform biometric recognition authentication of the binding relationship of the corresponding biometric feature, and based on the authentication passing, using the second private key to sign the signature plaintext; The second private key is obtained by the biometric recognition client based on the received second FIDO message to perform biometric recognition authentication, and based on the authentication passing, using a preset national encryption algorithm to generate a second key component, and binding the private key in the second key component with the corresponding biometric feature and storing it in the trusted execution environment; The second FIDO message is the corresponding FIDO authentication strategy generated by the biometric recognition server based on the second FIDO request and sent in the form of a message, and the second FIDO message includes a FIDO authentication strategy for defining the storage of the second private key; The second FIDO request is generated and sent to the biometric recognition server after storing the first private key. ​ 4. The method of collaborative signing of claim 3, wherein, The second signature value and the third signature value are verified by the biometric server using the second public key stored in advance, and sent after verification; The second public key is sent by the biometric client to the biometric server through the co-signature client after generating the second key component.

5. The method of collaborative signing of claim 1, wherein, The first FIDO message further includes a FIDO authentication policy signed by the third private key; The third signature value is obtained by the co-signature client based on the first FIDO message, and the user's personal identification PIN code is authenticated, and based on the authentication, a third decryption key is obtained according to the temporary key and the third private key in the memory, so that the signature text is signed by the third decryption key to obtain; The third private key is generated by the co-signature client based on the received second FIDO message, using a preset national secret algorithm to generate a third key component, so that a private key in the third key component is obtained and stored in the memory according to the temporary key; The temporary key is generated by the co-signature client based on the second FIDO message, using the hardware information of the device to which the memory belongs and the PIN code; The second FIDO message is generated by the biometric server based on the second FIDO request, and the corresponding FIDO authentication policy is sent in the form of a message, and the second FIDO message includes a FIDO authentication policy for defining the storage of the second private key; The second FIDO request is generated and sent to the biometric server after storing the first private key.

6. The method of collaborative signing of claim 5, wherein, The third decryption key is obtained by the co-signature client using a preset key derivation algorithm to derive the temporary key, and combining a preset group encryption algorithm to decrypt the third private key in the memory; The third private key is obtained by the co-signature client using the preset key derivation algorithm to derive the temporary key, and combining the preset group encryption algorithm to encrypt the private key in the third key component.

7. The method of collaborative signing of claim 1, wherein, After sending the complete signature to the application server, it further includes: Receiving the complete signature and the signature text sent by the application server; verify the complete signature according to the signature original and the complete public key, to obtain a verification result; wherein the complete public key is generated according to a first public key stored in advance and a second public key and a third public key sent by the biometric recognition server, the first public key is generated by a preset national secret algorithm based on the application client sending an opening signature request forwarded by the application server in advance, the second public key is used to represent the public key in the second key component corresponding to the second private key, the second public key is sent by the biometric recognition client to the biometric recognition server through the collaborative signature client after storing the second private key in the TEE, and the third public key is used to represent the public key in the third key component corresponding to the third private key, the third public key is sent by the collaborative signature client to the biometric recognition server after storing the third private key in the memory; return the verification result to the application server.

8. A co-signing apparatus characterized by comprising: Comprise: a signature module, receiving the signature original sent by the application client forwarded by the application server, and obtaining a first signature value according to the signature original and the first private key stored in the hardware encryption machine in advance; a signature receiving module, sending a first online fast identity verification (FIDO) request to the biometric recognition server, and receiving the second signature value and the third signature value sent by the biometric recognition server; wherein the second signature value is obtained by the biometric recognition client based on the received first FIDO message, the signature original sent by the application client and the second private key stored in the trusted execution environment (TEE) in advance, and sent to the biometric recognition server through the collaborative signature client, the third signature value is obtained by the collaborative signature client based on the received first FIDO message, the signature original sent by the application client and the third private key stored in the memory in advance, and sent to the biometric recognition server, and the first FIDO message is the FIDO authentication strategy generated by the biometric recognition server based on the first FIDO request, which is sent to the biometric recognition client and the collaborative signature client in the form of a message respectively; a signature integration module, obtaining a complete signature according to the first signature value, the second signature value and the third signature value, and sending the complete signature to the application server.

9. An electronic device comprising a memory, a processor, and a computer program stored on the memory and running on the processor, characterized in that, The processor executes the computer program to realize the collaborative signature method of any one of claims 1 to 7. 10.A non-transitory computer-readable storage medium having stored thereon a computer program, characterized in that, The computer program is executed by the processor to realize the collaborative signature method of any one of claims 1 to 7.

Citation Information

Patent Citations

  • Secure communication method and system based on software password module

    CN111614637A

  • Multi-party collaborative group signature method, device and system based on SM2 algorithm, and medium

    CN112118113A