Modular digital signature service construction method
By modularizing abstraction and combining digital signature services, the rigidity and poor scalability of traditional digital signature services are solved, and a flexible and scalable digital signature service system is implemented to adapt to diverse needs and compliance requirements.
Patent Information
- Application Number
- CN202510723299.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-30
- Publication Date
- 2025-09-16
AI Technical Summary
Existing digital signature technologies face severe challenges in key management, identity authentication, and compliance adaptation, making it difficult to build a digital signature service system that is flexible, compliant, and scalable.
A modular digital signature service construction method is adopted, and the digital signature service is abstracted into six core modules: signature hosting service, certificate management and authorization service, identity management service, software product module, signature tool module and custom service. It supports flexible selection and combination to realize a customizable and scalable digital signature service system.
The adaptability of digital signature services has been significantly improved to meet different application scenarios and diverse compliance requirements, reduce system coupling, and achieve more flexible and convenient service deployment and maintenance.
Smart Images

Figure CN120658400A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of software engineering, and in particular to a modular digital signature service construction method. Background Art
[0002] Digital signature technology, as a core means of ensuring the authenticity and integrity of electronic data, plays a vital role in modern information security. With the accelerated advancement of digital transformation, digital signature technology has been widely adopted in key areas such as e-government, financial transactions, and software distribution. Based on asymmetric encryption algorithms, digital signature technology uses private key signatures and public key verification mechanisms to ensure that data sources are trustworthy and have not been tampered with. However, with the increasing complexity and globalization of application scenarios, traditional digital signature technology faces significant challenges in key management, identity authentication, and regulatory compliance.
[0003] Establishing a trust system is a core task of digital signature technology. Currently, mainstream trust system solutions fall into three categories: PGP (Pretty Good Privacy) utilizes a decentralized trust model, establishing a trust network through mutual authentication between users. While flexible, this model also carries high management costs. PKI (Public Key Infrastructure) relies on centralized certificate authorities (CAs) to build a hierarchical trust chain. While this structure is clear, it carries the risk of single points of failure. Hybrid models attempt to combine the advantages of both. Traditional digital signature technology requires users to maintain and establish a trust system, requiring significant human and material resources. This is one of the main obstacles to its widespread adoption. Key Management Systems (KMS) simplify management by hosting user private keys, but this results in users losing control of their keys. The recently emerged Sigstore technology system innovatively employs transparent logging and keyless signature technologies. It also leverages OIDC (OpenID Connect) identity binding and short-term certificate mechanisms, significantly enhancing the ease of use of digital signature technology while ensuring security. However, its service architecture suffers from regional limitations in terms of algorithms, privacy protection, and software format compatibility. While these technical solutions each offer advantages in specific scenarios, none fully address the diverse needs of digital signature services.
[0004] Therefore, how to build a digital signature service system that is flexible, compliant and scalable has become an important technical challenge that the industry urgently needs to overcome. Summary of the Invention
[0005] The present invention provides a modular digital signature service construction method, which solves the problem in the prior art that the digital signature service architecture is rigid and difficult to adapt to the needs of diverse scenarios, and realizes the construction of a customizable and scalable digital signature service system through modular abstraction and flexible combination.
[0006] The present invention provides a modular digital signature service construction method, comprising the following steps: Select core process modules according to demand instructions; Determine the corresponding key operation module based on the selected core process module; Combining the core process module and the key operation module to obtain a modular digital signature service; The key operation module is obtained by abstracting the key operations in the digital signature service, including the signature hosting service module, the certificate management and authorization service module, the identity management service module, the software product module, the signature tool module and the custom service module; The core process module is implemented based on the abstract interaction interface of the key operation module, and different core process modules correspond to multiple digital signature service processes.
[0007] According to the modular digital signature service construction method provided by the present invention, the signature hosting service is abstracted into a signature hosting service module, which specifically includes: initializing the signature hosting service; determining a signature record uploading method based on the initialized signature hosting service, and the signature record uploading method is used to upload the signature record to the signature hosting service; determining a signature record acquisition method based on the initialized signature hosting service, and the signature record acquisition method is used to obtain the signature record in the signature hosting service based on the unique ID of the signature record or the content of the signature record; determining a signature record verification method based on the initialized signature hosting service, and the signature record verification method is used to verify whether the complete signature record exists in the signature hosting service and verify the legitimacy of the certificate validity period in the signature record; determining a signature record parsing method based on the initialized signature hosting service, and the signature record parsing method is used to parse the signature record into a signature, a certificate and related information; encapsulating the signature record upload method, the signature record acquisition method, the signature record verification method and the signature record parsing method to obtain the signature hosting service module.
[0008] According to the modular digital signature service construction method provided by the present invention, the certificate management and authorization service is abstracted into a certificate management and authorization service module, which specifically includes: initializing the certificate management and authorization service; determining a certificate acquisition method based on the initialized certificate management and authorization service, and the certificate acquisition method is used to request a signature certificate; determining a certificate verification method based on the initialized certificate management and authorization service, and the certificate verification method is used to verify the signature certificate, and the verification content includes the integrity and credibility of the signature certificate content and the legitimacy of the validity period of the signature certificate; determining a root trust acquisition method based on the initialized certificate management and authorization service, and the root trust acquisition method is used to obtain the trust root and intermediate certificates of the certificate management service; encapsulating the certificate acquisition method, the certificate verification method and the root trust acquisition method to obtain the certificate management and authorization service module.
[0009] According to the modular digital signature service construction method provided by the present invention, the identity management service is abstracted into an identity management service module, which specifically includes: initializing the identity management service; determining an identity acquisition method based on the initialized identity management service, the identity acquisition method being used to verify the applicant information and issue a legal digital identity; determining an identity authentication method based on the initialized identity management service, the identity authentication method being used to verify the legitimacy of the digital identity; and encapsulating the identity acquisition method and the identity authentication method to obtain the identity management service module.
[0010] According to the modular digital signature service construction method provided by the present invention, the software product service is abstracted into a software product service module, which specifically includes: initializing the software product service; determining a product type judgment method based on the initialized software product service, the product type judgment method being used to judge the product format; determining a signature data acquisition method based on the initialized software product service, the signature data acquisition method being used to extract target signature data according to the product format; determining a digest calculation method based on the initialized software product service, the digest calculation method being used to calculate the digest of the target signature data; determining a signature embedding method based on the initialized software product service, the signature embedding method being used to embed the signature into the software product according to the product format; determining a signature extraction method based on the initialized software product service, the signature extraction method being used to extract the embedded signature from the software product; encapsulating the product type judgment method, the signature data acquisition method, the digest calculation method, the signature embedding method and the signature extraction method to obtain a software product module.
[0011] According to the modular digital signature service construction method provided by the present invention, the signature tool service is abstracted into a signature tool module, which specifically includes: initializing the signature tool service; determining a key pair generation method based on the initialized signature tool service, and the key pair generation method is used to generate an asymmetric key pair according to a specified algorithm; determining a public key acquisition method based on the initialized signature tool service, and the public key acquisition method is used to obtain the public key of the signature tool; determining a signing method based on the initialized signature tool service, and the signing method is used to digitally sign data according to a private key; determining a signature verification method based on the initialized signature tool service, and the signature verification method is used to verify the legitimacy of the target data and the signature according to the public key; encapsulating the key pair generation method, the public key acquisition method, the signing method and the signature verification method to obtain the signature tool module.
[0012] According to the modular digital signature service construction method provided by the present invention, the custom service is abstracted into a custom service module, which specifically includes: initializing the custom service; determining a module method list acquisition method based on the initialized custom service, and the module method list acquisition method is used to provide a method list and description defined by the current module; determining a module method access method based on the initialized custom service, and the module method access method is used to call a specified module method according to a given method name and calling method; encapsulating the module method list acquisition method and the module method access method to obtain a custom service module.
[0013] The present invention also provides a modular digital signature service construction device, comprising the following modules: A key operation determination module is used to determine multiple key operation modules based on the digital signature service process. The key operation modules are obtained by abstracting the key operations in the digital signature service, including a signature hosting service module, a certificate management and authorization service module, an identity management service module, a software product module, a signature tool module, and a custom service module; A key operation selection module is used to select the key operation module according to the demand instruction, and generate the interaction instruction of the core process module according to the selected key operation module; The key operation combination module is used to organize the key operation modules according to the interaction instructions to obtain a modular digital signature service.
[0014] The present invention also provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the modular digital signature service construction method as described above is implemented.
[0015] The present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements any of the modular digital signature service construction methods described above.
[0016] The present invention also provides a computer program product, comprising a computer program, wherein when the computer program is executed by a processor, the computer program implements any of the above-described modular digital signature service construction methods.
[0017] The present invention provides a modular digital signature service construction method with the following beneficial effects: By modularizing and abstracting the key operations of digital signature services into six core modules: signature hosting service, certificate management and authorization service, identity management service, software product processing, signature tools, and custom services, and supporting the flexible selection and combination of these modules according to actual needs, this method effectively solves the rigidity and poor scalability of traditional digital signature service architectures. This method significantly improves the adaptability of digital signature services to meet diverse application scenarios, diverse compliance requirements, and personalized technical needs. Furthermore, by decoupling modules, the system coupling is reduced, making service deployment more flexible and maintenance more convenient. Ultimately, a new generation of digital signature service systems is built that is customizable, scalable, and balances security and compliance. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] In order to more clearly illustrate the technical solutions in the present invention or the prior art, a brief introduction is given below to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0019] Figure 1 It is a schematic diagram of the PKI and PGP signature tool provided by the present invention.
[0020] Figure 2 This is a schematic diagram of the Sigstore key issuance process provided by the present invention.
[0021] Figure 3 It is a schematic diagram of the problems faced by the digital signature service provided by the present invention.
[0022] Figure 4 This is a flow chart of the modular digital signature service construction method provided by the present invention.
[0023] Figure 5 This is a diagram of the modular signature service architecture provided by the present invention.
[0024] Figure 6 This is a schematic diagram of the modules included in the core library provided by the present invention.
[0025] Figure 7 It is a core flow diagram provided by the present invention.
[0026] Figure 8 This is a schematic diagram of the signature process provided by the present invention.
[0027] Figure 9 This is a schematic diagram of the signature verification process provided by the present invention.
[0028] Figure 10 It is a structural diagram of the modular digital signature service construction device provided by the present invention.
[0029] Figure 11 It is a structural schematic diagram of the electronic device provided by the present invention. DETAILED DESCRIPTION
[0030] To make the objectives, technical solutions, and advantages of the present invention more clear, the technical solutions of the present invention will be clearly and completely described below in conjunction with the accompanying drawings. Obviously, the embodiments described are only some of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.
[0031] The English abbreviations and terms involved in the present invention are explained below.
[0032] PGP (Pretty Good Privacy) is a data encryption and digital signature application based on asymmetric encryption and adopts a decentralized trust model.
[0033] PKI (Public Key Infrastructure) is a security framework that manages the binding of public keys and identities through digital certificates and certificate authorities.
[0034] CA (Certificate Authority) is a trusted third-party organization responsible for issuing, managing and verifying digital certificates.
[0035] KMS (Key Management System) is a service system that centrally manages the entire life cycle of keys (generation, storage, rotation, and revocation).
[0036] OCI (Open Container Initiative) is an open source project that develops container image standards.
[0037] OIDC (OpenID Connect) is an authentication protocol based on OAuth 2.0, used to bind short-term keys to user identities.
[0038] GDPR (General Data Protection Regulation) is a personal data protection regulation implemented by the European Union.
[0039] DID (Decentralized Identifier) is a new type of digital identity system.
[0040] APT (Advanced Persistent Threat) refers to long-term, covert network attacks against systems.
[0041] GCP (Google Cloud Platform) is the cloud computing platform where the Signstore service is currently deployed.
[0042] Sigstore is an open source digital signature service project based on transparent log technology.
[0043] Fulcio, the certificate issuance component in Sigstore responsible for issuing short-term certificates.
[0044] Rekor, a transparent log component in Sigstore that records signature metadata.
[0045] Modularity: Breaking down a complex system or process into modules.
[0046] Digital Signature Service: A technology used to verify the authenticity and integrity of electronic data.
[0047] A digital signature (also known as a public key digital signature) is a method for signing electronic messages. It is a string of numbers that can only be generated by the sender and cannot be forged by others. This string also effectively proves the authenticity of the message sent by the sender. Recipients can use signature verification tools to confirm the document's origin and whether it has been tampered with during transmission. Digital signatures utilize digital digest technology and asymmetric key encryption. Asymmetric encryption uses an algorithm to generate a pair of keys: one for signing (private key) and the other for verification (public key). Common algorithms include RSA, DSA, and SM2. During use, the public key is publicly available, while the private key must be kept private. The issuer of the signature first calculates a digital digest of the signed data and then encrypts the digest using the private key to produce the digital signature. The digital signature is verified if and only if it can be correctly decrypted using the corresponding public key.
[0048] During the key maintenance and distribution process, it is easy to be attacked by malicious behaviors such as key theft and man-in-the-middle attacks, which may lead to key leakage or tampering, and then cause trust issues in digital signatures. At present, the use of digital certificates is the main measure to solve the trust problem. Digital certificates realize the binding of public keys and identities, and establish the user's trust in the source of the certificate through different mechanisms. They are mainly divided into three categories: PGP, PKI and hybrid methods, such as Figure 1 shown.
[0049] PGP (Pretty Good Privacy) utilizes a decentralized, end-to-end trust model. In a communication network, any node is deemed trustworthy and can be used as a source of trust. Furthermore, this trust is transmitted through the trust relationships between nodes within the network. This trust model, with its decentralized structure and open standards, effectively lowers the barrier to use and access. However, such networks are often complex, leading to high management costs.
[0050] PKI (Public Key Infrastructure) is the infrastructure for managing digital keys and certificates. The certificates and accompanying private keys generated and managed by PKI are issued by CAs (Certificate Authorities). The PKI system adopts a centralized trust model, where CAs and the root certificates they issue are considered trustworthy. Multiple CAs are organized in a tree-like structure, with the trustworthiness of each level guaranteed only by the level above. This system provides a clear and manageable structure for certificates and CAs, making it suitable for highly regulated environments. However, it also presents challenges such as high maintenance costs and single points of risk.
[0051] The hybrid approach primarily utilizes PKI management, incorporating PGP-issued certificates into management. From a PGP perspective, this is equivalent to building a two-layer trust network. Currently, open source operating systems widely adopt this hybrid approach to achieve trusted management of software package sources.
[0052] Based on the signature verification function, the digital signature service adds the management of resources such as identity, keys, and certificates, improves security and efficiency, and lowers the threshold for using digital signature technology.
[0053] KMS (Key Management System) is a common way to implement digital signature services, and its core positioning is the full life cycle management of keys. KMS usually integrates digital signature capabilities, including key generation, storage, rotation, and revocation. Users can call the private key hosted by KMS to sign data. The private key is always protected by KMS and is not exposed to users or applications. The public key can be distributed externally to verify the validity of the signature. KMS supports non-exportable private keys, which can reduce the risk of leakage and make it easier to meet the compliance requirements for key management in scenarios requiring strong control, such as finance and government. In addition, KMS can be integrated with other services to simplify the signing process.
[0054] Sigstore is a digital signature service based on transparent log technology. The main process is as follows Figure 2 Its features include: (1) Keyless Signature mode, which supports automated key management capabilities, eliminating the need for users to manage and maintain private keys; (2) User-friendly and easy-to-use signature verification tools, which provide transparent audit logs for all operations after the product is stored, solving the mutual recognition problem of multiple CAs in traditional PKI; (3) Support for signature verification of all cloud-native products that comply with the OCI specification, as well as support for authentication and auditing of the OIDC protocol, solving the problem of signer identity authentication.
[0055] The three main operations performed by Sigstore include: (1) OIDC issuance, ensuring that the client controls its identity; (2) associating a short-term public key certificate with the client identity and publishing the certificate to the identity log; and (3) publishing the component's long-term signature to the artifact log, allowing verifiers to check its valid identity. Operations (1) and (2) are performed by the component Fulcio, which acts as the certificate authority for the OIDC identity log and is responsible for maintaining it; operation (3) is performed by the component Rekor, which is a transparent log of artifact signatures. Through these components and operations, the three main phases of Sigstore are met: trust setup, signing process, and signature verification process.
[0056] Digital signatures are a key technology for addressing open source software supply chain risks. However, whether it's signature tools like GPG or signature services like KMS and SignStore, they all face different challenges when implementing digital signature technology. This has severely hindered the widespread adoption of digital signature technology, making it difficult to effectively address risks in the open source software supply chain.
[0057] Specifically, the challenges faced by existing digital signatures in actual implementation are as follows: Figure 3 shown.
[0058] The main problem with traditional signing tools is the separate maintenance required for keys and certificates. Whether it's PGP's end-to-end trust model or PKI's centralized management structure, the high costs of managing, maintaining, and updating keys and certificates have led to a low user willingness to use these signing tools. Furthermore, complex management methods can also lead to security issues, such as malicious keys and certificates, and the leakage of key certificates.
[0059] While KMS addresses the high key and certificate management and maintenance costs associated with traditional signing tools, it also presents some challenges. The first is the issue of key management permissions. KMS's key management prevents users from fully controlling the physical storage and backup of keys. This leads to two issues: a security trust boundary and backup and disaster recovery limitations. The security trust boundary refers to the fact that users must fully trust the KMS service. Issues with permissions or advanced persistent threats (APTs) can lead to key leaks. Furthermore, KMS's own permissions or configuration issues pose the risk of security vulnerabilities. The backup and disaster recovery limitations stem from the fact that keys are completely managed by the KMS service, preventing users from managing their own keys and relying on the backup and protection mechanisms provided by the service provider. Furthermore, KMS's disaster recovery capabilities are heavily dependent on the KMS service itself, which may not align with the user's own disaster recovery strategy. Furthermore, KMS also faces functional limitations, primarily in signing and key management. In terms of signature functions, KMS signature services are provided by service providers and generally do not support user-defined algorithms. In terms of key management, the key rotation policies of some KMS are not flexible enough, such as mandatory fixed-period rotation and flexible adjustment of rotation policies, which may not meet the requirements of some regional regulations and user needs.
[0060] Compared to KMS, Sigstore's main advantage is that it connects identities with short-term keys. Based on transparent log technology and keyless signature mode, it emphasizes the openness and verifiability of signatures, which simplifies the key management process while increasing the transparency and credibility of the signing process. Sigstore's keyless signature mode reduces the risk of long-term key leakage by binding these keys to identities supported by the OIDC protocol. At the same time, Sigstore provides a transparent log mechanism. The transparent log Rekor can record the metadata of the signature in an unchangeable record. Anyone can determine whether the information is credible by querying the metadata, which increases the transparency and credibility of the signed data. The keyless signature mode and transparent log technology reduce KMS's key management authority issues, security trust boundary issues, and backup and disaster recovery limitations. However, Sigstore-related technologies still face many challenges in actual implementation, including: legal compliance, technical compatibility, service continuity, and trust system construction. Specifically as follows: 1. Legal compliance issues: (1) Sigstore involves the acquisition and transmission of personal privacy data such as email addresses, and different regions have different regulatory requirements for privacy data. (2) Traditional CAs are very strict on the identity verification of digital certificate holders, and the identity confirmation process is lengthy and complicated. Sigstore's digital certificate issuance rules also face regulatory challenges in different regions.
[0061] 2. Compatibility issues: (1) Account system compatibility issues: Sigstore supports a limited number of OIDC service providers and has a high threshold for expansion support, making it difficult for some platform users to access the service. (2) Cryptographic algorithm compatibility issues: Currently, the supported cryptographic algorithms are limited and the expansion threshold is high, which cannot meet the algorithm requirements of some specific scenarios. (3) Limited compatible product formats: Currently, only OCI images and universal binary files are supported. Other products are uniformly treated as binary files (blobs). Embedded signature protocols in formats such as RPM, KO, and UEFI are not supported, which limits the usage scenarios.
[0062] 3. Service continuity issue: All data used for verification and auditing is hosted in a fixed region (the United States). If the network service is interrupted due to geopolitical factors, the signature cannot be verified.
[0063] 4. Trust Issues: (1) The SignStore service is currently deployed on GCP, which is inconvenient to use directly. If another set is maintained in other regions around the world, data synchronization issues need to be resolved. (2) The trust root key holder can only be elected from community participating organizations, and the participation threshold of this community is high.
[0064] In summary, to address the problems of low user willingness to sign in traditional digital signature trust management systems, high adaptation costs for KMS digital signature services, and difficulty implementing Sigstore, this invention summarizes the signature processes under a large number of different application scenarios, abstracts the main features of the signature process into seven different modules, and decouples key operations from the signature process. This allows for the flexible and rapid construction of digital signature services under different requirements, different regulations, and different application scenarios. This not only ensures the autonomy, compatibility, and scalability of the constructed digital signature service, but also effectively solves a series of problems faced by the implementation of Sigstore technology, such as legal compliance, service continuity, and trust.
[0065] The modular digital signature construction approach first abstracts the key operations in the digital signature process. It then selects appropriate key operation modules based on the digital signature service requirements of different regions, regulations, and application scenarios. Finally, it connects these key operation modules through a carefully designed signing and verification process. This effectively addresses the compliance, compatibility, service continuity, and trust issues faced by the implementation of Sigstore-related technologies.
[0066] The following combination Figure 4-11 The embodiments of the present invention are described in detail.
[0067] Figure 4 This is one of the flow charts of the modular digital signature service construction method provided by the present invention. Figure 4 As shown, the method includes the following steps: S410: Select a core process module according to the required instructions.
[0068] S420. Determine the corresponding key operation module according to the selected core process module.
[0069] S430. Combine the core process module and the key operation module to obtain a modular digital signature service.
[0070] Specifically, by summarizing the signature processes under a large number of different application scenarios, the key operations in the signature process are abstracted into six different key operation modules. The implementation of key operations is decoupled from the signature process, enabling flexible and rapid construction of signature services under different requirements, different regulations, and different application scenarios. This includes: analyzing the requirements, regulations, and application scenarios of the signature service, selecting appropriate key operation modules, and rationally arranging the interaction methods and data types between different key operation modules. The abstract key operation modules can be implemented in different ways to meet the abstract methods defined by the module and comply with the interaction requirements of the core process. The core process module implements modular construction of digital signature services by organizing and arranging different key operation modules. The abstract key operation modules include a signature hosting service module, a certificate management and authorization service module, an identity management service module, a software product module, a signature tool module, and a custom service module.
[0071] Furthermore, the overall architecture of the modular digital signature service is as follows: Figure 5As shown, the core library abstracts key operations in the digital signature system and decouples different modules from the signature process, allowing digital signature services to be built according to different needs. Clients rely on the core library to access services such as signature hosting, certificate management and authorization, and identity management. In the overall architecture, the core library implements the main abstractions and core logic, and both clients and service gateways rely on the core library to meet end-user needs. The signature hosting service provides hosting and verification of signatures and related information, the certificate management and authorization service provides certificate issuance and verification services, and the identity management service provides identity identification and management. These three key operational modules constitute the core functions of the digital signature service trust system. Taking Sigstore as an example, it implements the certificate management and authorization service and signature hosting service modules based on the transparent log service, and delegates the functions of the identity management service module to the OIDC service provider.
[0072] The structure of the core library is as follows Figure 6 As shown, the core library comprises seven modules: a signature hosting service module, a software artifact module, a certificate management and authorization service module, a signature tool module, an identity management service module, a core process module, and a custom service module. These modules are based on the analysis and refinement of existing processes, with each module responsible for implementing key operations within the process. By abstracting these key operations into workflow nodes and chaining these nodes together to implement different process instances for different scenarios, a flexible and scalable approach to organizing signature and verification processes is achieved.
[0073] According to the modular digital signature service construction method provided by the present invention, the signature hosting service is abstracted into a signature hosting service module, which specifically includes: initializing the signature hosting service; determining a signature record uploading method based on the initialized signature hosting service, the signature record uploading method is used to upload the signature record to the signature hosting service; determining a signature record obtaining method based on the initialized signature hosting service, the signature record obtaining method is used to obtain the signature record in the signature hosting service based on the unique ID of the signature record or the content of the signature record; determining a signature record verification method based on the initialized signature hosting service, the signature record verification method is used to verify whether the complete signature record exists in the signature hosting service, and verify the legitimacy of the certificate validity period in the signature record; determining a signature record parsing method based on the initialized signature hosting service, the signature record parsing method is used to parse the signature record into signatures, certificates and related information; encapsulating the signature record uploading method, the signature record obtaining method, the signature record verification method and the signature record parsing method to obtain the signature hosting service module.
[0074] Specifically, the management method of signature records is abstracted, supporting multiple hosting methods such as centralized and decentralized, and is responsible for managing, verifying, and supervising signature records. Specifically, the methods in the signature hosting service include: an initialization method, which initializes the required signature hosting service based on different requirements for signature hosting; a signature record upload method, which uploads the relevant signature record to the signature hosting service; a signature record acquisition method, which acquires the signature record from the signature hosting service based on the unique ID of the record; a signature record search method, which acquires the signature record from the signature hosting service based on the content of the signature record; a signature record integrity verification method, which verifies whether the complete signature record exists in the signature hosting service; a signature record certificate legitimacy verification method, which verifies the legitimacy of the certificate validity period in the signature record; and a signature record parsing method, which parses the signature record into signatures, certificates, and related information.
[0075] According to the modular digital signature service construction method provided by the present invention, the certificate management and authorization service is abstracted into a certificate management and authorization service module, which specifically includes: initializing the certificate management and authorization service; determining a certificate acquisition method based on the initialized certificate management and authorization service, and the certificate acquisition method is used to request a signature certificate; determining a certificate verification method based on the initialized certificate management and authorization service, and the certificate verification method is used to verify the signature certificate, and the verification content includes the integrity and credibility of the signature certificate content and the legitimacy of the validity period of the signature certificate; determining a root trust acquisition method based on the initialized certificate management and authorization service, and the root trust acquisition method is used to obtain the trust root and intermediate certificates of the certificate management service; encapsulating the certificate acquisition method, the certificate verification method and the root trust acquisition method to obtain the certificate management and authorization service module.
[0076] Specifically, it abstracts the management of digital certificates and is responsible for issuing and verifying digital certificates. The certificate management and authorization service includes: an initialization method that initializes the required certificate management service; a certificate acquisition method that requests a signed certificate from the certificate management service; a certificate verification method that verifies the certificate with the certificate management and authorization service modules, including whether the certificate content is credible, whether the signature record is credible, and the validity period of the certificate; and a root trust acquisition method that obtains the root of trust from the certificate management service for certificate trust chain verification.
[0077] According to the modular digital signature service construction method provided by the present invention, the identity management service is abstracted into an identity management service module, which specifically includes: initializing the identity management service; determining an identity acquisition method based on the initialized identity management service, the identity acquisition method being used to verify the applicant's information and issue a legal digital identity; determining an identity authentication method based on the initialized identity management service, the identity authentication method being used to verify the legitimacy of the digital identity; and encapsulating the identity acquisition method and the identity authentication method to obtain the identity management service module.
[0078] Specifically, it abstracts the management methods of digital identities and is responsible for issuing and verifying digital identities. Identity management services include: initialization methods, which are used to initialize identity management based on different methods, such as OIDC and DID; identity acquisition methods, which are used to verify and issue legitimate digital identities; and authentication methods, which are used to verify the legitimacy of digital identities.
[0079] According to the modular digital signature service construction method provided by the present invention, the software product service is abstracted into a software product service module, which specifically includes: initializing the software product service; determining a product type judgment method based on the initialized software product service, the product type judgment method is used to judge the product format; determining a signature data acquisition method based on the initialized software product service, the signature data acquisition method is used to extract target signature data according to the product format; determining a digest calculation method based on the initialized software product service, the digest calculation method is used to calculate the digest of the target signature data; determining a signature embedding method based on the initialized software product service, the signature embedding method is used to embed the signature into the software product according to the product format; determining a signature extraction method based on the initialized software product service, the signature extraction method is used to extract the embedded signature from the software product; encapsulating the product type judgment method, signature data acquisition method, digest calculation method, signature embedding method and signature extraction method to obtain a software product module.
[0080] Specifically, the key operations for signing and verifying software artifacts are abstracted. Software artifact services include: a signature data acquisition method, which extracts target signature data based on the artifact format; a digest calculation method, which calculates a digest of the target signature data; a signature embedding method, which embeds the signature into the software artifact according to the artifact format requirements; and a signature extraction method, which extracts the embedded signature based on the format of the currently verified software artifact.
[0081] According to the modular digital signature service construction method provided by the present invention, the signature tool service is abstracted into a signature tool module, which specifically includes: initializing the signature tool service; determining a key pair generation method based on the initialized signature tool service, and the key pair generation method is used to generate an asymmetric key pair according to a specified algorithm; determining a public key acquisition method based on the initialized signature tool service, and the public key acquisition method is used to obtain the public key of the signature tool; determining a signing method based on the initialized signature tool service, and the signing method is used to digitally sign data according to a private key; determining a signature verification method based on the initialized signature tool service, and the signature verification method is used to verify the legitimacy of the target data and the signature according to the public key; encapsulating the key pair generation method, the public key acquisition method, the signing method and the signature verification method to obtain the signature tool module.
[0082] Specifically, the key operations of the signature tool are abstracted, providing signing and verification capabilities based on different algorithms. The signature tool service includes: an initialization method that returns a signature tool instance based on different algorithm requirements; a key pair generation method that generates a key pair based on the initialization algorithm; a public key acquisition method that obtains the public key specified by the signature tool for signature verification; a signing method that digitally signs data using the private key; and a signature verification method that verifies the validity of the target data and signature using the public key.
[0083] According to the modular digital signature service construction method provided by the present invention, the custom service is abstracted into a custom service module, which specifically includes: initializing the custom service; determining the module method list acquisition method based on the initialized custom service, the module method list acquisition method is used to provide the method list and description of the current module definition; determining the module method access method based on the initialized custom service, the module method access method is used to call the specified module method according to the given method name and calling method; encapsulating the module method list acquisition method and the module method access method to obtain the custom service module.
[0084] Specifically, it abstracts potentially unknown key operations, allowing for custom extensions of key operation modules, such as key management systems and physical key devices. Custom services include: a module method list acquisition method, which provides a list of methods defined in the current module and their descriptions to guide method calls; and a module method access method, which calls a specified module method based on a given method name and call method.
[0085] The abstract methods of different key operation modules are shown in Table 1, where the custom service module can be used to meet the abstraction and access requirements of customized operations, such as accessing the key management system and hardware encryption devices in the signature process, to ensure the scalability of the present invention. The core process module is used to connect the other six modules in series, such as Figure 7As shown in the figure, the digital signature service logic that meets different needs is implemented by orchestrating the methods provided by the other six modules.
[0086] Table 1 Abstract methods of key operation modules
[0087] Example 1 The core process module realizes the connection and arrangement of different modules by accessing the module definition method. The keyless signature method proposed by Sigstore is regarded as a signature process. Figure 8 The steps shown are based on the method proposed in this invention to modularize the Sigstore signature process. The specific steps are as follows: 1. Obtain key or certificate information based on different signing methods - Keyless signing method: First, use the signature tool to generate a key pair for the required algorithm; second, obtain an identity token through the identity management service module; finally, apply for a certificate through the certificate management and authorization service module; - Self-maintained key signature method: directly obtain the self-maintained private key for signing; - Signature method for keys managed by the key management system or hardware encryption device: Obtain the private key stored in the key management system or hardware encryption device using a custom method based on the custom service module.
[0088] 2. Sign the target data using the signature method of the signature tool module.
[0089] 3. The core process module decides whether to destroy the key in the core process module based on the user option.
[0090] 4. The core process module decides whether to embed the signature into the artifact based on the user's preferences; - If you choose to embed the signature into the artifact, the signature will be embedded into the artifact using the embedded signature method of the software artifact module, and there is no need to package it in the core process module; - If you choose not to embed the signature into the artifact, the core process module will proceed to the next step based on the user's choice to decide whether to use the default format for packaging; 5. The core process module determines the packaging format based on user options; - If the user chooses to package the artifacts without embedded signatures in the default format, the signatures and artifacts will be packaged in the default format in the core process module; - If the user chooses not to package in the default format, the core process module will retain the signed artifacts and their signatures separately.
[0091] 6. The core process module decides whether to save the signature record based on the user's preference. If the user decides to keep the signature record, the signature hosting service module uploads the signature record to the signature hosting service. If the user decides not to keep the signature record, the module proceeds directly to the next step.
[0092] 7. The core process module returns signature / signed artifacts and certificate information as needed.
[0093] Example 2 You can refer to Figure 9 The process shown in the figure is based on the method proposed in this invention to modularize the Sigstore signature verification process. The specific steps are as follows: 1. The core process module obtains relevant information based on the artifact's embedded signature method. If the artifact has an embedded signature, it only needs to obtain the signed object; otherwise, it obtains the signed object, signature, public key, or certificate.
[0094] 2. The core process module obtains the certificate or public key according to different key management methods: - Keyless signature method: First, obtain the certificate through the certificate management and authorization service module's certificate acquisition method. Then, determine whether the certificate content is credible using the certificate verification method. Then, verify whether the signature record is credible using the signature hosting service module's signature record verification method. Finally, obtain a certificate record and signature record with credible content. - Self-maintained key signature method: First, obtain the signature and certificate or public key based on the self-maintained key method. Then, verify the authenticity of the certificate content through the certificate verification method of the certificate management and authorization service module. - Signature method for keys managed by the key management system or hardware encryption device: First, the signature and certificate or public key stored in the key management system or hardware encryption device are obtained through a custom method in the custom service module. Then, the authenticity of the certificate content is verified through the certificate verification method in the certificate management and authorization service module. 3. The core process module verifies the certificate according to different key management methods: - Signature method for self-maintained keys, key management systems, or hardware encryption devices: If the obtained key is a public key, proceed to the next step; if the obtained key is a certificate, first verify the validity of the certificate and then proceed to the next step; - Keyless signature method: Based on the obtained certificate records and signature records, the legitimacy of the certificate and signature is verified through the certificate verification method of the certificate management and authorization service module, and then the next step is executed.
[0095] 4. The core process module verifies the correctness of the signature using the signature verification method of the signature tool module based on the certificate / public key, signature, and signed object obtained in the previous two steps.
[0096] 5. Return the verification results in the core process module.
[0097] This invention effectively solves the compliance, compatibility, service continuity and trust issues faced by the implementation of Sigstore related technologies. The details are as follows: 1. Legal compliance issues: (1) Different regions usually have different requirements for security levels. By setting the corresponding security requirements for the signature hosting service module, certificate management and authorization service module, identity management service module, and signature tool module, the actual functions of the key operation modules can meet the security requirements, such as my country's requirements for the use of commercial encryption in signature services. (2) Based on the certificate management and authorization service module, certificate management services that meet different needs can be flexibly integrated into the signing process, such as traditional PKI methods, transparent log-based methods, decentralized methods, etc.
[0098] 2. Compatibility issues: (1) Account system compatibility issues: Based on different implementation methods of the identity management service module, when facing identity providers that support the OIDC protocol, identity management services are provided based on the OIDC protocol; when facing other protocols, it supports the OIDC protocol as an identity agent and is compatible with different account systems. (2) Cryptography algorithm compatibility issues: Different implementations are provided for the signature tool module, such as those based on different cryptographic libraries such as OpenSSL and Tongsuo, which are compatible with various encryption algorithms and meet the password requirements under different regulations and scenarios.
[0099] 3. Service continuity issues: Due to geopolitical issues, entry and exit of privacy data, and other issues, the services provided by Sigstore are likely to be interrupted or blocked. Based on the modular digital signature service construction method proposed in this invention, by implementing signature hosting service modules, certificate management and authorization service modules, and custom service modules, the digital signature services implemented based on different underlying services can be flexibly deployed in different regions. Users within a region can access services in this region without restrictions. When there is a need to access cross-regional services, a unified module abstract interface can also be used to ensure mutual access and mutual trust between different regions.
[0100] 4. Trust: Different key operation modules abstract digital signature service functions and implementation details, abstracting module functionality and construction methods. These abstract key operation modules can be implemented based on different services or in different ways. On the one hand, when building digital signature services, implementing specific key operation modules can introduce trusted services into the signing process, resolving trust issues. On the other hand, as the number of key operation module implementations increases, more services will participate in the modular construction of digital signatures, gradually forming a healthy digital signature service community. This will attract enthusiasts from around the world to participate in the construction, breaking through regional restrictions and fostering broader trust.
[0101] The modular digital signature service construction device provided by the present invention is described below. The modular digital signature service construction device described below and the modular digital signature service construction method described above can be referenced to each other.
[0102] like Figure 10 The present invention provides a modular digital signature service construction device, comprising: The core process selection module 1010 is used to select the core process module according to the demand instruction; A key operation selection module 1020 is used to determine a corresponding key operation module according to the selected core process module; A combination module 1030 is used to combine the core process module and the key operation module to obtain a modular digital signature service; The key operation module is obtained by abstracting the key operations in the digital signature service, including the signature hosting service module, certificate management and authorization service module, identity management service module, software product module, signature tool module and custom service module; The core process module is implemented based on the abstract interaction interface of the key operation module. Different core process modules correspond to multiple digital signature service processes.
[0103] Figure 11 An example of a physical structure diagram of an electronic device is shown below. Figure 11As shown, the electronic device may include: a processor 1110, a communications interface 1120, a memory 1130, and a communications bus 1140, wherein the processor 1110, the communications interface 1120, and the memory 1130 communicate with each other via the communications bus 1140. The processor 1110 may call logic instructions in the memory 1130 to execute a modular digital signature service construction method, which includes: selecting a core process module according to a demand instruction; determining a corresponding key operation module based on the selected core process module; and combining the core process module and the key operation module to obtain a modular digital signature service. The key operation module is obtained by abstracting the key operations in the digital signature service, and includes a signature hosting service module, a certificate management and authorization service module, an identity management service module, a software product module, a signature tool module, and a custom service module. The core process module is implemented based on the abstract interaction interface of the key operation module, and different core process modules correspond to multiple digital signature service processes.
[0104] Furthermore, the logic instructions in the aforementioned memory 1130 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the portion that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product, stored in a storage medium, includes instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the various embodiments of the method of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as a USB flash drive, a mobile hard drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.
[0105] On the other hand, the present invention also provides a computer program product, which includes a computer program, which can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the modular digital signature service construction method provided by the above methods, which includes: selecting a core process module according to the demand instructions; determining the corresponding key operation module according to the selected core process module; combining the core process module and the key operation module to obtain a modular digital signature service; the key operation module is obtained by abstracting the key operations in the digital signature service, and includes a signature hosting service module, a certificate management and authorization service module, an identity management service module, a software product module, a signature tool module and a custom service module; the core process module is implemented based on the abstract interaction interface of the key operation module, and different core process modules correspond to multiple digital signature service processes.
[0106] On the other hand, the present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements a modular digital signature service construction method provided by the above-mentioned methods, the method comprising: selecting a core process module according to a demand instruction; determining a corresponding key operation module according to the selected core process module; combining the core process module and the key operation module to obtain a modular digital signature service; the key operation module is obtained by abstracting the key operations in the digital signature service, and includes a signature hosting service module, a certificate management and authorization service module, an identity management service module, a software product module, a signature tool module and a custom service module; the core process module is implemented based on the abstract interaction interface of the key operation module, and different core process modules correspond to multiple digital signature service processes.
[0107] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units. That is, they may be located in one place or distributed across multiple network units. Some or all of the modules may be selected based on actual needs to achieve the objectives of the present embodiment. Persons of ordinary skill in the art will be able to understand and implement the present invention without inventive effort.
[0108] Through the above description of the embodiments, those skilled in the art will clearly understand that each embodiment can be implemented using software plus a necessary general-purpose hardware platform, or of course, hardware. Based on this understanding, the essence of the above technical solution, or the portion that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a magnetic disk, or an optical disk, and includes a number of instructions for causing a computer device (such as a personal computer, server, or network device) to execute the methods of each embodiment or certain portions of the embodiments.
[0109] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present invention.
Claims
1. A modular digital signature service construction method, characterized in that: include: Select core process modules according to demand instructions; Determine the corresponding key operation module based on the selected core process module; Combining the core process module and the key operation module to obtain a modular digital signature service; The key operation module is obtained by abstracting the key operations in the digital signature service, including the signature hosting service module, the certificate management and authorization service module, the identity management service module, the software product module, the signature tool module and the custom service module; The core process module is implemented based on the abstract interaction interface of the key operation module, and different core process modules correspond to multiple digital signature service processes.
2. The modular digital signature service construction method according to claim 1, characterized in that: The signature hosting service is abstracted into a signature hosting service module, which specifically includes: Initialize signature hosting service; Determining a signature record uploading method based on the initialized signature hosting service, wherein the signature record uploading method is used to upload the signature record to the signature hosting service; Determining a signature record acquisition method based on the initialized signature escrow service, wherein the signature record acquisition method is used to acquire the signature record from the signature escrow service based on the unique ID of the signature record or the content of the signature record; Determining a signature record verification method based on the initialized signature escrow service, wherein the signature record verification method is used to verify whether the complete signature record exists in the signature escrow service and to verify the legitimacy of the certificate validity period in the signature record; Determining a signature record parsing method based on the initialized signature hosting service, wherein the signature record parsing method is used to parse the signature record into a signature, a certificate, and related information; The signature record uploading method, the signature record obtaining method, the signature record verification method and the signature record parsing method are encapsulated to obtain a signature hosting service module.
3. The modular digital signature service construction method according to claim 1, characterized in that: The certificate management and authorization services are abstracted into a certificate management and authorization service module, which specifically includes: Initialize certificate management and authorization services; Determining a certificate acquisition method based on the initialized certificate management and authorization service, wherein the certificate acquisition method is used to request a signed certificate; Determining a certificate verification method based on the initialized certificate management and authorization service, wherein the certificate verification method is used to verify the signature certificate, including the integrity and credibility of the signature certificate content and the legitimacy of the validity period of the signature certificate; Determine a root trust acquisition method based on the initialized certificate management and authorization services, wherein the root trust acquisition method is used to obtain the trust root and intermediate certificates of the certificate management service; The certificate acquisition method, the certificate verification method and the root trust acquisition method are encapsulated to obtain a certificate management and authorization service module.
4. The modular digital signature service construction method according to claim 1, characterized in that: The identity management service is abstracted into an identity management service module, which specifically includes: Initialize identity management services; Determining an identity acquisition method based on the initialized identity management service, wherein the identity acquisition method is used to verify the applicant information and issue a legal digital identity; Determining an identity authentication method based on the initialized identity management service, wherein the identity authentication method is used to verify the legitimacy of the digital identity; The identity acquisition method and the identity authentication method are encapsulated to obtain an identity management service module.
5. The modular digital signature service construction method according to claim 1, characterized in that: Abstract software product services into software product service modules, specifically including: Initialize software product services; Determining a product type determination method based on the initialized software product service, wherein the product type determination method is used to determine the product format; Determining a signature data acquisition method based on the initialized software product service, wherein the signature data acquisition method is used to extract target signature data according to the product format; determining a digest calculation method based on the initialized software product service, wherein the digest calculation method is used to calculate a digest of the target signature data; Determining a signature embedding method based on the initialized software product service, wherein the signature embedding method is used to embed the signature into the software product according to the product format; determining a signature extraction method based on the initialized software artifact service, the signature extraction method being used to extract an embedded signature from the software artifact; The product type determination method, the signature data acquisition method, the digest calculation method, the signature embedding method and the signature extraction method are encapsulated to obtain a software product module.
6. The modular digital signature service construction method according to claim 1, characterized in that: The signature tool service is abstracted into a signature tool module, which specifically includes: Initialize the signature tool service; Determining a key pair generation method based on the initialized signature tool service, wherein the key pair generation method is used to generate an asymmetric key pair according to a specified algorithm; Determining a public key acquisition method based on the initialized signature tool service, wherein the public key acquisition method is used to acquire the public key of the signature tool; Determining a signature method based on the initialized signature tool service, wherein the signature method is used to digitally sign data according to a private key; Determine a signature verification method based on the initialized signature tool service, wherein the signature verification method is used to verify the legitimacy of the target data and the signature according to the public key; The key pair generation method, the public key acquisition method, the signature method and the signature verification method are encapsulated to obtain a signature tool module.
7. The modular digital signature service construction method according to claim 1, characterized in that: Abstract custom services into custom service modules, including: Initialize custom services; Determine a module method list acquisition method based on the initialized custom service, wherein the module method list acquisition method is used to provide a method list and description defined by the current module; Determine a module method access method based on the initialized custom service, wherein the module method access method is used to call a specified module method according to a given method name and calling method; The module method list acquisition method and the module method access method are encapsulated to obtain a custom service module.
8. A modular digital signature service construction device, characterized in that: include: Core process selection module, used to select core process modules according to demand instructions; The key operation selection module is used to determine the corresponding key operation module according to the selected core process module; A combination module, used to combine the core process module and the key operation module to obtain a modular digital signature service; The key operation module is obtained by abstracting the key operations in the digital signature service, including the signature hosting service module, the certificate management and authorization service module, the identity management service module, the software product module, the signature tool module and the custom service module; The core process module is implemented based on the abstract interaction interface of the key operation module, and different core process modules correspond to multiple digital signature service processes.
9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the modular digital signature service construction method according to any one of claims 1 to 7 is implemented.
10. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the modular digital signature service construction method according to any one of claims 1 to 7 is implemented.