Information security contract signing system based on block chain
Through hash processing, digital signature, feature parameter extraction and finite element risk prediction modules, the problem of private key vulnerability caused by random number reuse in the ECDSA signature mechanism is solved, and dynamic security management of the signature process and efficient protection of the contract system are achieved.
Patent Information
- Application Number
- CN202510778719.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-11
- Publication Date
- 2025-09-19
- Estimated Expiration
- 2045-06-11
AI Technical Summary
During the contract signing process based on the ECDSA signature mechanism, if the signing device reuses the same random number for multiple signatures or uses a predictable pseudo-random number generation algorithm, an attacker can derive the private key by obtaining multiple signature samples, thereby forging signatures and tampering with the contract content, seriously threatening the security and credibility of the contract system.
A unique contract hash value is generated through the hash processing module, the digital signature module uses the signer's private key to sign, the feature parameter extraction module extracts signature-related feature parameters, the finite element risk prediction module builds an analysis model, calculates the risk of random number duplication or leakage during the signing process, and the risk level determination module evaluates the possibility of attack and triggers a security response mechanism.
It realizes dynamic perception of the signing process and early identification of abnormal behavior patterns, prevents signature forgery and contract tampering, and significantly improves the credibility and anti-attack capabilities of the blockchain contract system.
Smart Images

Figure CN120671186A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and in particular to an information security contract signing system based on blockchain. Background Art
[0002] Blockchain-based information security contract signing leverages the decentralized, tamper-proof, and traceable nature of blockchain technology to digitally record contract details on the blockchain, ensuring data security and trustworthiness during contract signing, storage, and execution. This approach prevents contract forgery or tampering, strengthens trust in contract performance among all parties, and effectively improves the transparency and efficiency of contract management.
[0003] The prior art has the following deficiencies:
[0004] During the ECDSA-based contract signing process, if the signing device reuses the same random number or uses a predictable pseudo-random number generation algorithm for multiple signatures, an attacker could derive the private key by obtaining multiple signature samples, thereby forging signatures and tampering with the contract content, seriously threatening the security and credibility of the contract system. This vulnerability has been exploited in the Bitcoin system and is a highly concealed but extremely serious security risk. Summary of the Invention
[0005] The purpose of the present invention is to provide an information security contract signing system based on blockchain to address the shortcomings of the background technology.
[0006] To achieve the above-mentioned purpose, the present invention provides the following technical solution: a blockchain-based information security contract signing system, comprising a hash processing module, a digital signature module, a feature parameter extraction module, a finite element risk prediction module, and a risk level determination module;
[0007] The hash processing module is used to perform hash operations on the contract content and generate a unique contract hash value;
[0008] The digital signature module is used to call the signatory's private key to digitally sign the contract hash value and generate corresponding signature data;
[0009] A blockchain writing module is used to package the contract hash value and the corresponding signature data as transaction data and write them into the blockchain storage;
[0010] Feature parameter extraction module, used to extract signature-related feature parameters in multiple signature operations, including signature time deviation value and signature data trajectory similarity value;
[0011] A finite element risk prediction module, configured to construct a finite element analysis model based on the signature-related characteristic parameters and calculate a risk prediction value of random number duplication or leakage during the signing process;
[0012] The risk level determination module is used to divide the risk level according to the risk prediction value, and combine the mathematical reversibility of known attack samples to evaluate the possibility that the attacker can deduce the signatory's private key, form a comprehensive security level, and trigger a security response mechanism.
[0013] Preferably, the hash processing module specifically includes: parsing the electronic contract content uploaded by the user, encoding and uniformly processing the contract content, performing field extraction and serialization processing on the contract content, and generating a standard input string based on the field sequence; calling the cryptographic hash function to perform a hash operation on the standard string to generate a unique contract hash value.
[0014] Preferably, the digital signature module specifically includes: verifying the identity of the signatory, including biometrics, certificate chain verification or password verification; loading the signatory private key through a local key management system or a hardware security module; using an elliptic curve signature algorithm to sign the contract hash value; using a newly generated high-entropy random number k to ensure the uniqueness of each signature; outputting a signature pair (r, s), and encapsulating it into a signature data structure with a signature timestamp, a public key identifier and signature algorithm information.
[0015] Preferably, the characteristic parameter extraction module is used to extract the signature time deviation value during the continuous signing process;
[0016] Suppose there are n consecutive signature operations, and the corresponding timestamp sequence is: ; Perform adjacent differences on timestamps to obtain the time interval sequence: ;get: ;
[0017] Divide all ΔT values into several time intervals to form an interval set: ;
[0018] Count the number of times Z that ΔT appears in each interval and calculate its probability distribution: ;in, is the probability of the jth time interval, and m is the total number of time interval distribution intervals;
[0019] Information entropy is calculated according to the Shannon entropy formula: ;in: is the entropy value of the signature time deviation, For the probability of occurrence of each time interval, calculate the signature time deviation value, the expression is: ; is the maximum entropy, The signature time deviation value ranges from [0,1].
[0020] Preferably, the method for obtaining the signature data trajectory similarity value is:
[0021] Suppose there are c consecutive signature data, each signature generates a value pair , forming a trajectory set: ;
[0022] Choose two signatures , calculate its Euclidean distance: ; 、 is the normalized signature vector; perform distance calculation on all signature pairs to obtain the distance set: ; Calculate the average distance , the expression is: ; Based on the maximum distance Perform reverse normalization to obtain the signature data trajectory similarity value , the expression is: ;in: ∈[0,1].
[0023] Preferably, the finite element model constructed by the finite element risk prediction module is a two-dimensional behavior space model, including:
[0024] Mapping the signature time deviation value and the signature data trajectory similarity value to the two-dimensional plane coordinate axis;
[0025] The coordinates are used as disturbance nodes to simulate the disturbance propagation behavior in the constructed two-dimensional grid;
[0026] Integrate the grid response to form a global stability function;
[0027] Normalize the integral results to obtain the risk prediction value .
[0028] Preferably, the risk prediction value output by the finite element analysis model To classify, if If the value is between 0 and 0.2, it is considered safe, indicating that the signature behavior distribution is natural and random enough; if Between 0.2 and 0.5, it is judged as a weak warning, indicating that a certain behavior dimension has an abnormal trend but has not yet posed a serious threat; If it falls within the range of 0.5 to 0.8, it is considered high risk, indicating that there are regular or repetitive characteristics in the signature process; If it exceeds 0.8, it is classified as a critical anomaly. It is highly suspected that the private key or random number has been reused, leaked, or attacked during the signing process, and security response measures will be automatically taken.
[0029] Preferably, in the risk level determination module, the attack reversibility factor is obtained , the acquisition method is: Assume that the attacker obtains two signature samples: Signature pair 1: Corresponding hash h1; signature pair 2: Corresponding to hash h2; construct reversibility sub-indicators, including: Sub-indicator A: r value repeatability factor ; ; Sub-indicator B: Time interval factor ; Define the time interval as ΔT=T2-T1, normalized to: ;in The maximum security signature interval set; Sub-index C: s value similarity factor ; ;in is the elliptic curve order or empirical maximum;
[0030] The attack reversibility factor is obtained by performing weighted sum calculation on sub-indicators A, B, and C. .
[0031] Optimized, comprehensive evaluation indicators It can be expressed as: ;in, and is the weight coefficient, according to The value of is used to grade the overall signature security; if If the value is greater than or equal to the preset threshold ST, the signature behavior will be judged to have a high risk of private key leakage and marked as a high risk level. The account will be locked immediately or the subsequent signing process will be blocked. If it is less than the preset threshold ST, the system security status is considered to be good, marked as a low risk level, and recorded only for future reference.
[0032] In the above technical solution, the technical effects and advantages provided by the present invention are:
[0033] 1. This invention innovatively addresses the problem of private key derivation in existing ECDSA signature mechanisms, which can be caused by random number reuse or low-quality random number generation, by introducing signature behavior feature analysis and a finite element risk prediction model. By extracting signature time deviation values and signature data trajectory similarity values, the system can dynamically detect abnormal behavior patterns during the signing process. Using two-dimensional finite element perturbation simulation to construct a behavioral stability evaluation mechanism, this system calculates the risk prediction value of random number use during the signing process, enabling early identification and hierarchical management of security risks.
[0034] 2. This invention incorporates cryptographic reversibility analysis to design an attack reversibility factor. By constructing multiple sub-indicators, it quantitatively assesses the repeatability, temporal consistency, and data similarity of signature samples. These indicators are then integrated with the finite element analysis output to form a comprehensive security level. If the comprehensive security level exceeds a preset threshold, the system automatically triggers security response mechanisms such as account lockout and signature blocking, effectively preventing high-risk incidents such as signature forgery and contract tampering, significantly improving the credibility, attack resistance, and practicality of blockchain contract systems. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments described in the present invention. For ordinary technicians in this field, other drawings can also be obtained based on these drawings.
[0036] Figure 1 This is a mind map of the system modules of the present invention. DETAILED DESCRIPTION
[0037] To make the objectives, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.
[0038] For examples, see Figure 1 As shown, the blockchain-based information security contract signing system described in this embodiment includes a hash processing module, a digital signature module, a feature parameter extraction module, a finite element risk prediction module, and a risk level determination module;
[0039] The hash processing module is used to perform hash operations on the contract content and generate a unique contract hash value;
[0040] The digital signature module is used to call the signatory's private key to digitally sign the contract hash value and generate corresponding signature data;
[0041] A blockchain writing module is used to package the contract hash value and the corresponding signature data as transaction data and write them into the blockchain storage;
[0042] Feature parameter extraction module, used to extract signature-related feature parameters in multiple signature operations, including signature time deviation value and signature data trajectory similarity value;
[0043] A finite element risk prediction module, configured to construct a finite element analysis model based on the signature-related characteristic parameters and calculate a risk prediction value of random number duplication or leakage during the signing process;
[0044] a risk level determination module, configured to classify the risk level according to the risk prediction value and, in combination with the mathematical reversibility of known attack samples, evaluate the likelihood that an attacker can derive the signatory's private key to form a comprehensive security level;
[0045] The intelligent response control module is used to trigger a security response mechanism when the comprehensive security level reaches a preset risk threshold.
[0046] In this embodiment, a hash processing module is provided for use in a blockchain-based information security contract signing system, which is used to preprocess and hash the content of the electronic contract to be signed, generate a unique contract hash value, and serve as the basis for subsequent digital signatures and blockchain records.
[0047] Users upload an electronic contract through the front-end interface. The system supports contract formats including .pdf, .docx, .json, and .txt. For example, the system automatically uses a file parsing tool to extract the PDF content into plain text and identify fields such as title, number, body, and signatory information.
[0048] The extracted text is converted to UTF-8 encoding, removing any unwanted text such as BOM headers, hidden characters, and control characters. The system further streamlines the text by replacing all paragraph markers with a uniform line break format and compressing excess spaces to ensure consistent text content.
[0049] The system extracts the structured information in the contract by fielding and constructs the input string to be hashed in the following order: contract title + contract number + contract body + signatory ID + current timestamp;
[0050] For structured contracts, such as electronic contracts in JSON format, the system uses Canonical JSON encoding rules to serialize fields in lexicographic order to prevent differences in hash results caused by changes in field order.
[0051] The system calls the SHA-256 hash algorithm in the encryption library, reads the serialized contract input string, and performs a hash operation: contract_hash = SHA256(serialized_contract_text); the hash value is a 64-bit hexadecimal string that uniquely identifies the contract content.
[0052] The generated contract_hash value undergoes a one-time local verification (confirming length, character set, etc.), and is then passed to the signature module through the system's internal interface for digital signature using the signer's private key. This hash value is also included as part of the contract summary and is packaged and uploaded to the blockchain along with the signature result.
[0053] Through this embodiment, the system can generate a highly consistent and secure hash value when processing contract texts from different sources and in different formats, ensuring that subsequent digital signatures and blockchain evidence are based on the same content, significantly enhancing the legitimacy and non-repudiation of the entire contract signing process.
[0054] The digital signature module is used to receive the contract hash value, call the signatory's private key to perform the digital signature operation, generate legally effective signature data (r, s) or an equivalent signature pair, and submit the signature data as a signing certificate to the subsequent processing module.
[0055] Before executing the signature, the system authenticates the signatory, including: private key ownership authentication (such as fingerprint, face recognition, password verification); digital certificate validity check (such as X.509 format certificate chain verification); after verification, the private key signature engine is allowed to be called.
[0056] The system securely loads the private key of the corresponding signer from the local key management system (KMS) or hardware security module (HSM); at the same time, it calls the signature algorithm parameters, such as the elliptic curve name (such as secp256k1) and the signature scheme (such as ECDSA, EdDSA, or RSA-PSS).
[0057] The loaded private key is used to perform an encrypted signature operation on the contract hash value to generate a signature value; the system ensures that a new random number k with sufficient entropy is used in each signing process to prevent reuse.
[0058] The generated signature result and related auxiliary data are encapsulated into a standard signature data structure, including but not limited to: the original contract hash value; the signature value (r, s) or the signature string; the signatory public key or address identifier; the signature timestamp and the algorithm identifier.
[0059] Through this module, the system can generate unforgeable and verifiable signature data while ensuring the secure isolation of the signatory's identity and private key, and provide a strong encryption foundation for blockchain evidence storage, effectively preventing attacks such as signature replay, forgery, and random number reuse.
[0060] The blockchain writing module is used to encapsulate the generated contract hash value and its corresponding signature data into transaction data in a preset format, send it to the blockchain network, and complete the writing and storage through the consensus mechanism, so as to achieve tamper-proof and traceable on-chain evidence of the contract signing process.
[0061] Receive structured data from the signature module. The data fields include:
[0062] Contract hash value (contract_hash);
[0063] Signature value (such as r and s in ECDSA);
[0064] The identity of the signatory (e.g., address, public key, certificate number);
[0065] Auxiliary fields such as timestamp and signature algorithm identifier;
[0066] Build the on-chain transaction structure (Transaction Payload).
[0067] To reduce on-chain storage costs, data compression or encoding is performed, such as using Base58 or RLP encoding for hexadecimal data; removing redundant fields and using hash indexes instead of original descriptions; and converting encoded transaction data into a format acceptable on-chain, such as JSON, CBOR, or Solidity ABI encoding format.
[0068] Construct the transaction structure and attach necessary on-chain metadata (such as gas, nonce, chain ID);
[0069] Transactions are signed using the system private key (not the contract signer) to prevent tampering; transactions are broadcast to the network through blockchain node interfaces (such as Ethereum's JSON-RPC, Hyperledger Fabric SDK, and Polkadot Substrate API).
[0070] Network nodes verify the legitimacy of transactions through preset consensus algorithms (such as PoW, PoS, PBFT); transactions are packaged into new blocks and form tamper-proof records on the chain; the system monitors transaction hashes and block heights to confirm the completion of transaction writes.
[0071] After the transaction is confirmed, the system automatically records: transaction hash (tx_hash); block number (block_number); block timestamp (onchain_timestamp); and simultaneously creates a local index (such as contract ID → block address) to facilitate subsequent retrieval and verification.
[0072] The feature parameter extraction module is used to extract key behavioral feature parameters related to security from each signature data during the system's execution of multiple digital signature operations. The feature parameters include but are not limited to signature time deviation values and signature data trajectory similarity values, for subsequent risk prediction model analysis.
[0073] After each digital signature is completed, the system stores the following data in the signature log: signing timestamp (T); signature value (r, s); signatory identification; contract hash value; the data is organized in a time series to form a complete set of signature behavior records.
[0074] The method for obtaining the signature time deviation value is:
[0075] Suppose there are n consecutive signature operations, and the corresponding timestamp sequence is: ; Perform adjacent differences on timestamps to obtain the time interval sequence: ;get: ;
[0076] Divide all ΔT values into several time intervals (interval width can be customized), for example, 1 second as one interval, to form an interval set: ;
[0077] Count the number of times Z that ΔT appears in each interval and calculate its probability distribution: ;in, is the probability of the jth time interval, and m is the total number of time interval distribution intervals;
[0078] Information entropy is calculated according to the Shannon entropy formula: ;in: is the entropy value of the signature time deviation, For the probability of occurrence of each time interval, calculate the signature time deviation value, the expression is: ; is the maximum entropy, It is the signature time deviation value, ranging from [0,1]. The larger the value, the more abnormal the deviation.
[0079] The method for obtaining the signature data trajectory similarity value is:
[0080] Suppose there are c consecutive signature data, each signature generates a value pair , forming a trajectory set: ;
[0081] Choose two signatures , calculate its Euclidean distance: ; 、 is the normalized signature vector; perform distance calculation on all signature pairs to obtain the distance set: ; Calculate the average distance , the expression is: ; Based on the maximum possible distance (The maximum value under normalization) is reverse normalized to obtain the signature data trajectory similarity value , the expression is: ;in: ∈[0,1], the closer it is to 1, the more similar the signature trajectories are (the higher the potential risk).
[0082] The finite element risk prediction module is used to construct a finite element analysis model for behavioral stability simulation based on the key behavioral characteristic parameters in the signing process, model and simulate possible random number reuse, weak random number or signature forgery behaviors, and output the corresponding risk prediction value.
[0083] The module receives the following key parameters provided by the feature extraction module:
[0084] The signature time deviation value and signature trajectory similarity value, parameters are normalized to the [0,1] interval and used as input variables.
[0085] Model the behavior space as a 2D finite element region:
[0086] The horizontal axis is the time deviation dimension (representing the stability of the signature rhythm);
[0087] The vertical axis is the trajectory similarity dimension (representing the regularity of signature data);
[0088] A two-dimensional grid consisting of multiple units and nodes is constructed in this area to simulate the behavioral stable states corresponding to different feature combinations.
[0089] Apply disturbance sources to key nodes using the received signature time deviation value and signature data trajectory similarity value;
[0090] Simulate the stability / instability of behavioral deviations propagating through the grid;
[0091] The response functions (such as strain and deformation) within the model unit are integrated to obtain the global stability index.
[0092] Converting finite element simulation results into numerical scores , indicating the stability of random number security: ;in: The higher the value, the less stable the signature process is, and there is a risk of duplication / leakage. The model supports precision adjustment and can train different mapping functions based on empirical samples.
[0093] Risk prediction value output from the finite element analysis model To classify, if If the value is between 0.0 and 0.2, it is considered safe, indicating that the signature behavior distribution is natural and random enough; if If the value is between 0.2 and 0.5, it is considered a weak warning, indicating that a certain behavior dimension (such as signature interval or signature result) has an abnormal trend but has not yet posed a serious threat; If it falls within the range of 0.5 to 0.8, the system identifies it as high risk, indicating that the signature process has significant regularity or repetitive characteristics, and it is suspected that an unsafe random number is used; if If it exceeds 0.8, it is classified as a critical anomaly, and there is a high suspicion that the private key or random number has been reused, leaked, or attacked during the signing process. The system will automatically take security response measures such as blocking signing and locking the account.
[0094] Risk prediction value output from the finite element analysis model ,The system further combines the mathematical reversibility characteristics of the ,attack samples to jointly evaluate the possibility of the attacker ,deriving the signatory's private key, thereby forming a more accurate ,comprehensive security level.
[0095] In the specific implementation, first calculate , reflecting the stability and abnormality of the signature behavior; then the attack reversibility factor is introduced This factor is scored based on cryptographic reversible conditions such as whether the existing signature samples contain repeated random numbers k, whether the signature values r are consistent, and whether the time interval is extremely short. If the system finds the same r value in two signatures, or extremely similar (r, s) pairs, and the time intervals between signatures are abnormally concentrated, a higher score is calculated. , which means that an attacker can use this formula to deduce the private key.
[0096] Attack reversibility factor Aims to quantify the possibility of an attacker using signature data to reverse the private key. →1) → This indicates that the signature behavior is highly reversible; the reversibility is low ( →0)→Indicates that the signing process is secure and irreversible.
[0097] The acquisition method is: Assume that the attacker obtains two signature samples (take ECDSA as an example):
[0098] Signature pair 1: Corresponding hash h1;
[0099] Signature pair 2: Corresponding hash h2;
[0100] Extract analytical features from it:
[0101] Is there the same r value: If = , prompt random number k to repeat;
[0102] Is there a very small time interval (supporting attack inference): for example, a time difference of less than 1 second;
[0103] Is there an approximate s value or a linear relationship: s~h can be fitted linearly;
[0104] Construct reversibility sub-indicators, including:
[0105] Sub-indicator A: r-value repeatability factor ; ;
[0106] Sub-indicator B: Time interval factor ;
[0107] Define the time interval as ΔT=T2-T1, normalized to: ;in The maximum security signature interval (e.g. 10s)
[0108] Sub-index C: s-value similarity factor ; ;in is the elliptic curve order or empirical maximum, ensuring normalization;
[0109] The attack reversibility factor is obtained by performing weighted sum calculation on sub-indicators A, B, and C. .
[0110] Comprehensive evaluation indicators It can be expressed as: ;in, and is the weight coefficient, which reflects the degree to which the system emphasizes behavioral risk and mathematical reversible risk.
[0111] according to The value of is used to grade the overall signature security. If the value is greater than or equal to the preset threshold ST, the signature behavior will be judged to have a high risk of private key leakage and marked as a high risk level. The account will be locked immediately or the subsequent signing process will be blocked. If the value is less than the preset threshold ST, the system is considered to be in good security status, marked as low risk, and recorded only for future reference. This method combines behavioral patterns with cryptographic principles to achieve more refined contract signing security control.
[0112] The above formulas are all dimensionless and numerical calculations. The formulas are obtained by collecting a large amount of data and performing software simulation to obtain the most recent real situation. The preset parameters in the formulas are set by technicians in this field according to actual conditions.
[0113] The above is only a specific implementation method of the present application, but the scope of protection of the present application is not limited thereto. Any technician familiar with this technical field can easily think of changes or replacements within the technical scope disclosed in this application, which should be covered by the scope of protection of the present application.
Claims
1. The blockchain-based information security contract signing system is characterized by: It includes hash processing module, digital signature module, feature parameter extraction module, finite element risk prediction module and risk level determination module; The hash processing module is used to perform hash operations on the contract content and generate a unique contract hash value; The digital signature module is used to call the signatory's private key to digitally sign the contract hash value and generate corresponding signature data; A blockchain writing module is used to package the contract hash value and the corresponding signature data as transaction data and write them into the blockchain storage; Feature parameter extraction module, used to extract signature-related feature parameters in multiple signature operations, including signature time deviation value and signature data trajectory similarity value; A finite element risk prediction module, configured to construct a finite element analysis model based on the signature-related characteristic parameters and calculate a risk prediction value of random number duplication or leakage during the signing process; The risk level determination module is used to divide the risk level according to the risk prediction value, and combine the mathematical reversibility of known attack samples to evaluate the possibility that the attacker can deduce the signatory's private key, form a comprehensive security level, and trigger a security response mechanism.
2. The blockchain-based information security contract signing system according to claim 1 is characterized by: The hash processing module specifically includes: parsing the electronic contract content uploaded by the user, encoding and uniformly processing the contract content, performing field extraction and serialization processing on the contract content, and generating a standard input string based on the field sequence; calling the cryptographic hash function to perform hash operation on the standard string to generate a unique contract hash value.
3. The blockchain-based information security contract signing system according to claim 1 is characterized by: The digital signature module specifically includes: verifying the identity of the signatory, including biometrics, certificate chain verification or password verification; loading the signatory's private key through a local key management system or hardware security module; using the elliptic curve signature algorithm to sign the contract hash value; using a newly generated high-entropy random number k to ensure the uniqueness of each signature; outputting a signature pair (r, s), and encapsulating it with a signature timestamp, public key identifier and signature algorithm information into a signature data structure.
4. The blockchain-based information security contract signing system according to claim 1, characterized in that: The characteristic parameter extraction module is used to extract the signature time deviation value during the continuous signature process; Suppose there are n consecutive signature operations, and the corresponding timestamp sequence is: ; Perform adjacent differences on timestamps to obtain a time interval sequence: ;get: ; Divide all ΔT values into several time intervals to form an interval set: ; Count the number of times Z that ΔT appears in each interval and calculate its probability distribution: ;in, is the probability of the jth time interval, and m is the total number of time interval distribution intervals; Information entropy is calculated according to the Shannon entropy formula: ;in: is the entropy value of the signature time deviation, For the probability of occurrence of each time interval, calculate the signature time deviation value, the expression is: ; is the maximum entropy, The signature time deviation value ranges from [0,1].
5. The blockchain-based information security contract signing system according to claim 4 is characterized by: in, The method for obtaining the signature data trajectory similarity value is: Suppose there are c consecutive signature data, each signature generates a value pair , forming a trajectory set: ; Choose two signatures , calculate its Euclidean distance: ; 、 is the normalized signature vector; perform distance calculation on all signature pairs to obtain the distance set: ; Calculate the average distance , the expression is: ; Based on the maximum distance Perform reverse normalization to obtain the signature data trajectory similarity value , the expression is: ;in: ∈[0,1].
6. The blockchain-based information security contract signing system according to claim 5, characterized in that: The finite element model constructed by the finite element risk prediction module is a two-dimensional behavior space model, including: Mapping the signature time deviation value and the signature data trajectory similarity value to the two-dimensional plane coordinate axis; The coordinates are used as disturbance nodes to simulate the disturbance propagation behavior in the constructed two-dimensional grid; Integrate the grid response to form a global stability function; Normalize the integral results to obtain the risk prediction value .
7. The blockchain-based information security contract signing system according to claim 6, characterized in that: Risk prediction value output from the finite element analysis model To classify, if If the value is between 0 and 0.2, it is considered safe, indicating that the signature behavior distribution is natural and random enough; if Between 0.2 and 0.5, it is judged as a weak warning, indicating that a certain behavior dimension has an abnormal trend but has not yet posed a serious threat; If it falls within the range of 0.5 to 0.8, it is considered high risk, indicating that there are regular or repetitive characteristics in the signature process; If it exceeds 0.8, it is classified as a critical anomaly. It is highly suspected that the private key or random number has been reused, leaked, or attacked during the signing process, and security response measures will be automatically taken.
8. The blockchain-based information security contract signing system according to claim 7, characterized in that: In the risk level determination module, obtain the attack reversibility factor , the acquisition method is: Assume that the attacker obtains two signature samples: Signature pair 1: Corresponding hash h1; signature pair 2: Corresponding to hash h2; construct reversibility sub-indicators, including: Sub-indicator A: r value repeatability factor ; ; Sub-indicator B: Time interval factor ; Define the time interval as ΔT=T2-T1, normalized to: ;in The maximum security signature interval set; Sub-index C: s value similarity factor ; ;in is the elliptic curve order or empirical maximum; The attack reversibility factor is obtained by performing weighted sum calculation on sub-indicators A, B, and C. .
9. The blockchain-based information security contract signing system according to claim 8, characterized in that: Comprehensive evaluation indicators It can be expressed as: ;in, and is the weight coefficient, according to The value of is used to grade the overall signature security; if If the value is greater than or equal to the preset threshold ST, the signature behavior will be judged to have a high risk of private key leakage and marked as a high risk level. The account will be locked immediately or the subsequent signing process will be blocked. If it is less than the preset threshold ST, the system security status is considered to be good, marked as a low risk level, and recorded only for future reference.
Citation Information
Patent Citations
File signature method and device, electronic device and readable storage medium
CN110826034A
Blockchain-based digital signature securing method
EP4440036A1
Behaviometric signature authentication system and method
GB201600390D0
Online signature verification apparatus by usingmapping between geometric extremes and method thereof
KR1020040006611A
Time intervals for stateful signature production
US20240097884A1
Cited By
Electronic contract security risk assessment system based on dynamic multi-element identity authentication
CN120934908A