A multi-level hash chain hybrid signature method and device

CN122457259BActive Publication Date: 2026-09-15SICHUAN LIANGSHANSHUILUOHE ELECTRICITY DEV CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202610912404.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2026-06-24
Publication Date
2026-09-15
Estimated Expiration
2046-06-24

AI Technical Summary

Technical Problem

[0008]本发明实施方式的目的是提供一种多级哈希链混合签名方法及装置,以至少解决现有技术存在着量子安全短板、硬件可信锚点缺失以及安全绑定深度不足的问题

Benefits of technology

[0066] This invention is based on the deep integration of the national cryptographic SM2 algorithm and the post-quantum algorithm (ML-DSA). It coordinates the hardware root key of the physical non-cloning function with quantum keys, and constructs a secure heterogeneous splitting mechanism and a multi-level hidden salt hash chain to achieve hardware-based traceability and integrity verification of message digests. These two types of fragmented messages are then embedded into a double-layered nested signature data structure. This invention simultaneously achieves the comprehensive goals of enhanced quantum security, hardware-level identity traceability verification, national cryptographic compliance signature verification, and multi-factor collaborative depth protection. Therefore, it provides highly robust, traceable, and multi-trust anchor point fusion technical support for digital signature systems during the quantum computing transition period.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122457259B_ABST
    Figure CN122457259B_ABST
Patent Text Reader

Abstract

The application provides a multi-level hash chain hybrid signature method and device, and belongs to the field of digital signature. The method comprises the following steps: generating a unique session ID and session context, reading a homologous quantum root key; obtaining a PUF negotiation root key and deriving a PUF session key; combining the unique session ID, the session context and the homologous quantum root key, performing a hash operation, and generating a unique session base key seed; performing heterogeneous splitting on an original signed message, and constructing a multi-level hidden salt hash chain; performing grouping on two message fragments and the multi-level hidden salt hash chain, performing compliance signature operation and post-quantum signature operation on the grouped data respectively, generating an inner layer national secret signature, and generating an outer layer anti-quantum trusted signature; packaging the above data to generate a signature data packet, and sending the signature data packet to a signature verification party. The application realizes the comprehensive goals of anti-quantum security enhancement, hardware-level identity traceability verification, national secret compliance signature verification and multi-factor collaborative in-depth protection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of digital signatures, and more specifically to a multi-level hash chain hybrid signature method and apparatus. Background Technology

[0002] Digital signatures are a core technology in cryptography, used to verify the authenticity, integrity, and non-repudiation of data. Authenticity ensures the signature's origin is traceable, preventing identity forgery; integrity guarantees the data has not been maliciously tampered with during transmission and storage; non-repudiation prevents the signer from later denying the signing, providing a legal basis for determining liability in electronic contracts, financial transactions, and other scenarios. In cryptographic systems, digital signatures are primarily implemented using asymmetric cryptography, generating the signature with the signer's unique private key, which can be verified by any verifier holding the corresponding public key. This process typically involves three key steps: first, a message of arbitrary length is compressed into a fixed-length digest using a hash function, ensuring that even minor alterations can be detected; second, the digest is signed using the private key to generate a signature value; and finally, the verifier uses the public key to verify the signature. If they match, it proves that the data has not been tampered with and was indeed signed by the private key holder.

[0003] In the field of digital signatures, widely used classical cryptographic algorithms include SM2, SM9, RSA, DSA, and ECDSA, whose security relies on mathematical problems such as large integer factorization or elliptic curve discrete logarithm problems. These algorithms have advantages such as high computational efficiency, high standardization, and mature software and hardware ecosystems, and continue to play a crucial role in mainstream scenarios such as e-government, financial payments, and code signing. However, with the rapid development of quantum computing technology, Shor's algorithm can efficiently solve these mathematical problems in polynomial time, posing a fundamental threat to the long-term security of classical digital signature schemes. To address this challenge, academia and industry are accelerating the research and application of post-quantum cryptography (PQC). The security of PQC algorithms is based on mathematical foundations such as lattice theory, hash functions, and coding theory, which are considered resistant to quantum attacks. In the field of digital signatures, lattice-based CRYSTALS-Dilithium and hash-based SPHINCS+ schemes have become core candidate algorithms in the PQC standardization process of the National Institute of Standards and Technology (NIST). These schemes can still maintain computational security in a quantum computing environment, but they generally face performance bottlenecks such as large signature size and high computational overhead, and there is an urgent need to find a better balance between security and efficiency.

[0004] Quantum Key Distribution (QKD) is a key exchange technology that achieves information-theoretic security based on the principles of quantum mechanics. Its core idea is to use the quantum states of single photons or weakly coherent light to transmit key information. Based on the Heisenberg uncertainty principle and the quantum no-cloning theorem, it ensures that any eavesdropping will introduce a detectable disturbance into the quantum channel. Once both communicating parties detect an abnormally high bit error rate, they can determine that eavesdropping has occurred and stop key generation, thus guaranteeing the absolute security of the final shared key. Currently, mainstream protocols include BB84, E91, and continuous-variable QKD, which have been practically deployed over hundreds of kilometers in fiber optic and free-space channels. Unlike traditional key exchange based on computational complexity, QKD's security does not rely on mathematical problem assumptions, and it still possesses long-term security guarantees even against attacks from future quantum computers. Therefore, QKD is considered a key component in building quantum-resistant cryptographic systems and is widely used in high-security fields such as government affairs, finance, and power.

[0005] A Physically Unclonable Function (PUF) is a hardware security technology based on the inherent differences in the physical characteristics of a chip. Its core principle lies in utilizing unavoidable process variations in semiconductor manufacturing, such as the random distribution of microscopic parameters like transistor threshold voltage, wire resistance, and oxide layer thickness, to generate a unique and uncopyable "digital fingerprint" for each chip. PUFs typically combine fuzzy extractor technology to reliably extract a stable and uniform key seed from the original response, and supplement this with public helper data to achieve key reconstruction. By binding the private key to the chip's physical characteristics, "invisible storage" of the key can be achieved—the key is generated in real-time by the PUF only when needed and discarded after use, effectively resisting physical probing and side-channel attacks.

[0006] However, current digital signatures have the following technical shortcomings:

[0007] Traditional single SM2 national cryptographic signatures cannot resist quantum computing attacks; conventional digital signatures lack reliable hardware identity verification carriers, making it difficult to achieve genuine and trustworthy entity identity confirmation and binding; conventional dual-algorithm parallel signatures generate the two signatures independently or simply stack them in modules, without establishing a deep binding link between the two signatures and the key and message, making it impossible to complete two-way trusted identity authentication based on dedicated keys, resulting in security issues such as message fragmentation and tampering, signature link disconnection, and cross-terminal identity forgery; in addition, existing solutions generally do not simultaneously incorporate a quantum root key and PUF hardware key collaboration mechanism, the inherent device-unique identity authentication value of the two types of keys is not utilized, the source of trust is singular, there is no effective technical basis for entity identity tracing and accountability, and it is difficult to simultaneously meet the hard requirements for commercial cryptographic compliance verification and global unique anti-reuse implementation. Summary of the Invention

[0008] The purpose of this invention is to provide a multi-level hash chain hybrid signature method and apparatus to at least solve the problems of quantum security shortcomings, lack of hardware trusted anchors, and insufficient security binding depth in the existing technology.

[0009] To achieve the above objectives, a first aspect of the present invention provides a multi-level hash chain hybrid signature method, the method being applied to the signer, and after the signer and the verifier establish a session, the method includes:

[0010] Generate a unique session ID and session context for this session, and read the same-source quantum root key stored locally on the signer's site;

[0011] Obtain the PUF negotiation root key and derive the PUF session key based on the unique session ID;

[0012] Combine the unique session ID, session context, and common quantum root key, and perform a hash operation to generate a unique session base key seed;

[0013] Obtain the original proxy-signed message, and perform heterogeneous splitting on the original proxy-signed message based on the security heterogeneous splitting rule created with the PUF session key to generate two message fragments;

[0014] A multi-level hidden salt hash chain is constructed based on two message fragments, a unique session base key seed, and a homogeneous quantum root key;

[0015] Grouping is performed on the two message fragments and the multi-level hidden salt hash chain to obtain two groups of data to be signed;

[0016] The SM2 algorithm is used to perform compliant signature operations on a group of data to be signed, generating an inner national cryptographic signature; the post-quantum algorithm is used to perform post-quantum signature operations on another group of data to be signed, generating an outer quantum-resistant trusted signature.

[0017] The original proxy signature message, unique session ID, session context, inner national cryptographic signature, and outer quantum-resistant trusted signature are packaged to generate a signature data packet, which is then sent to the signature verifier for verification.

[0018] Preferably, during the registration initialization phase between the signer and the verifier, the method further includes:

[0019] Both parties generate an SM2 key pair and a post-quantum algorithm key pair, respectively, where the two parties are the signer and the verifier. The SM2 key pair contains the SM2 public key, and the post-quantum algorithm key pair contains the post-quantum public key.

[0020] Both parties apply to a trusted certificate authority for a composite digital certificate, and the trusted certificate authority performs the digital signature. The composite digital certificate contains the SM2 public key and the post-quantum public key of the corresponding applicant.

[0021] During the registration phase, the first legitimacy verification is completed. Both parties send their respective composite digital certificates to each other through a trusted channel. Both parties verify the received SM2 public key and post-quantum public key. The other party stores the verified SM2 public key and post-quantum public key locally.

[0022] Preferably, the method further includes: generating a PUF negotiation root key during the registration initialization phase, including:

[0023] The signer invokes its own chip's underlying PUF hardware, inputs a unique challenge, and collects the PUF response;

[0024] The signer inputs the PUF response into the fuzz extractor to obtain the PUF root key and the corresponding auxiliary data;

[0025] The signer generates the first private key corresponding to the PUF root key based on the SM3 algorithm, and generates the first public key based on the first private key;

[0026] The signer obtains a second public key generated by the verifier, which is generated in the same way as the first public key; the first and second public keys are exchanged between the signer and verifier through a secure channel.

[0027] The signer performs SM2-ECDH key negotiation on the first private key and the second public key to generate a PUF negotiation root key shared by the signer and the verifier; the signer locks the PUF negotiation root key within the chip's secure area.

[0028] Preferably, the PUF negotiation root key is obtained, and the PUF session key is derived based on the unique session ID, including:

[0029] During the session, the underlying PUF hardware of the chip is invoked, the challenge is input, and a noisy PUF response is generated.

[0030] Obtain the auxiliary data stored locally, combine it with the noise PUF response, execute the fuzz extractor's reproducibility algorithm, and generate a new PUF root key;

[0031] Based on the SM3 algorithm, the private key corresponding to the new PUF root key is recalculated;

[0032] Within the chip's secure area, perform SM2-ECDH key negotiation on the private key corresponding to the new PUF root key to derive the PUF negotiation root key;

[0033] Input the PUF negotiation root key and unique session ID into the HKDF-SM3 key derivation function to derive the PUF session key for this session.

[0034] Preferably, the secure heterogeneous splitting rule is as follows:

[0035] Perform an SM3 hash operation on the original message to be signed to obtain the message digest hash value;

[0036] Perform an SM3 hash operation on the PUF session key, unique session ID, and session context to generate two message security splitting factors;

[0037] Two message fragments are generated by performing an XOR operation between the two message security splitting factors and the message digest hash value.

[0038] Preferably, a multi-level hidden salt hash chain is constructed based on two message fragments, a unique session base key seed, and a common quantum root key, including:

[0039] The two message fragments and the unique session base key seed are combined to perform an SM3 hash operation to generate a binding factor;

[0040] Using the binding factor as the root node of the hash chain, a primary hidden salt hash chain is obtained;

[0041] By combining the primary hidden salt hash chain, the same quantum root key, the PUF session key, and the first message fragment, an SM3 hash operation is performed to obtain the secondary hidden salt hash chain;

[0042] Obtain the user identifier hash value from the SM2 algorithm, combine it with the secondary hidden salt hash chain, the second message segment, and the user identifier hash value, and perform the SM3 hash operation to obtain the final hidden salt hash chain.

[0043] Preferably, the verifier verifies the signed data packet, including:

[0044] The verifier parses the signature data packet to obtain the parsed original proxy signature message, unique session ID, session context, inner national cryptographic signature, and outer quantum-resistant trusted signature;

[0045] The signature verifier performs a replication of the unique session base key seed based on the parsed unique session ID and session context;

[0046] The signer splits the parsed original proxy signature message based on the security heterogeneous splitting rule, resulting in two new message fragments.

[0047] The signatory obtains the same quantum root key stored locally, and combines it with the new message fragments and the reproduced unique session base key seed to recreate a new multi-level hidden salt hash chain;

[0048] The signatory re-executes the grouping based on the two new message fragments and the new multi-level hidden salt hash, obtaining two groups of data to be verified.

[0049] The verification party calls the SM2 public key and, based on the SM2 verification algorithm, uses the first group of data to be verified to perform integrity and legality verification on the parsed inner-layer national cryptographic signature.

[0050] The verifier invokes the quantum public key and, based on the ML-DSA verification algorithm, uses the second set of data to be verified to perform integrity and legality checks on the parsed outer quantum-resistant trusted signature.

[0051] Preferably, the homologous quantum root key is obtained through offline QKD distribution or trusted initialization via a trusted channel.

[0052] Preferably, the session context includes: a timestamp, a single session random number, and unique identifiers for both parties in the session; the method further includes:

[0053] After the signatory parses the signed data packet, it extracts the session context;

[0054] The signature verification party coordinates with the local network-wide trusted time synchronization service to verify the valid validity period of the timestamp; it also synchronously compares the local one-time random number cache pool to verify the global uniqueness of the random number for a single session.

[0055] If timestamp timeout or duplicate random number in a single session occurs, the signature verification is terminated, and a signature verification failure message is returned to the signer.

[0056] Secondly, the present invention provides a multi-level hash chain hybrid signature apparatus for implementing the above-described multi-level hash chain hybrid signature method, the apparatus comprising:

[0057] The session generation module is used to generate a unique session ID and session context for this session, and to read the same-source quantum root key stored locally on the signer's site;

[0058] The key derivation module is used to obtain the PUF negotiation root key and derive the PUF session key based on the unique session ID.

[0059] The key generation module is used to combine the unique session ID, session context, and homogeneous quantum root key, and perform hash operation to generate a unique session base key seed;

[0060] The message splitting module is used to obtain the original proxy signature message, perform heterogeneous splitting on the original proxy signature message based on the security heterogeneous splitting rules created with the PUF session key, and generate two message fragments;

[0061] The hash chain creation module is used to construct a multi-level hidden salt hash chain based on two message fragments, a unique session base key seed, and a homogeneous quantum root key;

[0062] The data grouping module is used to group the two message fragments and the multi-level hidden salt hash chain to obtain two groups of data to be signed.

[0063] The session signature module is used to perform compliant signature operations on a group of data packets to be signed using the SM2 algorithm to generate an inner national cryptographic signature; and to perform a post-quantum signature operation on another group of data packets to be signed using a post-quantum algorithm to generate an outer quantum-resistant trusted signature.

[0064] The data sending module is used to package the original proxy signature message, unique session ID, session context, inner national cryptographic signature and outer quantum-resistant trusted signature to generate a signature data packet, and send the signature data packet to the verification party for verification of the signature data packet.

[0065] The beneficial effects of this invention are:

[0066] This invention is based on the deep integration of the national cryptographic SM2 algorithm and the post-quantum algorithm (ML-DSA). It coordinates the hardware root key of the physical non-cloning function with quantum keys, and constructs a secure heterogeneous splitting mechanism and a multi-level hidden salt hash chain to achieve hardware-based traceability and integrity verification of message digests. These two types of fragmented messages are then embedded into a double-layered nested signature data structure. This invention simultaneously achieves the comprehensive goals of enhanced quantum security, hardware-level identity traceability verification, national cryptographic compliance signature verification, and multi-factor collaborative depth protection. Therefore, it provides highly robust, traceable, and multi-trust anchor point fusion technical support for digital signature systems during the quantum computing transition period. Attached Figure Description

[0067] The accompanying drawings are provided to further illustrate embodiments of the present invention and form part of the specification. They are used together with the following detailed description to explain the embodiments of the present invention, but do not constitute a limitation thereof. In the drawings:

[0068] Figure 1 This is a flowchart of the multi-level hash chain hybrid signature method provided by the present invention;

[0069] Figure 2 This is a block diagram of the multi-level hash chain hybrid signature device provided by the present invention. Detailed Implementation

[0070] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the present invention will be briefly introduced below in conjunction with the accompanying drawings and descriptions of the embodiments or the prior art. Obviously, the following description of the structure of the accompanying drawings is only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort. It should be noted that the description of these embodiments is for the purpose of helping to understand the present invention, but does not constitute a limitation of the present invention.

[0071] Example 1

[0072] like Figure 1 As shown, this embodiment provides a multi-level hash chain hybrid signature method. The method is applied to the signer. After the signer and the verifier establish a session, the method includes:

[0073] Step S1: Generate a unique session ID and session context for this session, and read the same-source quantum root key stored locally on the signer's site.

[0074] Step S2: Obtain the PUF negotiation root key and derive the PUF session key based on the unique session ID.

[0075] Step S3: Combine the unique session ID, session context, and same-source quantum root key, and perform a hash operation to generate a unique session base key seed.

[0076] Step S4: Obtain the original proxy signature message, perform heterogeneous splitting on the original proxy signature message based on the security heterogeneous splitting rule created with the PUF session key, and generate two message fragments.

[0077] Step S5: Construct a multi-level hidden salt hash chain based on two message fragments, a unique session base key seed, and a common quantum root key.

[0078] Step S6: Perform grouping on the two message fragments and the multi-level hidden salt hash chain to obtain two groups of data to be signed.

[0079] Step S7: Use the SM2 algorithm to perform a compliant signature operation on a group of data to be signed to generate an inner national cryptographic signature; use the post-quantum algorithm to perform a post-quantum signature operation on another group of data to be signed to generate an outer quantum-resistant trusted signature.

[0080] Step S8: Package the original proxy signature message, unique session ID, session context, inner national cryptographic signature, and outer quantum-resistant trusted signature to generate a signature data packet, and send the signature data packet to the verification party for verification.

[0081] Therefore, this embodiment is based on the deep integration of the national cryptographic SM2 algorithm and the post-quantum algorithm (ML-DSA), and coordinates the physical non-cloning function hardware root key and quantum key. By constructing a secure heterogeneous splitting mechanism and a multi-level hidden salt hash chain, it realizes hardware traceability fragmentation and integrity verification fragmentation of message digests, and embeds the two types of fragmented messages into the data structure to be signed in a double-layered nested signature. This invention simultaneously achieves the comprehensive goals of quantum security enhancement, hardware-level identity traceability verification, national cryptographic compliance signature verification, and multi-factor collaborative in-depth protection, thereby providing highly robust, traceable, and multi-trust anchor point fusion technical support for digital signature systems during the quantum computing transition period.

[0082] In this embodiment, before the signer and the verifier establish a session, both parties (the signer and the verifier) ​​generate a PUF negotiation root key, create a SM2 key pair and a post-quantum algorithm key pair, and generate a consistent quantum root key between the two parties during the underlying trust root registration initialization phase. The SM2 key pair contains the SM2 public key, the post-quantum algorithm key pair contains the post-quantum public key, and the two parties generate a consistent quantum root key.

[0083] The steps for generating the PUF negotiation root key are as follows:

[0084] The signer invokes its own chip's underlying PUF hardware, inputs a unique challenge, and collects the PUF response. The signer then inputs the PUF response into a fuzz extractor to obtain the PUF root key and corresponding auxiliary data. Similarly, the verifier invokes its own chip's underlying PUF hardware, inputs a unique challenge, and collects the PUF response. The verifier then inputs the PUF response into a fuzz extractor to obtain the PUF root key and corresponding auxiliary data.

[0085] In other words, the signer and the verifier call their respective chip's underlying PUF hardware, input their own independent challenges (denoted as CRI_s and CRI_r), collect their own unique PUF responses in real time, execute the fuzz extractor generation algorithm Gen, and output their respective device's unique PUF root keys Key_puf_s and Key_puf_r, as well as the corresponding auxiliary data HelperData_s and HelperData_r.

[0086] The signer generates a first private key sk_puf_s based on PUF:

[0087] sk_puf_s= SM3(Key_puf_s || "ECDH_KEY_DERIVATION") mod n;

[0088] Where n is the order of the SM2 curve, "ECDH_KEY_DERIVATION" is a string constant used to distinguish key derivation, and || represents bit string concatenation.

[0089] Then generate the corresponding first public key pk_puf_s:

[0090] pk_puf_s = [sk_puf_s]G

[0091] Where G is the base point of the elliptic curve as specified in the SM2 standard.

[0092] Similarly, the signature verifier generates a second private key sk_puf_r based on PUF:

[0093] sk_puf_r = SM3(Key_puf_r || "ECDH_KEY_DERIVATION") mod n

[0094] Then generate the corresponding second public key pk_puf_r:

[0095] pk_puf_r = [sk_puf_r]G.

[0096] After both parties generate their respective private and public keys, they exchange the first and second public keys through a secure channel. Both parties then perform SM2-ECDH key negotiation within their respective chip security areas to generate a PUF negotiation root key K_puf that is shared only by both parties.

[0097] K_puf=SM2_ECDH(sk_puf_s,pk_puf_r)=SM2_ECDH(sk_puf_r,pk_puf_s)

[0098] Among them, K_puf is locked in the chip's secure area by the hardware and is never exported.

[0099] The steps for creating the SM2 public key and post-quantum public key for both parties in this embodiment are as follows: Both parties apply to a compliant commercial cryptography CA and obtain a composite digital certificate containing the SM2 public key and post-quantum public key. The verification party pre-stores and verifies the legality of the signing party's SM2 public key and post-quantum public key.

[0100] In other words, both parties generate an SM2 key pair and a post-quantum algorithm key pair, with each party acting as the signer and verifier. The SM2 key pair contains the SM2 public key, and the post-quantum algorithm key pair contains the post-quantum public key. Both parties apply for a composite digital certificate from a trusted Certificate Authority (CA). This composite digital certificate contains the SM2 public key and the post-quantum public key of both parties and is digitally signed by the CA. During the registration phase, the first legitimacy verification is completed. Both parties send the certificate to each other via a trusted channel. The other party verifies the CA signature of the composite digital certificate using a pre-stored CA root certificate. If the verification is successful, both the SM2 public key and the bound post-quantum public key within the certificate are trusted. Finally, the two are associated and stored locally.

[0101] In this embodiment, the same quantum root key is generated by the two parties through offline QKD distribution or trusted initialization via a trusted channel to obtain the same quantum root key.

[0102] For step S1, in the generated unique session ID and session context, the session context contains a timestamp, a single session random number (Nonce), and a unique identifier (ID_A) for both communicating parties.

[0103] Therefore, in step S2, the specific steps for obtaining the PUF negotiation root key and deriving the PUF session key based on the unique session ID are as follows: During the session phase, the chip's underlying PUF hardware is invoked, a challenge is input, and a noisy PUF response is generated; auxiliary data stored locally is obtained, and combined with the noisy PUF response, the fuzz extractor's reproducibility algorithm is executed to generate a new PUF root key; based on the SM3 algorithm, the private key corresponding to the new PUF root key is recalculated; within the chip's secure area, SM2-ECDH key negotiation is performed on the private key corresponding to the new PUF root key to derive the PUF negotiation root key; the PUF negotiation root key and the unique session ID are input into the HKDF-SM3 key derivation function to derive the current PUF session key.

[0104] The formula for calculating the PUF session key is as follows:

[0105] Key = HKDF-SM3(K_puf, SessionID);

[0106] In the formula, Key is the PUF session key, K_puf is the PUF negotiation root key, SessionID is the unique session ID, and HKDF-SM3() is the HKDF-SM3 key derivation function.

[0107] After generating the PUF session key, the unique session base key seed b_seed is generated by combining the same quantum root key and the unique session ID through the national cryptographic SM3 hash operation:

[0108] b_seed = SM3(Kqr || Ctx || SessionID)

[0109] In the formula, Kqr is the same-source quantum root key, Ctx is the session context, SessionID is the unique session ID, and SM3() is the SM3 hash operation function.

[0110] Specifically, in step S4, heterogeneous splitting is performed on the original message to be signed based on the security heterogeneous splitting rule created with the PUF session key, including: performing an SM3 hash operation on the original message to be signed to obtain a message digest hash value; performing an SM3 hash hash operation on the PUF session key, unique session ID and session context to generate two message security splitting factors; and performing an XOR operation on the message digest hash value with the two message security splitting factors respectively to generate two message fragments.

[0111] In other words, firstly, for the original message M to be signed of arbitrary length, perform the national cryptographic SM3 hash operation to obtain the message digest hash value H_M = SM3(M); then, based on the PUF hardware session key Key, generate a dedicated message security splitting factor through the national cryptographic SM3 hash operation. and .

[0112] Among them, message security splitting factor The calculation formula is:

[0113] =SM3 (Key||Ctx||SessionID||Nonce||0x01);

[0114] Among them, message security splitting factor The calculation formula is:

[0115] =SM3 (Key||Ctx||SessionID||Nonce||0x02);

[0116] In the formula, || represents the bit string concatenation operation.

[0117] Then, message security splitting factor and The message digest hash value H_M is subjected to secure heterogeneous splitting based on hardware entropy to achieve strong binding between the fragment and the original message and hardware key, thereby generating the first message fragment. Second message sharding :

[0118] ;

[0119] In the formula, ⊕ represents the XOR operation, and the first message fragment... It undertakes the hardware identity traceability and verification function, is directly derived from the PUF session key Key, and is inseparably bound to the physical chip of the signer.

[0120] ;

[0121] Second message fragment It binds the original message and hardware identity, and undertakes the function of tracing and verifying the integrity of the original message.

[0122] Specifically, in step S5, the steps for constructing a multi-level hidden salt hash chain based on two message fragments, a unique session base key seed, and a homologous quantum root key are as follows: The two message fragments and the unique session base key seed are combined to perform an SM3 hash operation to generate a binding factor; the binding factor is used as the root node of the hash chain to obtain a primary hidden salt hash chain; the primary hidden salt hash chain, the homologous quantum root key, the PUF session key, and the first message fragment are combined to perform an SM3 hash operation to obtain a secondary hidden salt hash chain; the user identifier hash value in the SM2 algorithm is obtained, and the secondary hidden salt hash chain, the second message fragment, and the user identifier hash value are combined to perform an SM3 hash operation to obtain a final hidden salt hash chain.

[0123] In this embodiment, the generated b_seed is first combined with... and Cooperatively perform SM3 hash operation to generate binding factor b:

[0124]

[0125] Then, with the binding factor b as the root node of the hash chain, the PUF hardware session key Key and the homologous quantum root key Kqr are used as two-layer hardware-level hidden salts and embedded in the hash iteration link to synchronously construct a complete multi-level hidden salt hash chain. The multi-level hidden salt hash chain includes three levels of hidden salt hash chains: primary hidden salt hash chain, secondary hidden salt hash chain, and final hidden salt hash chain.

[0126] Among them, the primary hidden salt hash chain The function expression is: = b;

[0127] Among them, the secondary hidden salt hash chain The function expression is:

[0128] ;

[0129] Among them, the final-level hidden salt hash chain The function expression is:

[0130] ;

[0131] In the formula, Z_A is the user identifier hash value in the SM2 standard.

[0132] Specifically, in step S6, grouping is performed on the two message shards and the multi-level hidden salt hash chain, as follows:

[0133] Fragment the first message Binding factor b, hidden salt hash chain Perform a concatenation to construct the first pending data group, Data_SM2:

[0134] ;

[0135] Fragment the second message Binding factor b, hidden salt hash chain Perform a concatenation to construct the second pending data group, Data_PQ:

[0136] .

[0137] Specifically, in step S7, using the signer's SM2 national cryptographic algorithm private key d_A, the SM2 national cryptographic algorithm is used to perform a compliant signature operation on Data_SM2, generating the inner national cryptographic signature σ_sm2.

[0138] σ_sm2= SM2_Sign(Data_SM2, d_A);

[0139] Simultaneously, using the signer's ML-DSA post-quantum algorithm private key sk_pq, the ML-DSA algorithm performs post-quantum signature operations on Data_PQ to generate an outer quantum-resistant trusted signature σ_pq:

[0140] σ_pq= ML-DSA_Sign(Data_PQ, sk_pq).

[0141] Specifically, in step S8, the signer packages the verification parameters required for this session and finally outputs the signed data packet. σ: σ = (σ_sm2, σ_pq, Ctx, SessionID, M), and then send the signed data packet to the signer to perform the verification operation.

[0142] As a further optimization of this embodiment, the verifying party verifies the signed data packet, including:

[0143] Step A1: The verifier parses the signature data packet to obtain the parsed original proxy signature message, unique session ID, session context, inner national cryptographic signature, and outer quantum-resistant trusted signature.

[0144] In this embodiment, after parsing the signed data packet, the session context Ctx is extracted. First, the local trusted time service is activated to strictly verify the valid validity period of the timestamp. The local one-time random number cache pool is compared synchronously to verify the global uniqueness of the nonce. If there is a risk of timestamp timeout or random number duplication, the signature verification is terminated directly and a signature failure is returned to the signer. If no such abnormality occurs, the subsequent steps are executed.

[0145] Step A2: The signature verifier performs a replication of the unique session base key seed based on the parsed unique session ID and session context.

[0146] The steps for reproducing the unique session base key seed in this embodiment are as follows:

[0147] The signature verifier invokes the PUF hardware response CRI_r, combines it with HelperData_r to recover the PUF root key Key_puf_r, and calculates the PUF-based private key sk_puf_r:

[0148] sk_puf_r= SM3(Key_puf_r || "ECDH_KEY_DERIVATION");

[0149] Then, within the chip's secure area, execute K_puf=SM2_ECDH(sk_puf_r, pk_puf_s) to regenerate the PUF negotiation root key K_puf. Combined with SessionID, the PUF session key Key' =HKDF-SM3(K_puf, SessionID) is derived using the HKDF-SM3 algorithm.

[0150] The signer retrieves the local, consistent quantum root key Kqr, combines it with the current compliant session context Ctx and the temporary session identifier SessionID, and strictly follows the same-source algorithm rules of the signer to reproduce the unique session basic key seed b_seed′=SM3(Kqr || Ctx || SessionID).

[0151] Step A3: The signer splits the parsed original proxy signature message based on the security heterogeneous splitting rules, resulting in two new message fragments.

[0152] Specifically, the verifying party uses the same secure heterogeneous splitting rules as the signing party to split the parsed original proxy signature message, as follows:

[0153] For the parsed message M, perform the national cryptographic SM3 hash operation to obtain the message digest hash value H_M′= SM3(M);

[0154] By using the SM3 hash operation (a national cryptographic standard), and based on the PUF hardware session key Key', a unique message security splitting factor is generated. and message security splitting factor ;

[0155] in, ;

[0156] in, ;

[0157] Based on message security splitting factor and The message digest hash value H_M′ is subjected to secure heterogeneous splitting based on hardware entropy, which strongly binds the fragment to the original message and hardware key, generating a new first message fragment. And the new second message segment ;

[0158] in, ;

[0159] in, .

[0160] Step A4: The signatory obtains the same quantum root key stored locally, and combines it with the new message fragment and the reproduced unique session base key seed to recreate a new multi-level hidden salt hash chain.

[0161] Specifically, the verifier uses the same construction method as the signer to create a new multi-level hidden salt hash chain, as follows:

[0162] Calculate the new binding factor Using b′ as the root node of the hash chain, embedding the PUF session key Key' and the homologous quantum root key Kqr as hierarchical hidden salts, and synchronously constructing a complete multi-level hidden salt hash chain: , .

[0163] Step A5: The signer re-executes the grouping based on the two new message fragments and the new multi-level hidden salt hash, and obtains two groups of data to be verified.

[0164] Similarly, assemble the data to be tested into groups Data_SM2′:

[0165] ;

[0166] Assemble the test data into groups Data_PQ′:

[0167] .

[0168] Step A6: The signer calls the SM2 public key and, based on the SM2 signature verification algorithm, uses the first group of data to be verified to perform integrity and legality verification on the parsed inner-layer national cryptographic signature.

[0169] Specifically, the compliant SM2 national cryptographic signature verification algorithm is invoked, using the signer's SM2 algorithm public key P_A, to execute the SM2 signature verification algorithm, SM2_Verify(Data_SM2', σ_sm2, P_A), to verify the integrity and legality of the received inner signature σ_sm2.

[0170] Step A7: The signer calls the post-quantum public key and, based on the ML-DSA signature verification algorithm, uses the second set of data to be verified to perform integrity and legality verification on the parsed outer quantum-resistant trusted signature.

[0171] Specifically, the standardized ML-DSA post-quantum signature verification algorithm is invoked, using the post-quantum public key pk_pq from the signer's post-quantum algorithm, to execute the ML-DSA signature verification algorithm, ML-DSA_Verify(Data_PQ', σ_pq, pk_pq), to verify the integrity and compliance of the received outer signature σ_pq.

[0172] This embodiment achieves bidirectional compatibility between national cryptographic compliance and quantum security. The inner layer of commercial cryptographic signature and verification complies with commercial cryptographic compliance requirements, while the outer layer of post-quantum signature verification can resist post-quantum attacks, meeting the iterative needs of future quantum networks. Relying on message heterogeneous splitting, binding factors, and a multi-level hash chain architecture, combined with dual-key authentication results, it achieves strong binding across all dimensions of message fragmentation, session keys, and hardware identity. Through a hardware entropy-based message digest functional splitting mechanism, the first fragment is directly derived from the PUF session and is indivisibly bound to the physical chip. The second fragment is simultaneously bound to the original message and hardware entropy. The binding factor integrates the quantum root key, session context, and dual-fragment information to form a computationally indistinguishable cryptographic binding. The multi-level hidden salt hash chain injects the above binding relationship layer by layer into the data to be signed by the two signatures, avoiding security issues such as single-node data tampering, signature link stripping and dismantling, and malicious repudiation. It integrates the quantum root key and the PUF hardware key. The collaborative verification of dual hardware keys, with both keys embedded in a layered hash chain, forms dual trust anchors, completing the device's original trusted identity authentication and ensuring full traceability. It achieves an inseparable binding between the signature and specific physical device and quantum channel, utilizing PUF session keys and quantum root keys as layered hidden salts embedded in the hash chain, and generating message splitting factors from the session context. This ensures that the signature data structure simultaneously contains quantum security attributes, hardware uniqueness attributes, and user identity attributes. The verifier can accurately locate the terminal hardware initiating the signature by reconstructing the hash chain, fundamentally preventing cross-device identity forgery and repudiation. It implements dual-mode hierarchical signature and verification using commercial cryptography and post-quantum cryptography, adapting to current mainstream SM2 commercial cryptography systems. Relying on a dual-message fragmentation complete verification base, it can independently disable the ML-DSA outer verification, performing only the inner SM2 complete verification without modifying hardware or business links, natively compatible with various national cryptographic business scenarios, and achieving a smooth transition deployment.

[0173] Example 2

[0174] Figure 2 This is a block diagram of a multi-level hash chain hybrid signature device provided in one embodiment of the present invention. Figure 2 As shown, this embodiment provides a multi-level hash chain hybrid signature device for implementing the multi-level hash chain hybrid signature method in Embodiment 1. The device includes:

[0175] The session generation module is used to generate a unique session ID and session context for this session, and to read the same-source quantum root key stored locally on the signer's site;

[0176] The key derivation module is used to obtain the PUF negotiation root key and derive the PUF session key based on the unique session ID.

[0177] The key generation module is used to combine the unique session ID, session context, and homogeneous quantum root key, and perform hash operation to generate a unique session base key seed;

[0178] The message splitting module is used to obtain the original proxy signature message, perform heterogeneous splitting on the original proxy signature message based on the security heterogeneous splitting rules created with the PUF session key, and generate two message fragments;

[0179] The hash chain creation module is used to construct a multi-level hidden salt hash chain based on two message fragments, a unique session base key seed, and a homogeneous quantum root key;

[0180] The data grouping module is used to group the two message fragments and the multi-level hidden salt hash chain to obtain two groups of data to be signed.

[0181] The session signature module is used to perform compliant signature operations on a group of data packets to be signed using the SM2 algorithm to generate an inner national cryptographic signature; and to perform a post-quantum signature operation on another group of data packets to be signed using a post-quantum algorithm to generate an outer quantum-resistant trusted signature.

[0182] The data sending module is used to package the original proxy signature message, unique session ID, session context, inner national cryptographic signature and outer quantum-resistant trusted signature to generate a signature data packet, and send the signature data packet to the verification party for verification of the signature data packet.

[0183] This embodiment also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the multi-level hash chain hybrid signature method in Embodiment 1.

[0184] This embodiment also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the multi-level hash chain hybrid signature method in Embodiment 1.

[0185] This embodiment is based on the deep integration of the national cryptographic SM2 algorithm and the post-quantum ML-DSA algorithm. It coordinates the physical non-cloning function hardware root key and quantum key, and constructs a secure heterogeneous splitting mechanism and a multi-level hidden salt hash chain to achieve hardware-based traceability and integrity verification of message digests. The two types of fragmented messages are then embedded into a double-layered nested signature data structure. This invention simultaneously achieves the comprehensive goals of enhanced quantum security, hardware-level identity traceability verification, national cryptographic compliance signature verification, and multi-factor collaborative depth protection. Therefore, it provides highly robust, traceable, and multi-trust anchor point fusion technical support for digital signature systems during the quantum computing transition period.

[0186] Those skilled in the art will understand that embodiments of this application can be provided as methods, apparatus, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0187] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (devices), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0188] The above are merely embodiments of this application and are not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of the claims of this application.

Claims

1. A multi-level hash chain hybrid signature method, characterized by, The method is applied to the signing party. After the signing party and the verifying party establish a session, the method includes: Generate a unique session ID and session context for this session, and read the same-source quantum root key stored locally on the signer's site; the same-source quantum root key is obtained through offline QKD distribution or trusted initialization based on a trusted channel; Obtain the PUF negotiation root key that is pre-locked in the chip's secure area, and derive the PUF session key based on the unique session ID; the PUF negotiation root key is obtained by the signer and the verifier through SM2-ECDH negotiation of key pairs derived from their respective PUF hardware. Combine the unique session ID, session context, and common quantum root key, and perform a hash operation to generate a unique session base key seed; Obtain the original message to be signed, perform an SM3 hash operation on the original message to be signed to obtain the message digest hash value; combine the two preset distinguishing bytes with the PUF session key, the unique session ID and the session context respectively and perform an SM3 hash operation to generate two message security splitting factors; perform an XOR operation on the message digest hash value according to the two message security splitting factors respectively to generate two message fragments; The SM3 hash operation is performed collaboratively with the two message fragments and the unique session base key seed to generate a binding factor; the binding factor is used as the root node of the hash chain to obtain the primary hidden salt hash chain; the primary hidden salt hash chain, the same source quantum root key, the PUF session key, and the first message fragment are combined to perform the SM3 hash operation to obtain the secondary hidden salt hash chain; the user identifier hash value in the SM2 algorithm is obtained, and the secondary hidden salt hash chain, the second message fragment, and the user identifier hash value are combined to perform the SM3 hash operation to obtain the final hidden salt hash chain; The first message fragment, binding factor, and last-level hidden salt hash chain are combined to construct the first data group to be signed. The second message fragment, binding factor, and second-level hidden salt hash chain are combined to construct the second data group to be signed. The SM2 algorithm is used to perform a compliant signature operation on the first data block to be signed, generating the inner national cryptographic signature σ_sm2: σ_sm2= SM2_Sign(Data_SM2, d_A); In the formula, SM2_Sign is the SM2 national cryptographic algorithm, Data_SM2 is the first data block to be signed, and d_A is the private key of the SM2 national cryptographic algorithm; The second group of data to be signed is processed using a post-quantum algorithm to generate an outer quantum-resistant trusted signature σ_pq. σ_pq= ML-DSA_Sign(Data_PQ, sk_pq) In the formula, ML-DSA_Sign is the ML-DSA post-quantum algorithm, Data_PQ is the second data block to be signed, and sk_pq is the private key of the ML-DSA post-quantum algorithm; The original message to be signed, the unique session ID, the session context, the inner national cryptographic signature, and the outer quantum-resistant trusted signature are packaged to generate a signature data packet, which is then sent to the signer for verification.

2. The multi-level hash chain hybrid signature method of claim 1, wherein, During the registration initialization phase between the signer and the verifier, the method further includes: Both parties generate an SM2 key pair and a post-quantum algorithm key pair, respectively, where the two parties are the signer and the verifier. The SM2 key pair contains the SM2 public key, and the post-quantum algorithm key pair contains the post-quantum public key. Both parties apply to a trusted certificate authority for a composite digital certificate, and the trusted certificate authority performs the digital signature. The composite digital certificate contains the SM2 public key and the post-quantum public key of the corresponding applicant. During the registration phase, the first legitimacy verification is completed. Both parties send their respective composite digital certificates to each other through a trusted channel. Both the signer and the verifier verify the SM2 public key and the post-quantum public key they receive. Both the signer and the verifier store the verified SM2 public key and the post-quantum public key locally.

3. The multi-level hash chain hybrid signature method of claim 2, wherein, The method further includes: during the registration initialization phase, the signer and the verifier negotiate the PUF negotiation root key through SM2-ECDH based on their respective PUF hardware-derived key pairs, including: The signer invokes its own chip's underlying PUF hardware, inputs a unique challenge, and collects the PUF response; The signer inputs the PUF response into the fuzz extractor to obtain the PUF root key and the corresponding auxiliary data; The signer inputs the PUF root key into the SM3 hash algorithm to generate a digest value, takes the modulo of the order of the SM2 curve of the digest value to obtain the first private key corresponding to the PUF root key, and generates the first public key based on the first private key; The signer obtains the second public key generated by the verifier, and the second public key is generated in the same way as the first public key; The signer performs SM2-ECDH key negotiation on the first private key and the second public key to generate a PUF negotiation root key shared by the signer and the verifier; the signer locks the PUF negotiation root key within the chip's secure area.

4. The multi-level hash chain hybrid signature method of claim 3, wherein, Obtain the PUF negotiation root key, and derive the PUF session key based on the unique session ID, including: During the session, the underlying PUF hardware of the chip is invoked, the challenge is input, and a noisy PUF response is generated. Obtain the auxiliary data stored locally, combine it with the noise PUF response, execute the fuzz extractor's reproducibility algorithm, and generate a new PUF root key; Based on the SM3 algorithm, the private key corresponding to the new PUF root key is recalculated; Within the chip's secure area, SM2-ECDH key negotiation is performed on the private key corresponding to the new PUF root key to recover the PUF negotiation root key consistent with that of the registration initialization phase; Input the PUF negotiation root key and unique session ID into the HKDF-SM3 key derivation function to derive the PUF session key for this session.

5. The multi-level hash chain hybrid signature method according to claim 4, wherein, The verifier verifies the signed data packet, including: The verifier parses the signature data packet to obtain the original message to be signed, the unique session ID, the session context, the inner national cryptographic signature, and the outer quantum-resistant trusted signature. The signature verifier performs a replication of the unique session base key seed based on the parsed unique session ID and session context; The signature verifier splits the parsed original message to be signed based on the security heterogeneous splitting rule, resulting in two new message fragments. The signatory obtains the same quantum root key stored locally, and combines it with the new message fragments and the reproduced unique session base key seed to recreate a new multi-level hidden salt hash chain; The signatory re-executes the grouping based on the two new message fragments and the new multi-level hidden salt hash, obtaining two groups of data to be verified. The signer calls the SM2 public key stored locally and, based on the SM2 signature verification algorithm, uses the first group of data to be verified to perform integrity and legality verification on the parsed inner national cryptographic signature. The verifier calls the locally stored post-quantum public key and, based on the ML-DSA verification algorithm, uses the second set of data to be verified to perform integrity and legality verification on the parsed outer quantum-resistant trusted signature.

6. The multi-level hash chain hybrid signature method of claim 5, wherein, The session context includes: a timestamp, a single session random number, and unique identifiers for both parties in the session; the method further includes: After the signatory parses the signed data packet, it extracts the session context; The signature verification party coordinates with the local trusted time synchronization service across the entire network to verify the valid validity period of the timestamp; it also compares the local one-time random number cache pool to verify the local uniqueness of the random number for a single session. If timestamp timeout or duplicate random number in a single session occurs, the signature verification is terminated, and a signature verification failure message is returned to the signer.

7. A multi-level hash chain hybrid signature apparatus for implementing the multi-level hash chain hybrid signature method of any one of claims 1-6, characterized by, The device includes: The session generation module is used to generate a unique session ID and session context for this session, and read the same source quantum root key stored locally on the signer's site; the same source quantum root key is obtained through offline QKD distribution or trusted initialization based on a trusted channel; The key derivation module is used to obtain the PUF negotiation root key that is pre-locked in the chip's secure area and derive the PUF session key based on the unique session ID. The PUF negotiation root key is obtained by the signer and the verifier through negotiation via SM2-ECDH based on key pairs derived from their respective PUF hardware. The key generation module is used to combine the unique session ID, session context, and homogeneous quantum root key, and perform hash operation to generate a unique session base key seed; The message splitting module is used to obtain the original message to be signed, perform an SM3 hash operation on the original message to be signed to obtain the message digest hash value; combine the two preset distinguishing bytes with the PUF session key, the unique session ID and the session context respectively and perform an SM3 hash operation to generate two message security splitting factors; perform an XOR operation on the message digest hash value according to the two message security splitting factors respectively to generate two message fragments. The hash chain creation module is used to jointly perform SM3 hash operation with two message fragments and a unique session base key seed to generate a binding factor; using the binding factor as the root node of the hash chain, a primary hidden salt hash chain is obtained; combining the primary hidden salt hash chain, the same quantum root key, the PUF session key, and the first message fragment, an SM3 hash operation is performed to obtain a secondary hidden salt hash chain; obtaining the user identifier hash value from the SM2 algorithm, combining the secondary hidden salt hash chain, the second message fragment, and the user identifier hash value, an SM3 hash operation is performed to obtain the final hidden salt hash chain; The data grouping module is used to combine the first message fragment, binding factor, and last-level hidden salt hash chain to construct the first data group to be signed, and to combine the second message fragment, binding factor, and second-level hidden salt hash chain to construct the second data group to be signed. The session signature module is used to perform compliant signature operations on the first data block to be signed using the SM2 algorithm, generating the inner national cryptographic signature σ_sm2. σ_sm2= SM2_Sign(Data_SM2, d_A); In the formula, SM2_Sign is the SM2 national cryptographic algorithm, Data_SM2 is the first data block to be signed, and d_A is the private key of the SM2 national cryptographic algorithm; The second group of data to be signed is processed using a post-quantum algorithm to generate a quantum-resistant trusted outer signature σ_pq. σ_pq= ML-DSA_Sign(Data_PQ, sk_pq) In the formula, ML-DSA_Sign is the ML-DSA post-quantum algorithm, Data_PQ is the second data block to be signed, and sk_pq is the private key of the ML-DSA post-quantum algorithm; The data sending module is used to package the original message to be signed, the unique session ID, the session context, the inner national cryptographic signature, and the outer quantum-resistant trusted signature to generate a signature data packet, and send the signature data packet to the signer for verification.

Citation Information

Patent Citations

  • Post quantum cryptography and cryptographic algorithm mixed signature and verification method and device

    CN119483944A

  • Hybrid collaborative signature method fusing SM2 and post quantum cryptography algorithm

    CN121567329A