Distributed data signature and verification method and apparatus

By segmenting digital signatures and using cloud servers with geolocation numbers for distributed verification, the high cost of signature verification in existing technologies is solved, achieving efficient signature computation and verification.

WO2026091085A1PCT designated stage Publication Date: 2026-05-07VIEWAT TECH (SHENZHEN) CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
VIEWAT TECH (SHENZHEN) CO LTD
Filing Date
2024-11-01
Publication Date
2026-05-07

AI Technical Summary

Technical Problem

Existing technologies require significant investment in infrastructure upgrades or increased terminal costs to improve verification capabilities in big data signature and verification processing, resulting in low efficiency.

Method used

A distributed data signature verification method is adopted, which divides the digital signature into N segments and assigns M segments to cloud servers according to their geographical locations. Verification is performed by matching the cloud server corresponding to the successful number, and the computing power of multiple authentication centers is used for distributed parallel processing.

Benefits of technology

It improves the efficiency of signature calculation and verification, reduces time and resource consumption, makes full use of the computing power of existing cloud services, and avoids resource clustering and congestion.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024129350_07052026_PF_FP_ABST
    Figure CN2024129350_07052026_PF_FP_ABST
Patent Text Reader

Abstract

Disclosed in the present invention are a distributed data signature and verification method and apparatus. The method comprises: segmenting a numerical value of a digital signature into N segments of numerical values, wherein the digital signature belongs to CA authentication; numbering cloud servers which execute the CA authentication, and segmenting each number into M segments of numerical values; and matching at least one segment of numerical values among the N segments of numerical values of the digital signature with the M segments of numerical values of each number, and if the matching is successful, selecting the cloud server corresponding to the successfully matched number to verify the digital signature, wherein both N and M are greater than 1. In the present invention, on the basis of existing facilities, the computing power of a plurality of dispersed authentication centers are used to simultaneously participate in signature and verification, thereby achieving the effect of distributed parallel processing, enabling the computing power of cloud services to be fully exerted, and also ensuring a higher efficiency, a higher speed and a shorter time for signature operations and signature verification.
Need to check novelty before this filing date? Find Prior Art

Description

A distributed data signature verification method and apparatus Technical Field

[0001] This invention relates to the field of data processing, and in particular to a distributed data signature verification method and apparatus. Background Technology

[0002] In the era of big data, cloud services are the foundation of big data. Various types of data are generated, transmitted, and stored on the network. Therefore, the authenticity of all this data needs to be verified and validated, requiring efficient methods and technologies to achieve the best results in data applications. For example, in facial recognition applications, how can we quickly retrieve corresponding information from the database based on the collected facial features? Because the data volume is large and multiple verifications and calculations are required, many servers are needed to participate in the big data signature operation to store more data. Technical issues

[0003] Existing technical solutions primarily rely on the increased computing power and network bandwidth of CA (Certificate Authority) centers to meet the growing demands for big data signature and verification processing. Some also employ offline verification methods. These methods all require significant investment in infrastructure upgrades or increased terminal costs to achieve stronger verification capabilities. Technical solutions

[0004] To address the aforementioned technical problems, this invention provides a distributed data signature verification method and apparatus, ensuring higher efficiency in signature computation and verification.

[0005] A first aspect of the present invention provides a distributed data signature verification method, comprising:

[0006] The digital signature is segmented into N segments, and the digital signature is subject to CA authentication.

[0007] Assign a number to the cloud server performing CA authentication, and then segment the number into M segments of values;

[0008] At least one segment of the N segments of the digital signature is matched with the M segments of the number. If a match is successful, the cloud server corresponding to the successfully matched number is selected to verify the digital signature; where N and M are both greater than 1.

[0009] In one optional implementation, the digital signature is segmented into N segments, including:

[0010] The digital signature value is hashed to obtain H_SIGN, which increases the randomness and discreteness of the digital signature value.

[0011] In one optional implementation, the digital signature is segmented into N segments, including:

[0012] The H_SIGN is divided into four segments, each containing four bytes.

[0013] In one optional implementation, the step of numbering the cloud server performing CA authentication and segmenting the number into M segments includes:

[0014] The cloud servers are numbered according to their geographical location, and the number is divided into four segments: the first segment represents the province, the second segment represents the city, the third segment represents the district, and the fourth segment represents the IP address of the cloud server.

[0015] In one optional implementation, each of the N segments contains a four-byte value range, with the range of numbers for the provinces with cloud servers corresponding to the range of the four-byte values; the range of numbers for the cities corresponding to the provinces corresponding to the four-byte values; and the range of numbers for the regions corresponding to the cities corresponding to the four-byte values.

[0016] In one optional implementation, the province number contains eight, and the four-byte value corresponding to 0 to 4294967295 is divided into eight segments, each segment corresponding to a number.

[0017] In an optional embodiment, the distributed data signature verification method further includes storing feature values ​​corresponding to the digital signature, and storing the feature values ​​in a corresponding cloud server based on the matching result of at least one segment of the N segments of the digital signature with the M segments of the number.

[0018] A second aspect of the present invention provides a distributed data signature verification device, comprising:

[0019] The first segmentation processing module is used to segment the digital signature into N segments, wherein the digital signature is a CA authentication.

[0020] The second segmentation processing module is used to assign a number to the cloud server performing CA authentication and process the number into M segments of values.

[0021] The verification module is used to match at least one segment of the N segments of the digital signature with the M segments of the number. If the match is successful, the cloud server corresponding to the successfully matched number is selected to verify the digital signature; where N and M are both greater than 1.

[0022] A third aspect of the present invention provides an electronic device comprising:

[0023] At least one processor; and at least one memory communicatively connected to the processor, wherein the memory stores program instructions executable by the processor, and the processor invokes the program instructions to perform the method as described in the first aspect of the present invention.

[0024] A fourth aspect of the present invention provides a computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a computer, performs the method described in the first aspect of the embodiments of the present invention. Beneficial effects

[0025] Based on existing facilities, this invention utilizes the computing power of multiple distributed authentication centers to participate in signing and verification simultaneously, achieving the effect of distributed parallel processing and fully leveraging the computing power of cloud services; at the same time, it ensures higher efficiency, faster speed, and shorter time for signature calculation and signature verification. Attached Figure Description

[0026] Figure 1 is a flowchart illustrating a distributed data signature verification method according to an embodiment of the present invention;

[0027] Figure 2 is a flowchart illustrating another distributed data signature verification method in an embodiment of the present invention;

[0028] Figure 3 is a flowchart illustrating another distributed data signature verification method in an embodiment of the present invention;

[0029] Figure 4 is a schematic diagram of a distributed data signature verification device according to an embodiment of the present invention. Detailed Implementation

[0030] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0031] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0032] A digital signature (also known as a public-key digital signature) is a unique string of numbers that only the sender of the information can generate and that cannot be forged by others. This string also serves as valid proof of the authenticity of the information sent by the sender. It is similar to a physical signature written on paper, but implemented using public-key cryptography techniques, and is used to authenticate digital information. A digital signature typically defines two complementary operations: one for signing and the other for verification. Digital signatures are an application of asymmetric key encryption and digital digest techniques.

[0033] When sending a message, the sender uses a hash function to generate a message digest from the message text, and then encrypts this digest with the sender's private key. This encrypted digest is sent to the receiver along with the message as the message's digital signature. The receiver first calculates the message digest from the received original message using the same hash function as the sender, and then uses the public key to decrypt the digital signature attached to the message. If the two digests are the same, the receiver can confirm that the message belongs to the sender.

[0034] This invention, building upon existing infrastructure, utilizes the computing power of multiple distributed authentication centers to simultaneously participate in signing and verification, achieving distributed parallel processing and fully leveraging the computing power of cloud services. In this invention, feature information is hierarchically structured at multiple levels. This hierarchical approach identifies the corresponding storage server, where verification and querying are then performed. This different hierarchical information allows for the distribution of facial feature information, and the high degree of randomness in this distribution prevents the results from clustering, thereby improving efficiency.

[0035] Please refer to Figure 1. This invention provides a distributed data signature verification method, including:

[0036] Step 110: Divide the digital signature into N segments (N is greater than 1), and the digital signature belongs to CA authentication.

[0037] Digital signatures, also known as digital digests, have a fixed length. This invention performs a hash operation on the result of the digital signature to obtain H_SIGN. H_SIGN is the calculation result obtained by hashing the data. The hash operation is a Secure Hash Algorithm (SHA), a family of cryptographic hash functions, certified by FIPS. It is an algorithm that can calculate a fixed-length string (also known as a message digest) corresponding to a digital message. Furthermore, if the input messages are different, there is a high probability that they will correspond to different strings.

[0038] In this step, the digital signature value is hashed to obtain H_SIGN, increasing the random dispersion of the digital signature value. Because the characteristic of a digital signature value is that it has a very low repetition rate and strong dispersion, the hash operation further enhances this random dispersion. Utilizing this random dispersion characteristic, H_SIGN is then segmented to facilitate matching different cloud servers for CA authentication services. Typically, H_SIGN is a 16-byte data set, which can be divided into four segments of four bytes each.

[0039] Step 120: Number the cloud server performing CA authentication, and divide the number into M (M is greater than 1) segments.

[0040] For example, cloud servers are numbered according to their geographical location, also divided into four segments. For instance, the first segment represents the province, the second segment represents the city, the third segment represents the district, and the fourth segment represents the specific cloud server IP.

[0041] Step 130: Match at least one segment of the N segments of the digital signature with the M segments of the number. If the match is successful, select the cloud server corresponding to the successfully matched number to verify the digital signature.

[0042] Specifically, the first three segments of H_SIGN are matched with the first three segments of the cloud server ID. Once a match is found, the cloud server IP corresponding to the fourth segment is used to call the cloud server to verify the signature data.

[0043] Specifically, please refer to Figure 2. The distributed data signature verification method includes the following steps:

[0044] Step 210: Divide the H_SIGN into four segments, each containing four bytes.

[0045] Four bytes can represent a value from 0 to 4294967295, and the four segments are four values ​​from 0 to 4294967295 respectively.

[0046] Step 220: Divide the number into four numerical ranges.

[0047] For example, if there are data centers in 8 provinces in China, the range 0-4294967296 is divided into 8 segments, with each segment representing a different province. If the province number contains eight, the four-byte value corresponding to 0-4294967295 is divided into eight segments, with each segment corresponding to a number.

[0048] Accordingly, the cloud servers are numbered according to their geographical location, and the number is divided into four segments, where the first segment represents the province, the second segment represents the city, the third segment represents the district, and the fourth segment represents the IP address of the cloud server.

[0049] For example, 4294967296 can be divided into four segments, each with a value of 1073741824. The ranges from 1073741824 to 2147483648 to 3221225472 to 4294967296 represent the four extreme values ​​of each segment. If divided into eight segments, each segment would have a value of 536870912. For instance, Sichuan Province has 32 cities, so 0-4294967296 can be divided into 32 segments. Administrative divisions can also be divided similarly, with the number of segments corresponding to the number of districts and cities. Of course, not every city or district has a server, so the number of segments can be determined based on the actual situation. For example, the segment range for a city or district could be 0-4294967296, encompassing all four-byte values.

[0050] Step 230: Match the four byte segments with the four numerical ranges respectively.

[0051] As can be seen from the above, each of the N segments contains a four-byte value range, which corresponds to the range of numbers of the provinces with cloud servers; the range of numbers of the cities corresponding to the provinces; and the range of numbers of the areas corresponding to the cities.

[0052] Step 240: If the four bytes of the digital signature match the four numbers, then the cloud server IP corresponding to those four numbers is called to verify the digital signature. The first three bytes of H_SIGN are matched with the first three bytes of the cloud server number. If a match is found, the cloud server IP corresponding to the fourth byte is used to call the cloud server to verify the signature data.

[0053] This invention, based on existing cloud server infrastructure, utilizes the computing power of multiple distributed authentication centers to simultaneously participate in signing and verification, achieving distributed parallel processing and fully leveraging the computing power of cloud services. In this invention, feature information is hierarchically structured at multiple levels. This hierarchical approach identifies the corresponding server where the information is stored, and then verification and querying occur on that server. This different hierarchical information allows for the distribution of facial feature information, and because this feature information possesses good randomness, the distribution results do not cluster, thus improving efficiency.

[0054] Furthermore, the present invention also includes verifying the digital signature that needs to store feature values. As shown in Figure 3,

[0055] Step 310: Divide the H_SIGN into four segments, each containing four bytes.

[0056] Step 320: Divide the number into four numerical ranges.

[0057] Step 330: Match the four byte segments with the four numerical ranges respectively.

[0058] Step 340: If the four bytes of the digital signature match the four numbers, then call the cloud server IP corresponding to the four numbers to verify the digital signature.

[0059] Step 350: Store the feature value corresponding to the digital signature. Based on the matching result of at least one segment of the N segments of the digital signature with the M segments of the number, store the feature value in the corresponding cloud server.

[0060] For digital signatures that require storing feature values, the above method is used to calculate H_SIGN during the initial signature generation. Then, the same segmentation method is applied to find a matching server, and the feature value is stored on the corresponding server. Subsequent verifications will also use this matching method to find the corresponding server for verification. This ensures that data storage and verification calculations utilize server resources evenly, avoiding congestion and significantly improving the utilization of hardware and communication resources.

[0061] Referring to Figure 4, the present invention also provides a distributed data signature verification device, comprising:

[0062] The first segmentation processing module 41 is used to segment the digital signature into N segments, wherein the digital signature is a CA authentication.

[0063] The second segmentation processing module 42 is used to number the cloud server performing CA authentication and segment the number into M segments of values.

[0064] The verification module 43 is used to match at least one segment of the N segments of the digital signature with the M segments of the number. If the match is successful, the cloud server corresponding to the successfully matched number is selected to verify the digital signature; where N and M are both greater than 1.

[0065] Furthermore, the first segmentation processing module 41 is also used to perform a hash operation on the digital signature value to obtain H_SIGN, so as to increase the random discreteness of the digital signature value; and to divide the H_SIGN into four segments, each segment containing four bytes.

[0066] The second segmentation processing module 42 is also used to number the cloud server according to its geographical location and segment the number into four segments, wherein the first segment represents the province, the second segment represents the city, the third segment represents the district, and the fourth segment represents the IP of the cloud server.

[0067] Each of the N segments contains a four-byte value range, with the number range of the provinces with cloud servers corresponding to the range of these four-byte values. There are eight province numbers, and the four-byte values ​​from 0 to 4294967295 are divided into eight segments, each corresponding to a number.

[0068] The storage verification module 43 is further configured to map the range of the city's number corresponding to the province to the range of the four-byte values; and to map the range of the city's number to the range of the four-byte values. The distributed data signature verification device also includes a storage verification module, which stores the feature value corresponding to the digital signature. Based on the matching result of at least one segment of the N segments of the digital signature with the M segments of the number, the feature value is stored in the corresponding cloud server.

[0069] The present invention also provides an electronic device, comprising:

[0070] At least one processor; and at least one memory communicatively connected to the processor, wherein the memory stores program instructions executable by the processor, and the processor can execute the above-described distributed data signature verification method by invoking the program instructions.

[0071] The present invention also provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the above-described distributed data signature verification method.

[0072] It is understood that computer-readable storage media can include: any entity or device capable of carrying computer programs, recording media, USB flash drives, portable hard drives, magnetic disks, optical disks, computer memory, read-only memory (ROM), random access memory (RAM), and software distribution media, etc. Computer programs include computer program code. Computer program code can be in the form of source code, object code, executable files, or certain intermediate forms, etc. Computer-readable storage media can include: any entity or device capable of carrying computer program code, recording media, USB flash drives, portable hard drives, magnetic disks, optical disks, computer memory, read-only memory (ROM), random access memory (RAM), and software distribution media, etc.

[0073] In some embodiments of the present invention, the device may include a controller, which is a microcontroller chip integrating a processor, memory, communication module, etc. The processor may refer to the processor included in the controller. The processor may be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc.

[0074] Any process or method description in the flowchart or otherwise herein can be understood as representing a module, segment, or portion of code comprising one or more executable instructions for implementing a particular logical function or process, and the scope of the preferred embodiments of the invention includes additional implementations in which functions may be performed not in the order shown or discussed, including substantially simultaneously or in reverse order depending on the functions involved, as will be understood by those skilled in the art to which embodiments of the invention pertain.

[0075] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of each example have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this invention.

[0076] The above embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit it. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A distributed data signature verification method, characterized in that, include: The digital signature is segmented into N segments, and the digital signature is subject to CA authentication. Assign a number to the cloud server performing CA authentication, and then segment the number into M segments of values; At least one segment of the N segments of the digital signature is matched with the M segments of the number. If a match is successful, the cloud server corresponding to the successfully matched number is selected to verify the digital signature; where N and M are both greater than 1.

2. The distributed data signature verification method according to claim 1, characterized in that, The digital signature is segmented into N segments, including: The digital signature value is hashed to obtain H_SIGN, which increases the randomness and discreteness of the digital signature value.

3. The distributed data signature verification method according to claim 2, characterized in that, The digital signature is segmented into N segments, including: The H_SIGN is divided into four segments, each containing four bytes.

4. The distributed data signature verification method according to claim 1, characterized in that, The process of assigning a number to the cloud server performing CA authentication and dividing that number into M segments includes: The cloud servers are numbered according to their geographical location, and the number is divided into four segments: the first segment represents the province, the second segment represents the city, the third segment represents the district, and the fourth segment represents the IP address of the cloud server.

5. The distributed data signature verification method according to claim 4, characterized in that, Each of the N segments contains a four-byte value range, with the range of numbers for the provinces with cloud servers corresponding to the range of the four-byte values; the range of numbers for the cities corresponding to the provinces corresponding to the four-byte values; and the range of numbers for the regions corresponding to the cities corresponding to the four-byte values.

6. The distributed data signature verification method according to claim 4, characterized in that, The province number contains eight, and the four-byte value corresponding to 0 to 4294967295 is divided into eight segments, each segment corresponding to a number.

7. The distributed data signature verification method according to claim 1, characterized in that, It also includes storing the feature value corresponding to the digital signature, and storing the feature value in the corresponding cloud server according to the matching result of at least one segment of the N segments of the digital signature and the M segments of the number.

8. A distributed data signature verification device, characterized in that, include: The first segmentation processing module is used to segment the digital signature into N segments, wherein the digital signature is a CA authentication. The second segmentation processing module is used to assign a number to the cloud server performing CA authentication and process the number into M segments of values. The verification module is used to match at least one segment of the N segments of the digital signature with the M segments of the number. If the match is successful, the cloud server corresponding to the successfully matched number is selected to verify the digital signature; where N and M are both greater than 1.

9. An electronic device, characterized in that, include: At least one processor; And at least one memory communicatively connected to the processor, wherein: the memory stores program instructions executable by the processor, and the processor can execute the distributed data signature verification method as described in any one of claims 1 to 7 by invoking the program instructions.

10. A computer-readable storage medium, characterized in that, It stores a computer program, which, when executed by a computer, performs the distributed data signature verification method as described in any one of claims 1 to 7.

Citation Information

Patent Citations

  • Digital signature method, and method, device and system for verifying digital signature

    CN101980471A

  • Collaborative signature method, security service middleware, related platform and system

    CN111404696A

  • Distributed data signature verification method and device

    CN117134918A