The invention relates to the technical field of
information security, and discloses a signature
verification system based on a digital
certificate. The
system comprises a
certificate state acquisition module, a distributed
verification network module, a local
verification agent module and a zero-knowledge verification engine module. According to the invention, most of
certificate state verification requests are locally processed by a user by constructing a distributed verification network and cooperating with a local cache and incremental synchronization mechanism, so that the real-time dependence on a centralized online certificate state protocol responder is greatly reduced; the verification performance
bottleneck caused by
network delay or overhigh load of the center node is effectively overcome, and the
processing efficiency of the signature verification service and the service reliability of the whole
system are remarkably improved. A zero-knowledge proof verification protocol is introduced, so that when remote verification is necessary, a user does not need to
expose a specific serial number of a certificate to be verified to a verification node, the leakage risk of a user service behavior track is fundamentally eradicated, and stronger
privacy protection capability is provided.