CN109934585A

Signature method, device and system based on secure multi-party computing

Abstract

The embodiment of the invention discloses a signature method, device and system based on secure multi-party computing. The method comprises the following steps: obtaining transaction data, and generating a transaction hash from the transaction data by utilizing a preset rule; determining the signature level of the transaction data according to the relationship between the transaction limit and a first threshold value in the transaction data; determining a signature mechanism based on the signature level, the signature mechanism being a trusted mechanism for signing the transaction data; basedon the private key fragment stored by the determined signature mechanism and the private key fragment stored by the client, obtaining a signature file; wherein the transaction hash is signed and authenticated based on secure multi-party computing, private key fragments are stored in the trusted institution and the client respectively, and the private key fragments are composed of part of sub private keys generated based on segmentation of an asymmetric key. By utilizing the embodiment of the invention, the potential safety hazard of private key loss or stealing can be effectively solved, and the transaction security is greatly improved.

CN109934585A, drawing sheet 1
Sheet 1 of 1

Term

12.5 yearsto projected expiry

Projected expiry 8 March 2039, counted from filing; an application has no term until it is granted.

  1. Priority and filed
  2. Published
  3. Today
  4. Projected expiry

12 claims: 4 independent, 8 dependent

  1. 1
    1 A signature method based on secure multi-party computing, characterized by comprising:obtaining transaction data, and generating a transaction hash using preset rules for the transaction data;according to the relationship between the transaction amount in the transaction data and the first threshold, Determine the signature level of the transaction data;determine the signature authority based on the signature level, the signature authority being a trusted authority that signs the transaction data;based on the private key segment and the client saved by the determined signature authority The private key fragments stored by the client terminal are used to perform signature verification based on secure multi-party calculations on the transaction hash, wherein the trusted authority and the client respectively store private key fragments, and the private key fragments are It is composed of partial sub-private keys generated based on segmentation of asymmetric keys. 1 .一种基于安全多方计算的签名方法,其特征在于,包括: 获取交易数据,将所述交易数据利用预设规则生成交易哈希; 根据所述交易数据中交易额度与第一阈值的关系,确定所述交易数据的签名等级; 基于所述签名等级,确定签名机构,所述签名机构是对所述交易数据进行签名的可信 机构; 基于确定的签名机构所保存的私钥分片和客户端保存的私钥分片,对所述交易哈希进 行基于安全多方计算的签名认证,其中,所述可信机构和所述客户端分别保存有私钥分片, 所述私钥分片由基于对非对称密钥进行切分生成的部分子私钥组成。
  2. 7
    7 A signature device based on secure multi-party computing, characterized by comprising:a transaction data acquisition module for acquiring transaction data, and using the transaction data to generate a transaction hash using preset rules;a signature level determining module for The relationship between the transaction amount in the transaction data and the first threshold is used to determine the signature level of the transaction data;the signature authority determination module is configured to determine the signature authority based on the signature level, and the signature authority is responsible for determining the signature level of the transaction data. The trusted organization that performs the signature;the signature authentication module is used to divide the private key fragments saved by the determined signature organization and the private key saved by the client 7 .一种基于安全多方计算的签名装置,其特征在于,包括: 交易数据获取模块,用于获取交易数据,将所述交易数据利用预设规则生成交易哈希; 签名等级确定模块,用于根据所述交易数据中交易额度与第一阈值的关系,确定所述 交易数据的签名等级; 签名机构确定模块,用于基于所述签名等级,确定签名机构,所述签名机构是对所述交 易数据进行签名的可信机构; 签名认证模块,用于基于确定的签名机构所保存的私钥分片和客户端保存的私钥分 The transaction hash is authenticated by signature based on secure multi-party calculation, wherein the trusted organization and the client respectively store private key shards, and the private key shards are determined based on the pair of asymmetric keys It is composed of some sub-private keys generated by segmentation. 片,对所述交易哈希进行基于安全多方计算的签名认证,其中,所述可信机构和所述客户端 分别保存有私钥分片,所述私钥分片由基于对非对称密钥进行切分生成的部分子私钥组 成。
  3. 11
    11 A signature device based on secure multi-party computing, characterized by comprising a processor and a memory for storing processor-executable instructions, the instructions being executed by the processor include the following steps:acquiring transaction data, The transaction data uses a preset rule to generate a transaction hash;the signature level of the transaction data is determined according to the relationship between the transaction amount in the transaction data and the first threshold;the signature authority is determined based on the signature level, and the signature An institution is a trusted institution that signs the transaction data;based on the private key fragments stored by the determined signature institution and the private key fragments stored by the client, the transaction hash is authenticated based on secure multi-party calculations , Wherein the trusted organization and the client respectively store private key fragments, and the private key fragments are composed of partial sub-private keys generated based on splitting an asymmetric key. 11 .一种基于安全多方计算的签名设备,其特征在于,包括处理器及用于存储处理器可 执行指令的存储器,所述指令被所述处理器执行时实现包括以下步骤: 获取交易数据,将所述交易数据利用预设规则生成交易哈希; 根据所述交易数据中交易额度与第一阈值的关系,确定所述交易数据的签名等级; 基于所述签名等级,确定签名机构,所述签名机构是对所述交易数据进行签名的可信 机构; 基于确定的签名机构所保存的私钥分片和客户端保存的私钥分片,对所述交易哈希进 行基于安全多方计算的签名认证,其中,所述可信机构和所述客户端分别保存有私钥分片, 所述私钥分片由基于对非对称密钥进行切分生成的部分子私钥组成。
  4. 12
    12 A signature system based on secure multi-party computing, comprising at least one processor and a memory storing computer-executable instructions, and when the processor executes the instructions, it implements any one of claims 1-6 Method steps. 12 .一种基于安全多方计算的签名系统,其特征在于,包括至少一个处理器以及存储计 算机可执行指令的存储器,所述处理器执行所述指令时实现权利要求1-6中任意一项所述 方法的步骤。