A digital signature method and device, electronic equipment and storage medium

By deploying smart contracts on the blockchain and using short-range wireless communication to transmit user identity information, the problem of complex interactions between terminal devices in the digital signing process is solved, realizing automated signing, improving efficiency, and ensuring the credibility and immutability of the signature.

CN115130075BActive Publication Date: 2026-07-03ANT BLOCKCHAIN TECHNOLOGY (SHANGHAI) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
ANT BLOCKCHAIN TECHNOLOGY (SHANGHAI) CO LTD
Filing Date
2022-06-28
Publication Date
2026-07-03

AI Technical Summary

Technical Problem

During the digital signature process, users need to perform complex interactive processes between different terminal devices, resulting in low efficiency and a poor user experience.

Method used

User identity information is transmitted via short-range wireless communication between the first and second terminals, and the signing process is automatically performed using smart contracts deployed on the blockchain, which then call the corresponding digital seal based on the user's identity information.

Benefits of technology

It enables an automated digital signing process that requires no additional user intervention, improving efficiency and user experience while ensuring the credibility, traceability, and immutability of the signing process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115130075B_ABST
    Figure CN115130075B_ABST
Patent Text Reader

Abstract

This specification provides a digital signing method, apparatus, electronic device, and storage medium. The method includes: a first terminal acquiring a digital signing operation initiated by a user for a target digital file to be signed; in response to the digital signing operation, the first terminal acquiring the user's identity information and conducting short-range wireless communication with a second terminal maintaining the target digital file to transmit the user's identity information to the second terminal, so that the second terminal uses the user's identity information as a calling parameter to invoke a smart contract deployed on a blockchain for signing digital files, and performs signing processing on the target digital file based on a digital seal corresponding to the user's identity information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This specification relates to the field of blockchain technology, and more particularly to a digital signature method, apparatus, electronic device, and storage medium. Background Technology

[0002] Individuals, businesses, and organizations typically use their physical seals to sign documents. This means they can affix the image of their physical seal to paper documents or write their signatures to indicate that the seal holder or signer acknowledges the authenticity and correctness of the document.

[0003] To improve the efficiency of signature processing, with the advancement of information-based office work, the circulation of paper documents is also shifting to the circulation of digital documents. Digital seals (also known as electronic seals) have emerged, allowing users to use digital seals to sign digital documents.

[0004] However, when users manage their associated digital seals on one terminal device and need to sign digital documents maintained on another terminal device, they often have to go through a very complex interaction process. Therefore, improving the efficiency and user experience of digital signing in the above scenario has become an urgent problem to be solved. Summary of the Invention

[0005] This application provides a digital signature method, applied to a first terminal initiating a digital signature; the method includes:

[0006] Retrieve the digital signature operation initiated by the user for the target digital file to be signed;

[0007] In response to the digital signature operation, the user's identity information is obtained, and short-range wireless communication is established with a second terminal that maintains the target digital file to transmit the user's identity information to the second terminal. The second terminal then uses the user's identity information as a calling parameter to invoke a smart contract deployed on the blockchain for signing digital files. Based on the digital seal corresponding to the user's identity information, the target digital file is signed.

[0008] Optionally, the digital signature operation includes the user holding the first terminal close to the second terminal.

[0009] Optionally, the second terminal is equipped with a touch screen; the target digital file is output and displayed to the user through the touch screen.

[0010] The digital signature operation includes the user holding the first terminal and touching the touch screen of the second terminal;

[0011] The user's identity information is transmitted to the second terminal, which maintains the target digital file, via short-range wireless communication. The second terminal then uses the user's identity information as a parameter to invoke a smart contract deployed on the blockchain for signing digital files. Based on a digital seal corresponding to the user's identity information, the target digital file is signed, including:

[0012] The system performs short-range wireless communication with a second terminal that maintains the target digital file to transmit the user's identity information to the second terminal. The second terminal then uses the touch point on the touch screen of the first terminal and the user's identity information as calling parameters to invoke a smart contract deployed on the blockchain for signing digital files. Based on the digital seal corresponding to the user's identity information, the system performs a signature on the target digital file displayed to the user via the touch screen at the position corresponding to the touch point.

[0013] Optionally, the short-range wireless communication includes Near Field Communication (NFC).

[0014] This application also provides another digital signing method, applied to a second terminal that maintains a target digital document to be signed; the method includes:

[0015] The first terminal receives the user's identity information transmitted via short-range wireless communication with the second terminal in response to the user's digital signature operation on the target digital document.

[0016] In response to the user's identity information transmitted by the first terminal, the user's identity information is used as a calling parameter to invoke a smart contract deployed on the blockchain for signing digital files, and the target digital file is signed based on the digital seal corresponding to the user's identity information.

[0017] Optionally, the digital signature operation includes the user holding the first terminal close to the second terminal.

[0018] Optionally, the second terminal is equipped with a touch screen; the target digital file is output and displayed to the user through the touch screen.

[0019] The digital signature operation includes the user holding the first terminal and touching the touch screen of the second terminal;

[0020] The step of using the user's identity information as a calling parameter to invoke a smart contract deployed on the blockchain for signing digital documents, and signing the target digital document based on a digital seal corresponding to the user's identity information, includes:

[0021] Using the touch point on the touch screen of the first terminal on the second terminal and the user's identity information as calling parameters, the smart contract deployed on the blockchain for signing digital documents is invoked. Based on the digital seal corresponding to the user's identity information, the signing process is performed on the target digital document displayed to the user through the touch screen at the position corresponding to the touch point.

[0022] Optionally, the step of using the touch point on the touch screen of the first terminal on the second terminal and the user's identity information as calling parameters to call a smart contract deployed on the blockchain for signing digital documents, and performing signing processing on the target digital document displayed to the user through the touch screen at the position corresponding to the touch point based on the digital seal corresponding to the user's identity information, includes:

[0023] Generate authorization information to instruct the target digital document to be signed based on the user's digital seal;

[0024] The authorization information is signed based on the user's private key, and the signed authorization information is used as a calling parameter to be submitted to the smart contract deployed on the blockchain for signing digital files, so as to call the verification logic contained in the smart contract to verify the signature of the signed authorization information based on the user's public key.

[0025] In response to successful signature verification, the smart contract's signature logic is further invoked. Based on the digital seal corresponding to the user's identity information, the signature is processed at the position corresponding to the touch point in the target digital file displayed to the user via the touch screen.

[0026] Optionally, the method further includes:

[0027] Obtain the target digital file after the signature processing is complete;

[0028] The obtained target digital file with the completed signature processing will be output and displayed to the user.

[0029] Optionally, the short-range wireless communication includes Near Field Communication (NFC).

[0030] This application also provides a digital signature device, applied to a first terminal that initiates a digital signature; the device includes:

[0031] The acquisition unit is used to acquire digital signing operations initiated by the user for the target digital file to be signed;

[0032] The transmission unit is configured to, in response to the digital signature operation, obtain the user's identity information and conduct short-range wireless communication with a second terminal that maintains the target digital file to transmit the user's identity information to the second terminal, so that the second terminal uses the user's identity information as a calling parameter to call a smart contract deployed on the blockchain for signing digital files, and performs signature processing on the target digital file based on the digital seal corresponding to the user's identity information.

[0033] This application also provides another digital signing device for use on a second terminal that maintains a target digital document to be signed; the device includes:

[0034] The receiving unit is configured to receive the user's identity information transmitted by the first terminal in response to a digital signature operation initiated by the user for the target digital document, and by the second terminal through short-range wireless communication.

[0035] The signing unit is used to respond to the user's identity information transmitted by the first terminal, use the user's identity information as a calling parameter, call the smart contract deployed on the blockchain for signing digital files, and sign the target digital file based on the digital seal corresponding to the user's identity information.

[0036] This application also provides an electronic device, including a communication interface, a processor, a memory, and a bus, wherein the communication interface, the processor, and the memory are interconnected via the bus;

[0037] The memory stores machine-readable instructions, and the processor executes the above method by invoking the machine-readable instructions.

[0038] This application also provides a machine-readable storage medium storing machine-readable instructions, which, when called and executed by a processor, implement the above-described method.

[0039] In the above embodiments, on the one hand, the user only needs to initiate a digital signing operation on the target digital file maintained by the second terminal through the first terminal, and the first terminal only needs to respond to the digital signing operation by transmitting the user's identity information to the second terminal through short-range wireless communication. The second terminal can then call the smart contract deployed on the blockchain based on the obtained user identity information and automatically sign the target digital file based on the digital seal corresponding to the user's identity information. That is, the digital signing process can be automatically realized without requiring the user to perform other operations, thereby improving the user experience of digital signing and increasing the efficiency of digital signing.

[0040] On the other hand, since smart contracts for signing digital documents are deployed on the blockchain, the second terminal can invoke the smart contracts to sign the target digital documents based on the obtained user identity information; therefore, based on the decentralized, immutable, and traceable characteristics of blockchain, the credibility, traceability, and immutability of the digital signing process can be guaranteed. Attached Figure Description

[0041] To more clearly illustrate the technical solutions of the embodiments in this specification, the drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this specification. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0042] Figure 1 This is a schematic diagram illustrating the application environment of a blockchain-based digital signature method in one embodiment of this specification.

[0043] Figure 2 This is a schematic diagram illustrating the creation and invocation of a smart contract in one embodiment of this specification;

[0044] Figure 3 This is a flowchart of a digital signature method in one embodiment of this specification;

[0045] Figure 4 This is a flowchart of a digital signature method in another embodiment of this specification;

[0046] Figure 5 This is a schematic diagram of the structure of the electronic device containing the digital signature device in one embodiment of this specification;

[0047] Figure 6 This is a block diagram of a digital signature device according to one embodiment of this specification;

[0048] Figure 7 This is a block diagram of a digital signature device in another embodiment of this specification. Detailed Implementation

[0049] To enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions in the embodiments of this specification will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this specification, and not all embodiments. Based on the embodiments in this specification, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of this specification.

[0050] Individuals, businesses, and organizations typically use their physical seals to sign documents. This means they can affix the image of their physical seal to paper documents or write their signatures to indicate that the seal holder or signer acknowledges the authenticity and correctness of the document.

[0051] Common types of seals can be categorized into company seals, invoice seals, contract seals, legal representative seals, and financial seals. In practical applications, users can use specific types of seals to sign corresponding types of documents; for example, a company seal can be used to sign company announcements, and a contract seal can be used to sign commercial contracts, and so on.

[0052] However, physical seals present many inconveniences in their use. For example, they need to be kept and managed by designated personnel; users need to submit a seal application before using them, and receive the seal after the application is approved; and after using the physical seal to stamp paper documents, the seal needs to be properly kept and returned promptly.

[0053] To improve the efficiency of signature processing, with the advancement of information-based office work, the circulation of paper documents is also shifting to the circulation of digital documents. Digital seals (also known as electronic seals) have emerged, allowing users to use digital seals to sign digital documents.

[0054] However, when users manage their associated digital seals on one terminal device and need to sign digital documents maintained on another terminal device, they often have to go through a very complex interaction process. Therefore, improving the efficiency and user experience of digital signing in the above scenario has become an urgent problem to be solved.

[0055] In view of this, this specification aims to propose a technical solution for transmitting user identity information between two terminals via short-range wireless communication, and then automatically signing digital documents based on the acquired identity information.

[0056] In implementation, the first terminal initiating the digital signature can obtain the digital signature operation initiated by the user for the target digital file to be signed; in response to the digital signature operation, the first terminal can obtain the user's identity information and conduct short-range wireless communication with the second terminal maintaining the target digital file to transmit the user's identity information to the second terminal; further, after receiving the user's identity information, the second terminal can use the user's identity information as a calling parameter to call the smart contract deployed on the blockchain for signing digital files, and perform signing processing on the target digital file based on the digital seal corresponding to the user's identity information.

[0057] For example, the first terminal can be a mobile terminal such as a mobile phone, and the second terminal can be a PC (Personal Computer). The first terminal can be equipped with a client for managing user identity information or a client for managing user digital seals. In a scenario where a user uses a mobile phone to manage digital seals associated with that user and processes digital documents to be signed displayed on a screen on the PC, if the first terminal displays available digital seals and selectable digital documents to be signed, in response to detecting the user's selection of a digital seal and a digital document, the first terminal can obtain the user's digital signing operation for that digital document. Then, the first terminal can conduct short-range wireless communication with the second terminal to transmit the user's identity information to the second terminal. Furthermore, the second terminal can use the received user's identity information as a calling parameter to invoke a smart contract deployed on the blockchain for signing digital documents, and process the digital document based on the digital seal corresponding to the user's identity information.

[0058] Therefore, in the technical solution described in this specification, on the one hand, the user only needs to initiate a digital signing operation on the target digital file maintained by the second terminal through the first terminal, and the first terminal only needs to respond to the digital signing operation by transmitting the user's identity information to the second terminal through short-range wireless communication. The second terminal can then call the smart contract deployed on the blockchain based on the obtained user identity information and automatically sign the target digital file based on the digital seal corresponding to the user's identity information. In other words, the digital signing process can be automatically implemented without requiring the user to perform any other operations, thereby improving the user experience and efficiency of digital signing.

[0059] On the other hand, since smart contracts for signing digital documents are deployed on the blockchain, the second terminal can invoke the smart contracts to sign the target digital documents based on the obtained user identity information; therefore, based on the decentralized, immutable, and traceable characteristics of blockchain, the credibility, traceability, and immutability of the digital signing process can be guaranteed.

[0060] To enable those skilled in the art to better understand the technical solutions in the embodiments of this specification, the relevant blockchain technologies involved in the embodiments of this specification will be briefly described below.

[0061] Current blockchain systems typically include two main transaction models: one is the UTXO (Unspent Transaction Output) model, represented by the Bitcoin system; the other is the account model, represented by the Ethereum system.

[0062] When using an account-based blockchain to store data, the blockchain node devices need to store and maintain blockchain data, which typically includes block data and account status data corresponding to blockchain accounts. Block data can further include block header data, block transaction data, and transaction receipts corresponding to the block transaction data, etc.

[0063] When storing the various blockchain data shown above, blockchain node devices typically organize this data into a Merkle tree in the database, using key-value pairs. To query this blockchain data stored on the node device, the key of each data point can be used as a query index to traverse the Merkle tree for efficient data retrieval.

[0064] In this type of blockchain model, smart contracts for data notarization can be deployed on the blockchain. Users can call the smart contract to store the data that needs to be notarized as the account status of the contract account corresponding to the smart contract in the Merkle tree corresponding to the smart contract.

[0065] For example, Ethereum typically uses a special Merkle tree called an MPT tree to store and maintain blockchain data. Account state data is organized into an MPT state tree (commonly known as the world state) and stored in the database. The MPT state tree stores key-value pairs with the account address as the key and the account state data as the value. The data stored in the contract account corresponding to a smart contract is further organized into a storage tree (an MPT storage tree used to store data) and stored in the database. The hash value of the root node of the storage tree is used as part of the account state data corresponding to that contract account and populated into the MPT state tree. The hash of the root node of the MPT state tree is then used as the authentication root and further populated into the block header. When a user needs to store data, they can call a smart contract to store the data to be stored as the account state data of the contract account corresponding to that smart contract in the storage tree corresponding to that smart contract.

[0066] In the blockchain field, an important concept is the account. Taking Ethereum as an example, Ethereum typically divides accounts into two categories: external accounts and contract accounts. External accounts are accounts directly controlled by users, also known as user accounts; while contract accounts are accounts created by users through external accounts and contain contract code (i.e., smart contracts). Of course, for some blockchain models derived from the Ethereum architecture (such as Ant Blockchain), the types of accounts supported by the blockchain can be further expanded, which is not specifically limited in this specification.

[0067] For accounts in a blockchain, their state is typically maintained through a structure. When a transaction in a block is executed, the state of the account associated with that transaction in the blockchain usually changes as well.

[0068] In one example, the account structure typically includes fields such as Balance, Nonce, Code, and Storage. Among them:

[0069] The Balance field is used to maintain the current account balance.

[0070] The Nonce field is used to maintain the number of transactions for this account; it is a counter used to ensure that each transaction can be processed exactly once, effectively preventing replay attacks.

[0071] The Code field is used to maintain the contract code of the account; in practice, the Code field usually only maintains the hash value of the contract code; therefore, the Code field is often also called the Codehash field.

[0072] The Storage field is used to maintain the storage content of this account (the default field value is empty); for contract accounts, a separate storage space is usually allocated to store the storage content of the contract account; this separate storage space is usually referred to as the account storage of the contract account.

[0073] The stored content of a contract account is typically constructed into an MPT (Merkle Patricia Trie) tree data structure and stored in the aforementioned independent storage space; the MPT tree constructed based on the stored content of the contract account is also commonly referred to as the Storage tree. The Storage field usually only maintains the root node of this Storage tree; therefore, the Storage field is also commonly referred to as the StorageRoot field.

[0074] For external accounts, the Code and Storage fields shown above are both empty.

[0075] Please see Figure 1 , Figure 1 This is an exemplary embodiment illustrating an application environment diagram of a blockchain-based access verification method.

[0076] In such Figure 1 The network environment shown may include a client-side computing device 101, a server-side device 102, and at least one blockchain system; for example, blockchain system 103, blockchain system 104, and blockchain system 105.

[0077] In one embodiment, the client-side computing device 101 may include various different types of client-side computing devices; for example, client-side computing devices may include PC terminal devices, mobile terminal devices, Internet of Things devices, and other forms of intelligent devices with certain computing capabilities, etc.

[0078] In one implementation, at least a portion of the computing devices in the client-side computing device 101 can be coupled to the server-side 102 via various communication networks; for example... Figure 1 Devices 1 and 2 shown are coupled to server 102.

[0079] It is not difficult to understand that some computing devices in the client-side computing device 101 may not be coupled to the server-side 102, but instead act as blockchain nodes directly coupled to the blockchain system through various communication networks; for example, Figure 1 Device 4 shown in the diagram can be coupled to the blockchain system as a blockchain node.

[0080] The aforementioned communication network may include wired and / or wireless communication networks; for example, it may be a local area network (LAN), wide area network (WAN), Internet, or a combination thereof, based on a wired access network or wireless access network (such as a mobile cellular network) provided by an operator.

[0081] In one implementation, the client-side computing device 101 may further include one or more user-side servers; for example... Figure 1 Device 5 is shown in the diagram. At least a portion of the computing device in the client-side computing device 101 can be coupled to the user-side server, which can be further coupled to the aforementioned server 102; for example, Figure 1 Devices 1 and 2 shown are coupled to device 5, and device 5 is further coupled to server 102.

[0082] In one implementation, server 102 can also be coupled to one or more blockchain systems via various communication networks; for example... Figure 1 The server 102 shown can be coupled to blockchain system 103, blockchain system 104 and blockchain system 105, etc.

[0083] In one implementation, each blockchain system can maintain one or more blockchains (e.g., public blockchain, private blockchain, consortium blockchain, etc.) and include multiple blockchain nodes for hosting the aforementioned one or more blockchains; for example, such as Figure 1 The blockchain nodes 1, 2, 3, 4, and i shown can collectively support one or more blockchains. Cross-chain data access is also possible between the blockchains within each blockchain system, and between different blockchain systems themselves.

[0084] In one implementation, a blockchain node can be a physical device or a virtual device implemented in a server or server cluster. For example, a blockchain node device can be a physical host in a server cluster, or a virtual machine created by virtualizing the hardware resources of a server or server cluster based on virtualization technology. Each blockchain node can be coupled together to form a network through various types of communication methods (such as TCP / IP) to carry one or more blockchains.

[0085] In one implementation, server 102 may include a BaaS platform (also known as a BaaS cloud) for providing Blockchain as a Service (BaaS). The BaaS platform can provide pre-written software for activities occurring on the blockchain (such as subscriptions and notifications, user authentication, database management, and remote updates) to client-side computing devices coupled to the BaaS platform. This offers easy-to-use, one-click deployment, rapid verification, and flexible customization of blockchain services, thereby accelerating the development, testing, and deployment of blockchain business applications and facilitating the implementation of blockchain commercial application scenarios across various industries.

[0086] In one implementation, the BaaS platform can also provide enterprise-grade platform services based on blockchain technology to help enterprise customers build secure and stable blockchain environments and easily manage the deployment, operation, maintenance, and development of blockchains.

[0087] It's important to note that each time a new block is generated in the blockchain, the corresponding states of the executed transactions within that block change accordingly. For example, in a blockchain structured around an account model, the account states of external accounts or smart contract accounts typically change as transactions are executed.

[0088] For example, when a "transfer transaction" in a block is completed, the balances (i.e., the values ​​of the Balance field of these accounts) of the sender and receiver accounts associated with that "transfer transaction" will usually change accordingly.

[0089] For example, the "smart contract call transaction" in the block is used to call the smart contract deployed on the blockchain. The smart contract is called in the EVM corresponding to the node device to execute the "smart contract call transaction", and the account status of the smart contract account is updated in the smart contract account after the execution of the smart contract call transaction.

[0090] In practical applications, public, private, and consortium blockchains can all potentially offer smart contract functionality. A smart contract on a blockchain is a contract that can be triggered and executed through transactions. Smart contracts can be defined in the form of code.

[0091] Taking Ethereum as an example, it allows users to create and invoke complex logic within the Ethereum network. As a programmable blockchain, Ethereum's core is the Ethereum Virtual Machine (EVM), which can be run by every Ethereum node. The EVM is a Turing-complete virtual machine that can implement various complex logics. Users publish and invoke smart contracts on Ethereum, which run on the EVM. In fact, the EVM directly runs virtual machine code (virtual machine bytecode, hereinafter referred to as "bytecode"), so smart contracts deployed on the blockchain can be bytecode.

[0092] Please see Figure 2 , Figure 2 This is an exemplary embodiment illustrating a schematic diagram of creating and invoking a smart contract.

[0093] Creating a smart contract in Ethereum involves writing the smart contract, converting it into bytecode, and deploying it to the blockchain. Calling a smart contract in Ethereum involves initiating a transaction that points to the smart contract's address. Each node's EVM can execute this transaction, distributing the smart contract code across the virtual machines of every node in the Ethereum network.

[0094] After a user sends a transaction containing information about calling a smart contract to the Ethereum network, each node can execute this transaction in the EVM. The transaction's From field records the address of the account initiating the smart contract call, the To field records the address of the called smart contract, and the Data field records the method and parameters used to call the smart contract. After calling the smart contract, the contract account's state may change. Subsequently, a client can view the contract account's state through the connected blockchain node; for example, the account state can be stored in the smart contract's Storage tree in key-value pairs. The execution result of the smart contract call transaction can be stored in the MPT receipt tree in the form of a transaction receipt.

[0095] Smart contracts can be executed independently on each node of the blockchain in a prescribed manner. All execution records and data are stored on the blockchain. Therefore, once such a transaction is completed, the blockchain stores an immutable and unlost transaction certificate.

[0096] The technical solutions in this specification are described below through specific embodiments and in conjunction with specific application scenarios.

[0097] Please see Figure 3 , Figure 3 This is a flowchart of a digital signature method according to one embodiment of this specification. The above-described digital signature method can be applied to a first terminal that initiates a digital signature to implement the technical solution of this specification.

[0098] In this specification, the second terminal can be used to maintain digital files; the user can initiate a digital signing process for the target digital file that needs to be signed and processed, which is maintained by the second terminal, through the first terminal.

[0099] The first terminal and the second terminal can communicate wirelessly over short range to achieve data transmission. The second terminal can access the blockchain to achieve data interaction with the blockchain. Specifically, the second terminal can be connected to a node device in the blockchain or to a blockchain service platform. The blockchain can be any type of blockchain that provides smart contract functionality, and this specification does not impose any special limitations.

[0100] For example, combining Figure 1 The second terminal can be applied to the client-side computing device 101. Specifically, the second terminal can be directly connected to any node device in the blockchain system 103, or it can be connected through a blockchain service platform (such as...). Figure 1 The server (102) shown is connected to the blockchain system 103. The first terminal can connect to the blockchain system 103 to manage the user's digital seals stored in the blockchain; the first terminal can also communicate only with the second terminal without connecting to the blockchain system 103, which is not limited in this specification.

[0101] In this specification, the above-described digital signature method can be performed by following these steps:

[0102] Step 302: Obtain the digital signing operation initiated by the user for the target digital file to be signed;

[0103] Step 304: In response to the digital signature operation, obtain the user's identity information and conduct short-range wireless communication with the second terminal that maintains the target digital file to transmit the user's identity information to the second terminal, so that the second terminal uses the user's identity information as a calling parameter to call the smart contract deployed on the blockchain for signing digital files, and performs signature processing on the target digital file based on the digital seal corresponding to the user's identity information.

[0104] In this specification, the first terminal can acquire the digital signature operation initiated by the user for the target digital file.

[0105] The user who initiates the digital signing operation on the target digital file can be understood as the legitimate holder of the digital seal used for signing the target digital file, or another user authorized by the legitimate holder to use the digital seal. It should be noted that the user can be an individual user, or a non-individual user such as an institution, organization, or enterprise; this specification does not impose any restrictions.

[0106] The target digital file refers to any digital file that requires signing among all the digital files maintained by the second terminal. In implementation, the digital files maintained by the second terminal can be stored locally on the second terminal, or on a server or blockchain accessed by the second terminal. The second terminal can maintain the file identifier of the digital file and use it to access the corresponding digital file stored on the server or blockchain.

[0107] For example, the first terminal can output a user interface for signing digital documents to the user; the user can select a target digital document to be signed in the user interface; subsequently, in response to detecting the user's selection operation on the target digital document, the first terminal can consider that it has obtained the digital signing operation initiated by the user on the target digital document.

[0108] For example, after selecting the target digital file, the user clicks the "Confirm" button in the user interface. In response to detecting the user's click on the "Confirm" button, the first terminal can be considered to have obtained the digital signature operation initiated by the user on the target digital file.

[0109] For example, after selecting the target digital file, the user can also select a target digital seal from all the digital seals that the user has access to sign the target digital file. In response to detecting the user's selection operation on the target digital file and the target digital seal, the first terminal can consider that it has obtained the user's digital signing operation on the target digital file based on the target digital seal.

[0110] In one embodiment shown, the digital signature operation may include the user holding the first terminal close to the second terminal.

[0111] Specifically, when the distance between the first terminal and the second terminal is less than a preset threshold, it can be considered that the user holding the first terminal is close to the second terminal. It should be noted that those skilled in the art can flexibly set the value of the preset threshold as needed, and this specification does not impose any restrictions on it; for example, the value of the preset threshold can be no less than 0, and can not exceed the maximum distance supported by short-range wireless communication between the first terminal and the second terminal.

[0112] For example, if the first terminal detects that the user is holding the first terminal close to the second terminal, it can be determined that the user has initiated a digital signature operation on the target digital file.

[0113] In one possible scenario, the second terminal is equipped with a touchscreen display. The target digital document to be signed can be displayed to the user via the touchscreen display of the second terminal. Specifically, the digital signing operation may include the user holding the first terminal and touching the touchscreen display of the second terminal. For example, in response to the user holding the first terminal and touching the touchscreen display of the second terminal, it can be determined that the user has brought the first terminal close to the second terminal, thus the first terminal can obtain the user's initiated digital signing operation for the target digital document. Furthermore, in response to the user holding the first terminal and touching the touchscreen display of the second terminal, the second terminal can also determine the touch point of the first terminal on the touchscreen display of the second terminal.

[0114] In this specification, in response to the digital signature operation, the first terminal can obtain the user's identity information and conduct short-range wireless communication with the second terminal that maintains the target digital file to transmit the user's identity information to the second terminal; correspondingly, the second terminal can receive the user's identity information transmitted by the first terminal.

[0115] Specifically, the user's identity information may include one or more combinations of the following: the user's identity identifier (e.g., biometric information such as facial information, fingerprint information, account used to log in to the client, etc.); the user's blockchain account; and other information that can be used to uniquely identify the user.

[0116] For example, in response to receiving a digital signature operation initiated by the user for the target digital document, the first terminal can obtain the user's identity identifier and conduct short-range wireless communication with the second terminal to transmit the user's identity identifier to the second terminal; correspondingly, the second terminal can receive the user's identity identifier transmitted by the first terminal.

[0117] For example, in response to receiving a digital signature operation initiated by the user for the target digital file, the first terminal can obtain the user's identity identifier and the file identifier of the target digital file, and conduct short-range wireless communication with the second terminal to transmit the user's identity identifier and the file identifier of the target digital file to the second terminal; correspondingly, the second terminal can receive the user's identity identifier and the file identifier of the target digital file transmitted by the first terminal, and the user's identity identifier and the file identifier of the target digital file can be used to instruct the signing processing of the target digital file based on the user's digital seal.

[0118] In one embodiment shown, the short-range wireless communication may specifically include NFC (Near Field Communication). NFC technology is a short-range, high-frequency wireless communication technology that allows two NFC-enabled terminal devices to exchange data when they are close to each other.

[0119] For example, in response to receiving a digital signature operation initiated by the user for the target digital document, the first terminal can obtain the user's identity identifier and transmit the user's identity identifier to the second terminal via NFC technology; correspondingly, the second terminal can receive the user's identity identifier transmitted by the first terminal via NFC technology.

[0120] It should be noted that, in the embodiments shown above, compared with wireless communication technologies such as RFID (Radio Frequency Identification) and Bluetooth, using NFC technology to transmit the user's identity information between the first terminal and the second terminal is more secure, faster, and less costly.

[0121] For example, RFID technology has a communication range of up to 3 meters, Bluetooth technology up to 100 meters, while NFC technology has a communication range of less than 20 centimeters. Therefore, because the communication range supported by NFC technology is far shorter than that of other short-range wireless communication technologies, the user needs to hold the first terminal close enough to the second terminal to trigger a digital signature operation on the target digital document. This allows the user's identity information to be transmitted to the second terminal, thus preventing the misuse of the user's identity information and ensuring the security of the digital signature.

[0122] In one embodiment shown, to ensure that the user has the right to use the target digital seal and / or the right to sign the target digital document, the method may further include, before establishing short-range wireless communication with the second terminal: in response to obtaining the digital signature operation, authenticating the user based on the obtained user identity information; if the user authentication is successful, establishing short-range wireless communication with the second terminal to transmit the user's identity information to the second terminal.

[0123] For example, the association between digital seals and user identities can be maintained; the first terminal can search for the user's identity information corresponding to the target digital seal based on the above association; if it can be found, the user's identity verification can be considered successful; otherwise, the user's identity verification can be considered unsuccessful.

[0124] For example, the first terminal can search for the digital seal corresponding to the obtained user's identity information based on the association between the digital seal and the user's identity; if it can be found, the user's identity verification can be considered successful; otherwise, the user's identity verification can be considered unsuccessful.

[0125] In this specification, after the second terminal receives the user's identity information transmitted by the first terminal, in response to the user's identity information transmitted by the first terminal, the second terminal can use the user's identity information as a calling parameter to call the smart contract deployed on the blockchain for signing digital files, and perform signing processing on the target digital file based on the digital seal corresponding to the user's identity information.

[0126] Specifically, the implementation of the second terminal using the user's identity information as a calling parameter to call the smart contract deployed on the blockchain can be either a smart contract calling transaction or a request message.

[0127] For example, after the first terminal and the second terminal conduct short-range wireless communication, and the second terminal receives the user's identity information transmitted by the first terminal, if the second terminal is directly connected to a node device in the blockchain, the node device can receive a signing request transaction for the target digital file initiated by the second terminal. The signing request transaction may include the user's identity information. Furthermore, in response to the signing request transaction, the node device in the blockchain can invoke a smart contract deployed on the blockchain for signing digital files, and sign the target digital file based on a digital seal corresponding to the user's identity information.

[0128] For example, during short-range wireless communication between the first terminal and the second terminal, after the second terminal receives the user's identity information transmitted by the first terminal, if the second terminal accesses the blockchain through the blockchain service platform, the second terminal can send a signature request message for the target digital file to the blockchain service platform. The signature request message may include the user's identity information. Furthermore, in response to the signature request message, the blockchain service platform can initiate a signature request transaction for the target digital file to the node devices in the blockchain. Further, in response to the signature request transaction, the node devices in the blockchain can invoke a smart contract deployed on the blockchain for signing digital files, and sign the target digital file based on a digital seal corresponding to the user's identity information.

[0129] In one embodiment, the second terminal is equipped with a touch screen; the target digital document to be signed can be displayed to the user via the touch screen of the second terminal; the digital signing operation specifically includes the user holding the first terminal and touching the touch screen of the second terminal. In this case, since the second terminal can determine the touch point of the first terminal on the touch screen, the process of using the user's identity information as a calling parameter to invoke the smart contract deployed on the blockchain for signing digital documents, and signing the target digital document based on the digital seal corresponding to the user's identity information, specifically includes: using the touch point of the first terminal on the touch screen of the second terminal and the user's identity information as calling parameters to invoke the smart contract deployed on the blockchain for signing digital documents, and signing the target digital document at the position corresponding to the touch point in the touch screen-displayed target digital document.

[0130] For example, the target digital document to be signed can be displayed to the user via the touch screen of the second terminal. Based on the location in the target digital document where the stamping process is required, the user can hold the first terminal and touch the corresponding location in the target digital document displayed on the touch screen to initiate a digital signing operation at the location corresponding to the touch point. Furthermore, in response to the user's action of holding the first terminal and touching the touch screen of the second terminal, the second terminal can determine the touch point of the first terminal on the touch screen and can receive the user's identity information transmitted by the first terminal via short-range wireless communication. Further, the second terminal can use the touch point and the user's identity information as calling parameters to invoke a smart contract deployed on the blockchain for signing digital documents. Based on the digital seal corresponding to the user's identity information, the signing process is performed at the location corresponding to the touch point in the target digital document displayed to the user via the touch screen.

[0131] It should be noted that, in the embodiments shown above, the first terminal and the second terminal can "tap" each other to allow the second terminal to obtain information such as the user's identity information and the stamping location (i.e., the contact point of the first terminal on the touch screen). This enables the digital seal corresponding to the user's identity information to be stamped at a specified location in the target digital file maintained by the second terminal, thereby further simplifying the user operation in the digital stamping process, improving the user experience of digital signing, and increasing the efficiency of digital signing.

[0132] In another embodiment shown, to ensure the security of the digital seal, authorization can be granted based on the user's private key to use the user's digital seal to sign the target digital document.

[0133] The process of using the touch point on the touch screen of the first terminal on the second terminal and the user's identity information as calling parameters to invoke a smart contract deployed on the blockchain for signing digital files, and performing signing processing at the position corresponding to the touch point in the target digital file displayed to the user through the touch screen based on the digital seal corresponding to the user's identity information, specifically may include: generating authorization information to instruct the signing processing of the target digital file based on the user's digital seal; signing the authorization information based on the user's private key, and submitting the signed authorization information as a calling parameter to the smart contract deployed on the blockchain for signing digital files, so as to invoke the verification logic contained in the smart contract to verify the signature of the signed authorization information based on the user's public key; and in response to the signature verification passing, further invoking the signing logic contained in the smart contract to perform signing processing at the position corresponding to the touch point in the target digital file displayed to the user through the touch screen based on the digital seal corresponding to the user's identity information.

[0134] The authorization information may be generated based on one or more of the user's identity information, the file identifier of the target digital file, and the touch points on the touch screen of the first terminal on the second terminal.

[0135] For example, the authorization information may include the user's identity information, the file identifier of the target digital file, and the touch point. This information can then be used to instruct the user to authorize a signature based on their digital seal at the location corresponding to the touch point in the target digital file. Alternatively, the authorization information may include the user's identity information and the file identifier of the target digital file. This information can then be used to instruct the user to authorize a signature based on their digital seal at any location in the target digital file.

[0136] For example, the authorization information may not include the above-mentioned generation information, but only the generated authorization certificate file, which can be used to indicate that the user has authorized the use of the user's digital seal.

[0137] The smart contract includes verification logic, which is the verification logic corresponding to a portion of the contract code contained in the smart contract; the smart contract includes signing logic, which is the signing logic corresponding to a portion of the contract code contained in the smart contract.

[0138] The user's private key and public key are the private and public keys in a pair of asymmetric keys held by the user. For details on the specific implementation of signing the authorization information using the user's private key and verifying the signed authorization information based on the user's public key, please refer to relevant technologies; these details will not be elaborated upon here.

[0139] In practical applications, users can entrust their private keys to a storage system to avoid having to keep them safe themselves, thus providing convenience to users while ensuring the data security of the private keys.

[0140] In one scenario, the user's private key may be stored in a Trusted Execution Environment (TEE) mounted on the second terminal; the process of signing the authorization information based on the user's private key may specifically include: signing the authorization information based on the user's private key stored in the TEE.

[0141] In another scenario, the user's private key can be stored in the TEE (Trusted Equipment Environment) of the security hardware connected to the second terminal. The process of signing the authorization information based on the user's private key may specifically include: sending the authorization information to the security hardware so that the authorization information can be signed in the TEE based on the user's private key stored in the TEE.

[0142] In another scenario, the user's private key can be stored in a TEE (Transmission Equipment) hosted on a third-party storage platform. The process of signing the authorization information based on the user's private key may specifically include: sending the authorization information to the third-party storage platform, so that the third-party storage platform, within the TEE, signs the authorization information based on the user's private key stored in the TEE. The third-party storage platform can be a cloud storage platform.

[0143] In the embodiments shown above, the step of signing the target digital file based on the digital seal corresponding to the user's identity information may specifically include: obtaining the signature image corresponding to the user's digital seal and adding the signature image to the target digital file.

[0144] In one possible implementation, the blockchain maintains the association between user identity information and digital seals, allowing direct access to the digital seal corresponding to the user's identity information maintained on the blockchain. Specifically, the process of obtaining the signature image corresponding to the user's digital seal may include: obtaining the signature image of the user's digital seal based on the user's identity information.

[0145] In another possible embodiment, a digital seal for the user can be temporarily generated based on the obtained user's identity information. In implementation, the process of obtaining the signature image corresponding to the user's digital seal may specifically include: generating a signature image for the user's digital seal based on the user's identity information.

[0146] In the various embodiments shown above, the signature image corresponding to the user's digital seal can be directly added to the corresponding stamping position in the target digital file; or, the signature image corresponding to the user's digital seal can be added to the target digital file in the form of a digital watermark.

[0147] Optionally, the resolution of the digital watermark can be greater than the copying resolution. The copying resolution refers to the maximum resolution supported by the copying device; typically, since the copying resolution is designed with reference to the maximum resolution of the human eye, it usually does not exceed 300 dpi. Those skilled in the art can flexibly set the specific value of the digital watermark resolution as needed, and this specification does not impose any special restrictions; for example, if the printing resolution of the printing device is 1200 dpi, then the resolution of the digital watermark can be greater than the copying resolution and less than the printing resolution, that is, the resolution of the digital watermark can take any value within the range of (300 dpi, 1200 dpi).

[0148] It should be noted that when the resolution of the digital watermark is greater than the copy resolution, the printed copy and the copy corresponding to the target digital file can be distinguished. Based on this, when the target digital file with the added digital watermark is printed and then copied, the digital watermark will be "lost", making it impossible to detect the digital watermark in the copy, thus distinguishing the printed copy and the copy.

[0149] In one embodiment shown, in order to make the digital signature process traceable, the digital file that is signed based on the user's digital seal by calling the smart contract can be recorded so that the legality of the target digital file after the signature process is completed can be verified later.

[0150] In implementation, in response to the smart contract being invoked, node devices in the blockchain can generate a signature record of the user on the target digital file and store the generated signature record in the blockchain. Subsequently, if it is necessary to verify the legality of the target digital file provided by the user after it has been stamped, it can be determined whether a signature record corresponding to the target digital file is stored in the blockchain; if no such record is stored, it can be determined that the target digital file provided by the user after it has been stamped is an illegal document with a forged seal.

[0151] In this specification, in order to intuitively demonstrate to the user the result of the signature processing of the target digital file, after the target digital file is signed based on the digital seal corresponding to the user's identity information, the method may further include: the second terminal acquiring the target digital file after the signature processing is completed; and outputting and displaying the acquired target digital file after the signature processing is completed to the user.

[0152] For example, when a node device in the blockchain invokes the smart contract to sign the target digital file based on a digital seal corresponding to the user's identity information, it stores the signed target digital file in the blockchain so that the second terminal can obtain the signed target digital file and output and display the obtained signed target digital file to the user.

[0153] In one embodiment, after a node device in the blockchain invokes the smart contract to sign the target digital file based on a digital seal corresponding to the user's identity information, it can also generate a smart contract event corresponding to the signing of the target digital file. The smart contract event includes the target digital file after the signing process is completed. Furthermore, the generated smart contract event can be stored in the blockchain so that the second terminal can listen to the smart contract event stored in the blockchain. In response to listening to the smart contract event, the second terminal can obtain the target digital file after the signing process is completed and can output and display the obtained target digital file to the user.

[0154] In another embodiment shown, the node device in the blockchain or the blockchain server platform can listen for smart contract events stored in the blockchain; in response to listening for the smart contract event, the node device or the blockchain server platform can push the smart contract event to the second terminal based on its onboard event notification program; further, the second terminal can receive the smart contract event pushed by the event notification program. The target digital file with completed signing processing can be obtained and displayed to the user.

[0155] Specifically, the event notification program may include an SDK (Software Development Kit); the SDK can be used to provide a subscription service for smart contract events, that is, the SDK can listen for new smart contract events generated after a smart contract deployed on the blockchain is invoked, and can push the listened smart contract events to the corresponding user clients.

[0156] It should be noted that, in the above-described embodiments, compared to the implementation method where the second terminal actively listens for new smart contract events in the distributed ledger of the blockchain, by using an event notification program mounted on the blockchain service platform or the node device in the blockchain for event listening, the second terminal only needs to receive smart contract events pushed by the event notification program, which can save the event listening cost of the printing device.

[0157] As can be seen from the above embodiments, on the one hand, the user only needs to initiate a digital signature operation on the target digital file maintained by the second terminal through the first terminal, and the first terminal only needs to respond to the digital signature operation by transmitting the user's identity information to the second terminal through short-range wireless communication. The second terminal can then call the smart contract deployed on the blockchain based on the obtained user identity information and automatically sign the target digital file based on the digital seal corresponding to the user's identity information. That is, the digital signature process can be automatically realized without requiring the user to perform other operations, thereby improving the user experience of digital signature and increasing the efficiency of digital signature.

[0158] On the other hand, since smart contracts for signing digital documents are deployed on the blockchain, the second terminal can invoke the smart contracts to sign the target digital documents based on the obtained user identity information; therefore, based on the decentralized, immutable, and traceable characteristics of blockchain, the credibility, traceability, and immutability of the digital signing process can be guaranteed.

[0159] Please see Figure 4 , Figure 4 This is a flowchart of a digital signature method according to another embodiment of this specification. The above-described digital signature method can be applied to the second terminal to implement the technical solution of this specification. The above-described digital signature method can perform the following steps:

[0160] Step 402: Receive the user's identity information transmitted by the first terminal in response to the user's digital signature operation on the target digital document and by the second terminal via short-range wireless communication;

[0161] Step 404: In response to the user's identity information transmitted by the first terminal, the user's identity information is used as a calling parameter to call the smart contract deployed on the blockchain for signing digital files, and the target digital file is signed based on the digital seal corresponding to the user's identity information.

[0162] In this specification, the specific implementation of steps 402-404 is similar to that of steps 302-304 above, and will not be repeated here.

[0163] Corresponding to the embodiments of the digital signature method described above, this specification also provides embodiments of a digital signature device.

[0164] Please see Figure 5 , Figure 5 This is a schematic diagram of the electronic device containing the digital signature device in one embodiment of this specification. At the hardware level, the device includes a processor 502, an internal bus 504, a network interface 506, memory 508, and non-volatile memory 510, and may also include other hardware required for business operations. One or more embodiments of this specification can be implemented in software, for example, the processor 502 reads the corresponding computer program from the non-volatile memory 510 into memory 508 and then runs it. Of course, besides software implementation, one or more embodiments of this specification do not exclude other implementation methods, such as logic devices or a combination of hardware and software, etc. That is to say, the execution entity of the following processing flow is not limited to individual logic units, but can also be hardware or logic devices.

[0165] Please see Figure 6 , Figure 6 This is a block diagram of a digital signature device according to an embodiment of this specification. This digital signature device can be applied to, for example... Figure 5 The electronic device shown implements the technical solution of this specification. The digital signature device may include:

[0166] The acquisition unit 602 is used to acquire the digital signing operation initiated by the user for the target digital file to be signed;

[0167] The transmission unit 604 is configured to, in response to the digital signature operation, obtain the user's identity information and conduct short-range wireless communication with a second terminal that maintains the target digital file to transmit the user's identity information to the second terminal, so that the second terminal uses the user's identity information as a calling parameter to call a smart contract deployed on the blockchain for signing digital files, and performs signature processing on the target digital file based on the digital seal corresponding to the user's identity information.

[0168] In this embodiment, the digital signature operation includes the user holding the first terminal close to the second terminal.

[0169] In this embodiment, the second terminal is equipped with a touch screen; the target digital file is output and displayed to the user through the touch screen; the digital signature operation includes the user holding the first terminal and touching the touch screen of the second terminal;

[0170] The transmission unit 604 is specifically used for:

[0171] The touch point of the first terminal on the touch screen of the second terminal is determined, and short-range wireless communication is established between the first terminal and the second terminal, which maintains the target digital file, to transmit the user's identity information and the touch point to the second terminal. The second terminal then uses the touch point of the first terminal on the touch screen of the second terminal and the user's identity information as calling parameters to invoke a smart contract deployed on the blockchain for signing digital files. Based on the digital seal corresponding to the user's identity information, the signing process is performed at the position corresponding to the touch point in the target digital file displayed to the user through the touch screen.

[0172] In this embodiment, the short-range wireless communication includes Near Field Communication (NFC).

[0173] Please see Figure 7 , Figure 7 This is a block diagram of a digital signature device according to another embodiment of this specification. This digital signature device can be applied to, for example... Figure 5 The electronic device shown implements the technical solution of this specification. The digital signature device may include:

[0174] The receiving unit 702 is used to receive the user's identity information transmitted by the first terminal in response to the user's digital signature operation on the target digital file and by the second terminal through short-range wireless communication.

[0175] The signing unit 704 is used to respond to the user's identity information transmitted by the first terminal, use the user's identity information as a calling parameter, call the smart contract deployed on the blockchain for signing digital files, and sign the target digital file based on the digital seal corresponding to the user's identity information.

[0176] In this embodiment, the digital signature operation includes the user holding the first terminal close to the second terminal.

[0177] In this embodiment, the second terminal is equipped with a touch screen; the target digital file is output and displayed to the user through the touch screen; the digital signature operation includes the user holding the first terminal and touching the touch screen of the second terminal;

[0178] The signature unit 704 is specifically used for:

[0179] Using the touch point on the touch screen of the first terminal on the second terminal and the user's identity information as calling parameters, the smart contract deployed on the blockchain for signing digital documents is invoked. Based on the digital seal corresponding to the user's identity information, the signing process is performed on the target digital document displayed to the user through the touch screen at the position corresponding to the touch point.

[0180] In this embodiment, the signature unit 704 is specifically used for:

[0181] Generate authorization information to instruct the target digital document to be signed based on the user's digital seal;

[0182] The authorization information is signed based on the user's private key, and the signed authorization information is used as a calling parameter to be submitted to the smart contract deployed on the blockchain for signing digital files, so as to call the verification logic contained in the smart contract to verify the signature of the signed authorization information based on the user's public key.

[0183] In response to successful signature verification, the smart contract's signature logic is further invoked. Based on the digital seal corresponding to the user's identity information, the signature is processed at the position corresponding to the touch point in the target digital file displayed to the user via the touch screen.

[0184] In this embodiment, the device further includes a display unit, used for:

[0185] Obtain the target digital file after the signature processing is complete;

[0186] The obtained target digital file with the completed signature processing will be output and displayed to the user.

[0187] In this embodiment, the short-range wireless communication includes Near Field Communication (NFC).

[0188] The specific implementation process of the functions and roles of each unit in the above device can be found in the implementation process of the corresponding steps in the above method, and will not be repeated here.

[0189] For the device embodiments, since they basically correspond to the method embodiments, the relevant parts can be referred to in the description of the method embodiments. The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of the solution in this specification according to actual needs. Those skilled in the art can understand and implement this without creative effort.

[0190] In the 1990s, improvements to a technology could be clearly distinguished as either hardware improvements (e.g., improvements to the circuit structure of diodes, transistors, switches, etc.) or software improvements (improvements to the methodology). However, with technological advancements, many methodological improvements today can be considered direct improvements to the hardware circuit structure. Designers almost always obtain the corresponding hardware circuit structure by programming the improved methodology into the hardware circuit. Therefore, it cannot be said that a methodological improvement cannot be implemented using hardware physical modules. For example, a Programmable Logic Device (PLD) (such as a Field Programmable Gate Array (FPGA)) is such an integrated circuit whose logic function is determined by the user programming the device. Designers can program and "integrate" a digital system onto a PLD themselves, without needing chip manufacturers to design and manufacture dedicated integrated circuit chips. Furthermore, nowadays, instead of manually manufacturing integrated circuit chips, this programming is mostly implemented using "logic compiler" software. Similar to the software compiler used in program development, the original code before compilation must be written in a specific programming language, called a Hardware Description Language (HDL). There are many HDLs, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, and RHDL (Ruby Hardware Description Language). Currently, the most commonly used are VHDL (Very-High-Speed ​​Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art should understand that by simply performing some logic programming on the method flow using one of these hardware description languages ​​and programming it into an integrated circuit, the hardware circuit implementing the logical method flow can be easily obtained.

[0191] The controller can be implemented in any suitable manner. For example, it can take the form of a microprocessor or processor and a computer-readable medium storing computer-readable program code (e.g., software or firmware) executable by the (micro)processor, logic gates, switches, application-specific integrated circuits (ASICs), programmable logic controllers, and embedded microcontrollers. Examples of controllers include, but are not limited to, the following microcontrollers: ARC 625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicon Labs C8051F320. A memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art will also recognize that, in addition to implementing the controller in purely computer-readable program code form, the same functionality can be achieved by logically programming the method steps to make the controller take the form of logic gates, switches, application-specific integrated circuits, programmable logic controllers, and embedded microcontrollers. Therefore, such a controller can be considered a hardware component, and the means included therein for implementing various functions can also be considered as structures within the hardware component. Alternatively, the means for implementing various functions can be considered as both software modules implementing the method and structures within the hardware component.

[0192] The systems, devices, modules, or units described in the above embodiments can be implemented by computer chips or physical entities, or by products with certain functions. A typical implementation device is a server system. Of course, this application does not exclude the possibility that, with the future development of computer technology, the computer implementing the functions of the above embodiments can be, for example, a personal computer, a laptop computer, an in-vehicle human-machine interaction device, a cellular phone, a camera phone, a smartphone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or any combination of these devices.

[0193] While one or more embodiments of this specification provide the operational steps of the methods described in the embodiments or flowcharts, more or fewer operational steps may be included based on conventional or non-inventive means. The order of steps listed in the embodiments is merely one possible order of execution among many steps and does not represent the only possible order. In actual device or end product execution, the methods shown in the embodiments or drawings may be executed sequentially or in parallel (e.g., in a parallel processor or multi-threaded processing environment, or even a distributed data processing environment). The terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, product, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, product, or apparatus. Without further limitations, the presence of other identical or equivalent elements in the process, method, product, or apparatus that includes the elements is not excluded. For example, the use of terms such as "first," "second," etc., is to denote names and does not indicate any particular order.

[0194] For ease of description, the above devices are described in terms of function, divided into various modules. Of course, when implementing one or more of these specifications, the functions of each module can be implemented in one or more software and / or hardware components, or a module that performs the same function can be implemented by a combination of multiple sub-modules or sub-units. The device embodiments described above are merely illustrative. For example, the division of units is only a logical functional division; in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces, indirect coupling or communication connection between devices or units, and may be electrical, mechanical, or other forms.

[0195] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0196] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0197] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0198] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.

[0199] Memory may include non-persistent storage in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.

[0200] Computer-readable media, including both permanent and non-permanent, removable and non-removable media, can store information using any method or technology. Information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic magnetic disk storage, graphene storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.

[0201] Those skilled in the art will understand that one or more embodiments of this specification can be provided as a method, system, or computer program product. Therefore, one or more embodiments of this specification may take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, one or more embodiments of this specification may take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0202] One or more embodiments of this specification can be described in the general context of computer-executable instructions, such as program modules, that are executed by a computer. Generally, program modules include routines, programs, objects, components, data structures, etc., that perform a particular task or implement a particular abstract data type. One or more embodiments of this specification can also be practiced in distributed computing environments where tasks are performed by remote processing devices connected via a communication network. In a distributed computing environment, program modules can reside in local and remote computer storage media, including storage devices.

[0203] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, system embodiments are basically similar to method embodiments, so the description is relatively simple; relevant parts can be referred to the descriptions in the method embodiments. In the description of this specification, the terms "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., refer to specific features, structures, materials, or characteristics described in connection with that embodiment or example, which are included in at least one embodiment or example of this specification. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described can be combined in any suitable manner in one or more embodiments or examples. Moreover, without contradiction, those skilled in the art can combine and integrate the different embodiments or examples described in this specification and the features of different embodiments or examples.

[0204] The above description is merely an embodiment of one or more embodiments of this specification and is not intended to limit the scope of these embodiments. Various modifications and variations can be made to these embodiments by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this specification should be included within the scope of the claims.

Claims

1. A digital signature method, applied to a first terminal initiating a digital signature; the method comprising: Obtain a digital signing operation initiated by a user for a target digital document to be signed; wherein, the digital signing operation includes the user holding the first terminal close to the second terminal; In response to the digital signature operation, the system obtains the user's identity information and performs short-range wireless communication with the second terminal that maintains the target digital file to transmit the user's identity information to the second terminal. This causes the second terminal to generate authorization information instructing the signing of the target digital file based on a digital seal stored on the blockchain corresponding to the user's identity information. The authorization information is then signed using the user's private key, and the signed authorization information is submitted as a calling parameter to a smart contract deployed on the blockchain for signing digital files. This invokes the verification logic contained in the smart contract to verify the signature of the signed authorization information based on the user's public key. Furthermore, in response to successful signature verification, the system invokes the smart contract deployed on the blockchain for signing digital files to sign the target digital file based on the digital seal stored on the blockchain corresponding to the user's identity information.

2. The method according to claim 1, wherein the second terminal is equipped with a touch screen; the target digital file is output and displayed to the user through the touch screen; The digital signature operation includes the user holding the first terminal and touching the touch screen of the second terminal; The authorization information includes the touch points of the first terminal on the touch screen of the second terminal and the user's identity information; The signing process for the target digital document based on the digital seal corresponding to the user's identity information stored on the blockchain includes: Based on the digital seal stored on the blockchain corresponding to the user's identity information, the signature is processed at the position corresponding to the touch point in the target digital file displayed to the user through the touch screen.

3. The method according to claim 1, wherein the short-range wireless communication includes near-field communication (NFC).

4. A digital signature method, applied to a second terminal that maintains a target digital document to be signed; the method includes: The system receives the user's identity information transmitted via short-range wireless communication between the first terminal and the second terminal in response to a user-initiated digital signature operation on the target digital document; wherein the digital signature operation includes the user holding the first terminal close to the second terminal. In response to the user's identity information transmitted by the first terminal, authorization information is generated to instruct the target digital file to be signed based on a digital seal stored on the blockchain corresponding to the user's identity information. The authorization information is signed based on the user's private key, and the signed authorization information is submitted as a calling parameter to the smart contract deployed on the blockchain for signing digital files, so as to call the verification logic contained in the smart contract to verify the signature of the signed authorization information based on the user's public key. In response to successful signature verification, a smart contract deployed on the blockchain for signing digital documents is invoked to sign the target digital document based on the digital seal stored on the blockchain that corresponds to the user's identity information.

5. The method according to claim 4, wherein the second terminal is equipped with a touch screen; the target digital file is output and displayed to the user through the touch screen; The digital signature operation includes the user holding the first terminal and touching the touch screen of the second terminal; The authorization information includes the touch points of the first terminal on the touch screen of the second terminal and the user's identity information; Based on the digital seal stored on the blockchain corresponding to the user's identity information, the target digital document is signed, including: Based on the digital seal stored on the blockchain corresponding to the user's identity information, the signature is processed at the position corresponding to the touch point in the target digital file displayed to the user through the touch screen.

6. The method according to claim 4, further comprising: Obtain the target digital file after the signature processing is complete; The obtained target digital file with the completed signature processing will be output and displayed to the user.

7. The method according to claim 4, wherein the short-range wireless communication includes near-field communication (NFC).

8. A digital signature device, applied to a first terminal initiating a digital signature; the device comprising: The acquisition unit is used to acquire a digital signing operation initiated by the user for a target digital document to be signed; wherein, the digital signing operation includes the user holding the first terminal close to the second terminal; A transmission unit is configured to, in response to the digital signature operation, acquire the user's identity information and conduct short-range wireless communication with a second terminal that maintains the target digital file to transmit the user's identity information to the second terminal. This causes the second terminal to generate authorization information instructing the signing of the target digital file based on a digital seal stored on the blockchain corresponding to the user's identity information. The second terminal then signs the authorization information based on the user's private key and submits the signed authorization information as a calling parameter to a smart contract deployed on the blockchain for signing digital files. This invokes the verification logic contained in the smart contract to verify the signature of the signed authorization information based on the user's public key. Furthermore, in response to successful signature verification, the smart contract deployed on the blockchain for signing digital files is invoked to sign the target digital file based on the digital seal stored on the blockchain corresponding to the user's identity information.

9. A digital signature device, applied to a second terminal that maintains a target digital document to be signed; the device comprising: A receiving unit is configured to receive the user's identity information transmitted by the first terminal in response to a digital signature operation initiated by the user for the target digital document, and by the second terminal via short-range wireless communication; wherein the digital signature operation includes the user holding the first terminal close to the second terminal; The signing unit is configured to, in response to the user's identity information transmitted by the first terminal, generate authorization information instructing the signing of the target digital file based on a digital seal stored on the blockchain corresponding to the user's identity information; sign the authorization information based on the user's private key, and submit the signed authorization information as a calling parameter to a smart contract deployed on the blockchain for signing digital files, so as to call the verification logic contained in the smart contract to verify the signature of the signed authorization information based on the user's public key; and, in response to successful signature verification, call the smart contract deployed on the blockchain for signing digital files to sign the target digital file based on the digital seal stored on the blockchain corresponding to the user's identity information.

10. An electronic device, comprising a communication interface, a processor, a memory, and a bus, wherein the communication interface, the processor, and the memory are interconnected via the bus; The memory stores machine-readable instructions, and the processor executes the method of any one of claims 1-7 by invoking the machine-readable instructions.

11. A machine-readable storage medium storing machine-readable instructions that, when invoked and executed by a processor, implement the method of any one of claims 1-7.

Citation Information

Patent Citations

  • CN103309613A

  • CN112200569A