Block chain-based electronic contract signing method and related device
Electronic contracts are encrypted and distributedly signed through blockchain technology, solving the problems of data security and privacy protection in centralized systems, and achieving safe and efficient electronic contract signing.
Patent Information
- Application Number
- CN202510397308.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-31
- Publication Date
- 2025-07-18
AI Technical Summary
The existing electronic contract signing methods rely on centralized systems, with the risk of data and business logic being tampered with and leaked, and lack security and privacy protection.
Blockchain technology is adopted to encrypt the plain text of the electronic contract using symmetric keys, and use the public keys of each contract signing party to generate a key envelope list, and store it in the blockchain ledger through smart contracts, realizing distributed signing and signing process control, ensuring that only the authorized signing party can view and operate the contract data.
It improves the security and privacy protection of electronic contract signing, avoids the risks of data tampering and leakage, and ensures the decentralized storage and confidentiality of contract data.
Smart Images

Figure CN120337306A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of blockchain technology, and in particular, to a method for signing an electronic contract based on blockchain and related devices. Background Art
[0002] With the development of information technology, online signing has become a trend in the modern business field, and electronic contracts have gradually replaced traditional paper contracts. Compared with paper contracts, electronic contracts have the advantages of high signing efficiency, low cost, easy storage management, and easy access, which can bring convenience to the contract signing between signatories.
[0003] Under the existing technology, contract signing is usually carried out on an electronic contract system. The existing electronic contract system is usually a centralized platform. The contract-related data of the signatories is centrally stored in a centralized database, and the business logic of contract signing is implemented by a centralized background server, which has the risk of being tampered with and leaked for data and business logic.
[0004] In view of this, a method for signing an electronic contract based on blockchain needs to be proposed to overcome the above defects. Summary of the Invention
[0005] This application provides a method for signing an electronic contract based on blockchain and related devices to improve the security of electronic contract signing.
[0006] In a first aspect, an embodiment of this application provides a method for signing an electronic contract based on blockchain, which is applied to a contract initiator. The method includes:
[0007] Encrypt the plaintext of the electronic contract to be signed using a symmetric key to obtain the ciphertext of the electronic contract to be signed;
[0008] Encrypt the symmetric key using the respective public keys of each contract signatory of the electronic contract to be signed to generate a list of key envelopes, where the list of key envelopes includes: the respective key envelopes of each contract signatory;
[0009] Invoke a smart contract to store the ciphertext and the list of key envelopes in the blockchain ledger;
[0010] Obtain the signed electronic contracts returned by each contract signatory in the blockchain ledger to obtain the target electronic contract; the signed electronic contract is: after the corresponding contract signatory decrypts the ciphertext obtained from the blockchain ledger based on its key envelope and signs the corresponding digital signature on the plaintext.
[0011] In a possible embodiment, the method further includes:
[0012] Based on the CA certificate serial numbers of each contract signatory, a signing whitelist for the electronic contract to be signed is constructed, and the signing whitelist is used to verify whether the caller is an authorized contract signatory;
[0013] Invoke the smart contract and store the signing whitelist in the blockchain ledger.
[0014] Through the above method, precise access control is achieved, further improving the security of electronic contract signing.
[0015] In a possible embodiment, the respective digital signatures of each contract signatory are generated based on the private keys of the corresponding contract signatories;
[0016] In a possible embodiment, the signed electronic contracts returned by each contract signatory in the blockchain ledger have passed the correctness verification;
[0017] The correctness verification is a verification of the respective digital signatures of each contract signatory based on the respective public keys of each contract signatory.
[0018] Through the above method, the accuracy of the digital signature is ensured, guaranteeing the validity of the target electronic contract.
[0019] In a second aspect, an embodiment of the present application provides a blockchain-based electronic contract signing method, which is applied to a contract signatory. The method includes:
[0020] Invoke the smart contract to obtain the ciphertext of the electronic contract to be signed in the blockchain ledger and the key envelope of the contract signatory;
[0021] Use the private key of the contract signatory to decrypt the key envelope of the contract signatory to obtain the symmetric key;
[0022] Use the symmetric key to decrypt the ciphertext to obtain the plaintext of the electronic contract to be signed;
[0023] Generate a digital signature for the plaintext to obtain the signed electronic contract of the contract signatory, and invoke the smart contract to store the signed electronic contract in the blockchain ledger.
[0024] In a possible embodiment, invoking the smart contract to obtain the ciphertext of the electronic contract to be signed in the blockchain ledger and the key envelope of the contract signatory includes:
[0025] Send a contract query request for the electronic contract to be signed to the blockchain node;
[0026] When the contract signatory is an authorized contract signatory, receive the ciphertext of the electronic contract to be signed in the blockchain ledger and the key envelope of the contract signatory returned by the blockchain node.
[0027] Through the above method, the distributed collaboration of contracts is realized through the smart contract of the blockchain, and all contract data is stored on the chain and cannot be tampered with.
[0028] In a possible embodiment, the authorized contract signers are determined based on the CA certificate serial numbers of the contract signers and the signing whitelist of the electronic contract to be signed, where the signing whitelist consists of the CA certificate serial numbers of each contract signer of the electronic contract to be signed.
[0029] In a possible embodiment, generating a digital signature for the plaintext includes:
[0030] Using the private key of the contract signer to generate a digital signature for the plaintext.
[0031] Through the above method, the signing of the electronic contract to be signed is realized.
[0032] In a possible embodiment, calling the smart contract to store the signed electronic contract in the blockchain ledger includes:
[0033] Sending the signed electronic contract to the blockchain node, so that after the blockchain node verifies the digital signature of the contract signer based on the public key of the contract signer, the signed electronic contract is stored in the blockchain ledger.
[0034] Through the above method, the distributed signing of contracts is realized through the smart contract of the blockchain, and the signed electronic contract is stored on the chain and cannot be tampered with.
[0035] Thirdly, an embodiment of the present application further provides an electronic contract signing device based on the blockchain, which is applied to the contract initiator. The device includes:
[0036] The first encryption module is used to encrypt the plaintext of the electronic contract to be signed using a symmetric key to obtain the ciphertext of the electronic contract to be signed;
[0037] The second encryption module is used to encrypt the symmetric key using the public keys of each contract signer of the electronic contract to be signed to generate a key envelope list, and the key envelope list includes: the key envelopes of each contract signer;
[0038] The processing module is used to call the smart contract to store the ciphertext and the key envelope list in the blockchain ledger;
[0039] The receiving module is used to obtain the signed electronic contracts returned by each contract signer in the blockchain ledger to obtain the target electronic contract; the signed electronic contract is: after the corresponding contract signer decrypts the ciphertext obtained from the blockchain ledger based on its key envelope and signs the corresponding digital signature for the plaintext.
[0040] In a possible embodiment, the processing module is further configured to:
[0041] Based on the CA certificate serial numbers of each contract signatory, construct a signing whitelist for the electronic contract to be signed, where the signing whitelist is used to verify whether the caller is an authorized contract signatory;
[0042] Invoke a smart contract to store the signing whitelist in the blockchain ledger.
[0043] In a possible embodiment, the digital signature of each contract signatory is generated based on the private key of the corresponding contract signatory;
[0044] In a possible embodiment, the signed electronic contracts returned by each contract signatory in the blockchain ledger have passed the correctness verification;
[0045] The correctness verification is a verification of the digital signature of each contract signatory based on the public key of each contract signatory respectively.
[0046] Fourthly, an embodiment of the present application provides an electronic contract signing device based on a blockchain, which is applied to a contract signatory. The device includes:
[0047] An acquisition module, configured to invoke a smart contract to obtain the ciphertext of the electronic contract to be signed in the blockchain ledger and the key envelope of the contract signatory;
[0048] A first decryption module, configured to use the private key of the contract signatory to decrypt the key envelope of the contract signatory to obtain a symmetric key;
[0049] A second decryption module, configured to use the symmetric key to decrypt the ciphertext to obtain the plaintext of the electronic contract to be signed;
[0050] A signing module, configured to generate a digital signature for the plaintext to obtain the signed electronic contract of the contract signatory, and invoke a smart contract to store the signed electronic contract in the blockchain ledger.
[0051] In a possible embodiment, when invoking a smart contract to obtain the ciphertext of the electronic contract to be signed in the blockchain ledger and the key envelope of the contract signatory, the acquisition module is further configured to:
[0052] Send a contract query request for the electronic contract to be signed to the blockchain node;
[0053] When the contract signatory is an authorized contract signatory, receive the ciphertext of the electronic contract to be signed in the blockchain ledger and the key envelope of the contract signatory returned by the blockchain node.
[0054] In a possible embodiment, the contract signatory being the authorized contract signatory is determined based on the CA certificate serial number of the contract signatory and the signing whitelist of the electronic contract to be signed, where the signing whitelist consists of the CA certificate serial numbers of each contract signatory of the electronic contract to be signed.
[0055] In a possible embodiment, when generating a digital signature for the plaintext, the signing module is further configured to:
[0056] Use the private key of the contract signatory to generate a digital signature for the plaintext.
[0057] In a possible embodiment, when invoking a smart contract to store the signed electronic contract in the blockchain ledger, the signing module is further configured to:
[0058] Send the signed electronic contract to the blockchain node, so that after the blockchain node verifies the digital signature of the contract signatory based on the public key of the contract signatory, it stores the signed electronic contract in the blockchain ledger.
[0059] In a fifth aspect, an embodiment of the present application provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the steps of any of the above blockchain-based electronic contract signing methods are implemented.
[0060] In a sixth aspect, an embodiment of the present application provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of any of the above blockchain-based electronic contract signing methods are implemented.
[0061] In a seventh aspect, an embodiment of the present application provides a computer program product. When the computer program product is called by a computer, the computer is caused to execute the steps of any of the above blockchain-based electronic contract signing methods.
[0062] In the embodiment of the present application, first, the contract initiator encrypts the plaintext of the electronic contract to be signed using a symmetric key to obtain the ciphertext of the electronic contract to be signed; encrypts the symmetric key using the respective public keys of each contract signatory of the electronic contract to be signed to generate a key envelope list, where the key envelope list includes: the respective key envelopes of each contract signatory; invokes a smart contract to store the ciphertext and the key envelope list in the blockchain ledger.
[0063] Then, the contract signatories call the smart contract to obtain the ciphertext of the electronic contract to be signed in the blockchain ledger and the key envelope of the contract signatories; use the private key of the contract signatories to decrypt the key envelope of the contract signatories to obtain the symmetric key; use the symmetric key to decrypt the ciphertext to obtain the plaintext of the electronic contract to be signed; generate a digital signature for the plaintext to obtain the signed electronic contract of the contract signatories, and call the smart contract to store the signed electronic contract in the blockchain ledger.
[0064] In this way, the relevant business logic of contract signing is implemented based on the blockchain system, and the contract-related data is stored in the blockchain. Utilizing the characteristics of decentralization and consensus mechanism of the blockchain, the risks of data and business logic being tampered with and leaked during the process of electronic contract signing are avoided, and the security of electronic contract signing is improved. In addition, the symmetric key is used to encrypt the contract plaintext of the electronic contract to be signed, ensuring that only the contract signatories of the electronic contract to be signed can view and operate the electronic contract to be signed. Other users on the chain cannot see the plaintext of the contract and can only see the ciphertext, realizing the privacy protection of electronic contract data, improving the security of electronic contract signing, and encrypting the symmetric key sent to the contract signatories to ensure the security of the symmetric key and further improving the security of electronic contract signing. Description of the Drawings
[0065] Figure 1 It is a schematic diagram of the system architecture in the embodiment of the present application;
[0066] Figure 2 It is the first implementation flowchart of a blockchain-based electronic contract signing method provided in the embodiment of the present application;
[0067] Figure 3 It is the second implementation flowchart of a blockchain-based electronic contract signing method provided in the embodiment of the present application;
[0068] Figure 4 It is the third implementation flowchart of a blockchain-based electronic contract signing method provided in the embodiment of the present application;
[0069] Figure 5 It is a schematic diagram of the structure of a blockchain-based electronic contract signing device provided in the embodiment of the present application;
[0070] Figure 6 It is a schematic diagram of the structure of another blockchain-based electronic contract signing device provided in the embodiment of the present application;
[0071] Figure 7 It is a schematic diagram of the structure of an electronic device in the embodiment of the present application. Detailed Embodiments
[0072] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the following will clearly and completely describe the technical solutions of this application in conjunction with the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are some, rather than all, of the embodiments of the technical solutions of this application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments recorded in this application document without creative efforts fall within the scope of protection of the technical solutions of this application.
[0073] The following explains some terms in the embodiments of this application to facilitate the understanding of those skilled in the art.
[0074] (1) Blockchain: A distributed ledger technology in the field of information technology that achieves decentralization, immutability, and high transparency of information through methods such as cryptographic algorithms and distributed consensus mechanisms.
[0075] (2) Signing party public-private key pair: A key pair obtained through an asymmetric encryption algorithm. The private key is used for decryption and signature, and the public key is used for encryption and signature verification.
[0076] (3) Digital signature: An encrypted value generated by encrypting the original data with the private key of the contract signing party. The original data can be obtained by decrypting the encrypted value with the public key of the contract signing party.
[0077] (4) CA certificate: That is, a digital certificate, which is a digital identity used to verify and identify the identity of network service providers to ensure the security and integrity of data transmission. It uses public key encryption technology to verify the identity of the server through a pair of keys (public key and private key).
[0078] (5) Smart contract: A computer protocol designed to spread, verify, or execute contracts in an informatized manner. Smart contracts allow for trusted transactions without a third party, and these transactions are traceable and irreversible.
[0079] The following briefly introduces the design concept of the embodiments of this application:
[0080] With the development of communication and Internet technologies, electronic contracts have gradually replaced traditional paper contracts and are applied in various fields due to their advantages of high signing efficiency, low cost, easy storage management, and easy access.
[0081] However, existing electronic contract signing methods mainly rely on centralized electronic contract system platforms. Contract-related data is centrally stored in a centralized database, and the business logic of contract signing is implemented by a central server, which poses risks of data and business logic being tampered with and leaked.
[0082] In view of this, embodiments of the present application propose a method for signing an electronic contract based on a blockchain and related devices.
[0083] In the embodiments of the present application, first, the contract initiator encrypts the plaintext of the electronic contract to be signed using a symmetric key to obtain the ciphertext of the electronic contract to be signed; encrypts the symmetric key using the respective public keys of each contract signatory of the electronic contract to be signed to generate a key envelope list, and the key envelope list includes: the respective key envelopes of each contract signatory; calls a smart contract to store the ciphertext and the key envelope list in the blockchain ledger. In this way, the contract plaintext of the electronic contract to be signed is encrypted to ensure that only each contract signatory of the electronic contract to be signed can view and operate the electronic contract to be signed, and other users on the chain cannot see the contract plaintext and can only see the ciphertext, realizing the privacy protection of electronic contract data.
[0084] Then, the contract signatory calls the smart contract to obtain the ciphertext of the electronic contract to be signed and the key envelope of the contract signatory in the blockchain ledger; uses the private key of the contract signatory to decrypt the key envelope of the contract signatory to obtain the symmetric key; uses the symmetric key to decrypt the ciphertext to obtain the plaintext of the electronic contract to be signed; generates a digital signature for the plaintext to obtain the signed electronic contract of the contract signatory, and calls the smart contract to store the signed electronic contract in the blockchain ledger. Through the blockchain system, multi-party distributed signing and signing process control of the contract are realized, and the whole process is recorded and stored on the blockchain. Moreover, each contract signatory of the electronic contract to be signed can view and operate the electronic contract to be signed through the key envelope, and double decryption realizes the privacy protection of electronic contract data.
[0085] Finally, the contract initiator obtains the signed electronic contracts returned by each contract signatory in the blockchain ledger to obtain the target electronic contract.
[0086] In this way, the relevant business logic of contract signing is implemented based on the blockchain system, and the contract-related data of the signatory is stored in the blockchain. Utilizing the characteristics of decentralization and consensus mechanism of the blockchain, the risks of data and business logic being tampered with and leaked during the electronic contract signing process are avoided, and the security of electronic contract signing is improved. In addition, using a symmetric key to encrypt the contract plaintext of the electronic contract to be signed ensures that only each contract signatory of the electronic contract to be signed can view and operate the electronic contract to be signed, and other users on the chain cannot see the contract plaintext and can only see the ciphertext, realizing the privacy protection of electronic contract data and improving the security of electronic contract signing. Moreover, encrypting the symmetric key sent to the contract signatory ensures the security of the symmetric key and further improves the security of electronic contract signing.
[0087] The preferred embodiments of the present application will be described below in conjunction with the accompanying drawings of the specification. It should be understood that the preferred embodiments described herein are only for the purpose of illustrating and explaining the present application, and are not used to limit the present application. And without conflict, the embodiments of the present application and the features in the embodiments can be combined with each other.
[0088] Referring to Figure 1 As shown, it is a schematic diagram of the system architecture in the embodiment of the present application, including: a contract initiator 110, each contract signatory 120, and a blockchain 130. Electronic contract-related data is stored in the blockchain 130. For example, the ciphertext of the electronic contract to be signed and the list of key envelopes, as well as the signed electronic contracts returned by each contract signatory. The contract initiator 110 can draft the electronic contract to be signed and upload the ciphertext of the electronic contract to be signed to the blockchain, or obtain the signed electronic contract of the contract signatory from the blockchain; the contract signing end can obtain the electronic contract to be signed uploaded by the contract initiating end from the blockchain and sign the electronic contract to be signed.
[0089] It should be noted that Figure 2 The illustration shown is only an example. In fact, the number of the contract initiator 110 and the contract signatory 120 is not limited and is not specifically defined in the embodiment of the present application.
[0090] In the embodiment of the present application, a smart contract is written to implement the distributed contract business logic, and the smart contract is deployed to the blockchain.
[0091] Next, in combination with the above-described system architecture, the method for signing an electronic contract based on a blockchain provided by the exemplary embodiment of the present application will be described with reference to the accompanying drawings. It should be noted that the above system architecture is only shown for the convenience of understanding the spirit and principle of the present application, and the embodiments of the present application are not limited in this regard.
[0092] Referring to Figure 2 As shown, it is the first implementation flowchart of a method for signing an electronic contract based on a blockchain provided by the embodiment of the present application. Here, the contract initiator is taken as an example of the execution subject for introduction. The specific implementation process of the method is as follows:
[0093] Step 20: Encrypt the plaintext of the electronic contract to be signed using a symmetric key to obtain the ciphertext of the electronic contract to be signed.
[0094] Among them, the plaintext of the electronic contract to be signed is the original data of the electronic contract to be signed. The symmetric key can be an SM4 symmetric key, and the embodiment of the present application does not limit this.
[0095] In the embodiment of the present application, an SM4 symmetric key is generated, and the plaintext of the electronic contract to be signed is encrypted using the SM4 symmetric key to obtain the ciphertext of the electronic contract to be signed.
[0096] In this way, the plaintext of the electronic contract to be signed is visible to each contract signatory, while other users on the chain cannot see the plaintext of the contract and can only see the ciphertext, achieving privacy protection for contract data.
[0097] Step 21: Encrypt the symmetric key using the public key of each contract signatory of the electronic contract to be signed to generate a list of key envelopes.
[0098] Among them, the list of key envelopes includes: the respective key envelopes of each contract signatory. The public key of each contract signatory is the public key in the CA certificate of each contract signatory.
[0099] In the embodiment of the present application, for each contract signatory, the following operations are respectively performed: encrypt the SM4 symmetric key using the public key in the CA certificate of one signatory to obtain the key envelope of this signatory, and finally obtain the respective key envelopes of each contract signatory to generate a list of key envelopes.
[0100] In this way, encrypting the symmetric key to generate the key envelope of each contract signatory avoids the leakage of the symmetric key, improves confidentiality, and ensures that only the contract signatory can obtain the symmetric key.
[0101] In addition, it is worth noting that each of the obtained CA certificates of each contract signatory contains the serial number of the CA certificate, the identity information and public key information of the certificate owner, the validity period of the public key, and the unit that issues the CA certificate.
[0102] Step 22: Invoke the smart contract to store the ciphertext and the list of key envelopes in the blockchain ledger.
[0103] In the embodiment of the present application, invoke the contract initialization interface of the smart contract, submit the ciphertext and the list of key envelopes, so that the ciphertext and the list of key envelopes are stored in the blockchain ledger, and establish an association relationship between the ciphertext and the contract identifier of the electronic contract to be signed.
[0104] Optionally, in the embodiment of the present application, a signing whitelist for the electronic contract to be signed is further constructed based on the CA certificate serial numbers of each contract signatory, and the contract initialization interface of the smart contract is invoked to submit the signing whitelist, so that the signing whitelist is stored in the blockchain ledger, and an association relationship between the signing whitelist and the contract identifier of the electronic contract to be signed is established.
[0105] Among them, the signing whitelist is used to verify whether the caller is an authorized contract signatory.
[0106] In this way, precise access control is further realized, and the security of electronic contract signing is further improved.
[0107] Step 23: Obtain the signed electronic contracts respectively returned by each contract signatory in the blockchain ledger to obtain the target electronic contract.
[0108] Among them, the signed electronic contract is generated by the corresponding contract signatory decrypting the ciphertext obtained from the blockchain ledger based on its key envelope and then signing the corresponding digital signature on the plaintext.
[0109] Specifically, the signed electronic contract is generated by the corresponding contract signatory obtaining the symmetric key based on its key envelope, decrypting the ciphertext obtained from the blockchain ledger using the symmetric key, and then signing the corresponding digital signature on the plaintext. The digital signatures of each contract signatory are generated based on the private keys of the corresponding contract signatories.
[0110] In the embodiments of the present application, the signed electronic contracts respectively returned by each contract signatory in the blockchain ledger have passed the correctness verification.
[0111] Among them, the correctness verification is the verification performed by the blockchain nodes on the digital signatures of each contract signatory respectively based on the public keys of each contract signatory.
[0112] In addition, it is worth noting that the signed electronic contracts respectively returned by each contract signatory in the blockchain ledger can also meet: the order of the signed digital signatures conforms to the preset signing order.
[0113] In the embodiments of the present application, when all contract signatories have signed the contract, the entire contract signing process ends, and the signed electronic contracts respectively returned by each contract signatory in the blockchain ledger are obtained to obtain the target electronic contract.
[0114] Refer to Figure 3 As shown in the figure, it is the second implementation flowchart of an electronic contract signing method based on blockchain provided by the embodiments of the present application. Here, the contract signatory is taken as an example of the execution entity for introduction. The specific implementation process of this method is as follows:
[0115] Step 30: Invoke the smart contract to obtain the ciphertext of the electronic contract to be signed in the blockchain ledger and the key envelopes of the contract signatories.
[0116] In the embodiments of the present application, after the contract signatory receives the contract initialization event sent by the smart contract, it invokes the contract query interface of the smart contract. After the access control module of the smart contract (i.e., the blockchain node) verifies that the caller is an authorized contract signatory, it reads the ciphertext stored on the chain and the corresponding key envelopes and returns them to the caller.
[0117] Specifically, the contract signer sends a contract query request for the electronic contract to be signed to the blockchain node. When the blockchain node determines that the contract signer is an authorized contract signer, the blockchain node reads the ciphertext of the electronic contract to be signed and the key envelope of the contract signer stored on the chain and returns them to the contract signer. The contract signer receives the ciphertext of the electronic contract to be signed and the key envelope of the contract signer in the blockchain ledger returned by the blockchain node.
[0118] Among them, the contract query request includes the contract identifier of the electronic contract to be signed. Based on the contract identifier, the blockchain node queries and obtains the ciphertext of the electronic contract to be signed and the key envelope list.
[0119] In the embodiment of the present application, the contract signer being an authorized contract signer is determined based on the CA certificate serial number of the contract signer and the signing whitelist of the electronic contract to be signed. Among them, the signing whitelist consists of the CA certificate serial numbers of each contract signer of the electronic contract to be signed.
[0120] Specifically, the blockchain node reads the CA certificate of the contract signer from the on-chain transaction, parses out the CA certificate serial number, and checks whether the CA certificate serial number is on the signing whitelist. If it is, it determines that the contract signer is an authorized contract signer; otherwise, it determines that the contract signer is an unauthorized contract signer.
[0121] Step 31: Use the private key of the contract signer to decrypt the key envelope of the contract signer to obtain the symmetric key.
[0122] Among them, the private key of the contract signer is the private key in its CA certificate. The symmetric key can be an SM4 symmetric key, and the embodiment of the present application does not limit this.
[0123] In the embodiment of the present application, the contract signer uses its private key to decrypt the obtained key envelope of the contract signer to obtain the SM4 symmetric key.
[0124] Step 32: Use the symmetric key to decrypt the ciphertext to obtain the plaintext of the electronic contract to be signed.
[0125] Among them, the plaintext of the electronic contract to be signed is the original data of the electronic contract to be signed.
[0126] In the embodiment of the present application, the contract signer uses the obtained symmetric key to decrypt the ciphertext to obtain the plaintext of the electronic contract to be signed.
[0127] In this way, the contract signer can decrypt the plaintext of the electronic contract to be signed, enabling the contract signer to view the plaintext of the electronic contract to be signed, while other users on the chain cannot see the plaintext of the contract and can only see the ciphertext, realizing the privacy protection of contract data.
[0128] Step 33: Generate a digital signature for the plaintext to obtain the signed electronic contract of the contract signatory, and call the smart contract to store the signed electronic contract in the blockchain ledger.
[0129] In the embodiment of the present application, the contract signatory uses its private key to generate a digital signature for the plaintext of the electronic contract to be signed, obtains the signed electronic contract of the contract signatory, and calls the contract signing interface of the smart contract to store the signed electronic contract in the blockchain ledger.
[0130] Optionally, in the embodiment of the present application, a possible embodiment is provided for calling the smart contract to store the signed electronic contract in the blockchain ledger, and the following operations are specifically performed:
[0131] The contract signatory sends the signed electronic contract to the blockchain node, so that after the blockchain node verifies the digital signature of the contract signatory based on the public key of the contract signatory and passes the verification, the signed electronic contract is stored in the blockchain ledger. The blockchain node uses the public key of the contract signatory to verify the correctness of the digital signature of the contract signatory. After the verification passes, the signed electronic contract is stored in the blockchain ledger.
[0132] Optionally, when the blockchain node verifies the correctness of the digital signatures of each contract signatory, it also determines whether the order in which each contract signatory signs the digital signature conforms to the preset signing order.
[0133] In the embodiment of the present application, when each contract signatory digitally signs the plaintext, the signature time is attached, and the contract initiator obtains the order in which each contract signatory signs the digital signature according to the signature time; when all digital signatures pass the correctness verification and the contract signing order conforms to the preset signing order, the signed electronic contracts of each contract signatory are stored in the blockchain ledger.
[0134] Further, after the contract initiator associates and writes the contract identifier and the electronic contract to be signed into the blockchain ledger, the contract signatory can modify the contract. The following will describe the specific steps in detail:
[0135] In the embodiment of the present application, after the contract initiator associates and writes the contract identifier and the corresponding electronic contract to be signed into the blockchain ledger, each contract signatory calls the smart contract to query the electronic contract to be signed. When there are different opinions, specific terms are modified, and the modified electronic contract to be signed is written into the blockchain ledger. Then, the contract initiator calls the smart contract to obtain the modified electronic contract to be signed from the blockchain ledger.
[0136] Further, after modifying the electronic contract to be signed, each contract signatory also needs to approve the modified electronic contract to be signed. The following will describe the specific steps in detail:
[0137] In the embodiment of the present application, after the contract signatory associates and writes the modified electronic contract to be signed with the electronic contract identifier into the blockchain ledger, other contract signatories call the smart contract to query the modified electronic contract to be signed and conduct approval, and send the approval result to the contract initiator, or write the approval result into the blockchain ledger. Then, the contract initiator obtains the approval result from the blockchain ledger. In the approval result, the flag bit "1" indicates approval, and the flag bit "0" indicates disapproval. When the modified electronic contract to be signed passes the approval of each contract signatory respectively, the modified electronic contract to be signed is written into the blockchain ledger as the formal contract.
[0138] In this way, the blockchain detailedly records the initial drafted contract, the modified contract, and the formal contract after approval in the contract signing process, realizing the traceability and evidence preservation of contract signing. Since the blockchain has the characteristics of decentralization and consensus mechanism, the contract-related data stored in the blockchain is not easily tampered with, thus ensuring the security of electronic contract signing.
[0139] Refer to Figure 4 As shown, it is the third implementation flowchart of an electronic contract signing method based on blockchain provided by the embodiment of the present application. The specific implementation process of this method is as follows:
[0140] Step 40: The contract initiator uses the symmetric key to encrypt the plaintext of the electronic contract to be signed, obtains the ciphertext of the electronic contract to be signed, and uses the public keys of the respective contract signatories of the electronic contract to be signed to encrypt the symmetric key, generates a list of key envelopes, and constructs a signing whitelist of the electronic contract to be signed based on the CA certificate serial numbers of the respective contract signatories.
[0141] Step 41: The contract initiator sends a contract initialization request to the blockchain node, so that the blockchain node stores the ciphertext, the list of key envelopes, and the signing whitelist in the blockchain ledger.
[0142] Step 42: Any contract signatory among the respective contract signatories sends a contract query request for the electronic contract to be signed to the blockchain node.
[0143] Step 43: The blockchain node determines whether the contract signatory is an authorized contract signatory based on the CA certificate serial number of the contract signatory and the signing whitelist of the electronic contract to be signed.
[0144] Step 44: When the blockchain node determines that the contract signatory is an authorized contract signatory, it returns the ciphertext of the electronic contract to be signed in the blockchain ledger and the key envelope of the contract signatory to the contract signatory.
[0145] Step 45: The contract signatory uses its private key to decrypt the key envelope of the contract signatory, obtains the symmetric key, and uses the symmetric key to decrypt the ciphertext to obtain the plaintext of the electronic contract to be signed.
[0146] Step 46: The contract signatory uses its private key to generate a digital signature for the plaintext, obtaining the signed electronic contract of the contract signatory.
[0147] Step 47: The contract signatory sends the signed electronic contract to the blockchain node.
[0148] Step 48: The blockchain node verifies the digital signature of the contract signatory based on the public key of the contract signatory, and after the verification passes, stores the signed electronic contract in the blockchain ledger.
[0149] Step 49: The blockchain node sends the signed electronic contracts of each contract signatory in the blockchain ledger to the contract initiator, so that the contract initiator obtains the signed electronic contracts returned by each contract signatory in the blockchain ledger, obtaining the target electronic contract.
[0150] In addition, although the operations of the method of the present application are described in a specific order in the accompanying drawings, this does not require or imply that these operations must be performed in this specific order, or that all the shown operations must be performed to achieve the desired result. Additionally or alternatively, some steps may be omitted, multiple steps may be combined into one step for execution, and / or one step may be decomposed into multiple steps for execution.
[0151] Based on the same technical concept, refer to Figure 5 As shown, an electronic contract signing device based on blockchain is further provided in an embodiment of the present application, which is applied to a contract initiator. The device includes:
[0152] The first encryption module 501 is used to encrypt the plaintext of the electronic contract to be signed using the symmetric key, obtaining the ciphertext of the electronic contract to be signed;
[0153] The second encryption module 502 is used to encrypt the symmetric key using the public keys of each contract signatory of the electronic contract to be signed, generating a list of key envelopes, and the list of key envelopes includes: the key envelopes of each contract signatory;
[0154] The processing module 503 is used to call the smart contract to store the ciphertext and the list of key envelopes in the blockchain ledger;
[0155] The receiving module 504 is used to obtain the signed electronic contracts returned by each contract signatory in the blockchain ledger, obtaining the target electronic contract; the signed electronic contract is: after the corresponding contract signatory decrypts the ciphertext obtained from the blockchain ledger based on its key envelope and signs the corresponding digital signature for the plaintext.
[0156] In a possible embodiment, the processing module 503 is further configured to:
[0157] Based on the CA certificate serial numbers of each contract signatory, construct a signing whitelist for the electronic contract to be signed, where the signing whitelist is used to verify whether the caller is an authorized contract signatory;
[0158] Invoke a smart contract to store the signing whitelist in the blockchain ledger.
[0159] In a possible embodiment, the digital signature of each contract signatory is generated based on the private key of the corresponding contract signatory;
[0160] In a possible embodiment, the signed electronic contracts returned by each contract signatory in the blockchain ledger have passed the correctness verification;
[0161] The correctness verification is a verification of the digital signature of each contract signatory based on the public key of each contract signatory.
[0162] Based on the same technical concept, refer to Figure 6 As shown, the embodiment of the present application further provides another blockchain-based electronic contract signing device, which is applied to a contract signatory. The device includes:
[0163] An acquisition module 601, configured to invoke a smart contract to obtain the ciphertext of the electronic contract to be signed in the blockchain ledger and the key envelope of the contract signatory;
[0164] A first decryption module 602, configured to use the private key of the contract signatory to decrypt the key envelope of the contract signatory to obtain a symmetric key;
[0165] A second decryption module 603, configured to use the symmetric key to decrypt the ciphertext to obtain the plaintext of the electronic contract to be signed;
[0166] A signing module 604, configured to generate a digital signature for the plaintext to obtain the signed electronic contract of the contract signatory, and invoke a smart contract to store the signed electronic contract in the blockchain ledger.
[0167] In a possible embodiment, when invoking a smart contract to obtain the ciphertext of the electronic contract to be signed in the blockchain ledger and the key envelope of the contract signatory, the acquisition module 601 is further configured to:
[0168] Send a contract query request for the electronic contract to be signed to the blockchain node;
[0169] When the contract signatory is an authorized contract signatory, receive the ciphertext of the electronic contract to be signed in the blockchain ledger and the key envelope of the contract signatory returned by the blockchain node.
[0170] In a possible embodiment, the contract signatory being the authorized contract signatory is determined based on the CA certificate serial number of the contract signatory and the signing whitelist of the electronic contract to be signed, where the signing whitelist consists of the CA certificate serial numbers of the respective contract signatories of the electronic contract to be signed.
[0171] In a possible embodiment, when generating a digital signature for the plaintext, the signing module 604 is further configured to:
[0172] Generate a digital signature for the plaintext using the private key of the contract signatory.
[0173] In a possible embodiment, when invoking a smart contract to store the signed electronic contract in the blockchain ledger, the signing module 604 is further configured to:
[0174] Send the signed electronic contract to a blockchain node, so that after the blockchain node verifies the digital signature of the contract signatory based on the public key of the contract signatory, it stores the signed electronic contract in the blockchain ledger.
[0175] Based on the same technical concept, an embodiment of the present application further provides an electronic device, which can implement the method flow of blockchain-based electronic contract signing provided in the above embodiments of the present application.
[0176] In an embodiment, the electronic device can be a server, a terminal device, or other electronic devices.
[0177] Refer to Figure 7 As shown, the electronic device may include:
[0178] At least one processor 701 and a memory 702 connected to the at least one processor 701. In the embodiments of the present application, the specific connection medium between the processor 701 and the memory 702 is not limited. Figure 7 It is taken as an example that the processor 701 and the memory 702 are connected through a bus 700. The bus 700 is Figure 7 shown in thick lines. The connection manners between other components are only for illustrative purposes and are not to be construed as limiting. The bus 700 can be divided into an address bus, a data bus, a control bus, etc. For the sake of convenience of representation, Figure 7 only one thick line is used to represent it in the figure, but it does not mean that there is only one bus or one type of bus. Alternatively, the processor 701 can also be referred to as a controller, and there is no limitation on the name.
[0179] In an embodiment of the present application, the memory 702 stores instructions executable by at least one processor 701. By executing the instructions stored in the memory 702, the at least one processor 701 can execute a blockchain-based electronic contract signing method described above. The processor 701 can implement Figure 5 , 6 the functions of each module in the device shown.
[0180] Among them, the processor 701 is the control center of the device. It can connect various parts of the entire control device through various interfaces and lines. By running or executing the instructions stored in the memory 702 and calling the data stored in the memory 702, various functions of the device and process data, so as to monitor the device as a whole.
[0181] In a possible design, the processor 701 may include one or more processing units. The processor 701 may integrate an application processor and a modem processor. Among them, the application processor mainly processes the operating system, user interface, application programs, etc., and the modem processor mainly processes wireless communication. It can be understood that the above modem processor may not be integrated into the processor 701. In some embodiments, the processor 701 and the memory 702 can be implemented on the same chip. In some embodiments, they can also be separately implemented on independent chips.
[0182] The processor 701 can be a general-purpose processor, such as a CPU, a digital signal processor, an application-specific integrated circuit, a field programmable gate array, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, and can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor can be a microprocessor or any conventional processor, etc. The steps of a blockchain-based electronic contract signing method disclosed in combination with the embodiments of the present application can be directly embodied as being executed by a hardware processor, or executed by a combination of hardware and software modules in the processor.
[0183] The memory 702, as a non-volatile computer-readable storage medium, can be used to store non-volatile software programs, non-volatile computer-executable programs, and modules. The memory 702 can include at least one type of storage medium. For example, it can include flash memory, hard disk, multimedia card, card-type memory, random access memory (RAM), static random access memory (SRAM), programmable read-only memory (PROM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), magnetic memory, magnetic disk, optical disc, and so on. The memory 702 is any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 702 in the embodiments of the present application can also be a circuit or any other device capable of implementing a storage function, for storing program instructions and / or data.
[0184] By programming the design of the processor 701, the code corresponding to the method for signing an electronic contract based on blockchain introduced in the foregoing embodiments can be solidified into the chip, so that the chip can execute Figure 2 and 3 the steps of the method for signing an electronic contract based on blockchain shown in the embodiments. How to program the design of the processor 701 is a well-known technology to those skilled in the art and will not be elaborated here.
[0185] Based on the same inventive concept, the embodiments of the present application also provide a storage medium storing computer instructions, which, when run on a computer, cause the computer to execute a method for signing an electronic contract based on blockchain discussed above.
[0186] In some possible implementation manners, various aspects of the method for signing an electronic contract based on blockchain provided by the present application can also be implemented in the form of a program product, which includes program code. When the program product runs on a device, the program code is used to cause the control device to execute the steps in the method for signing an electronic contract based on blockchain according to various exemplary embodiments of the present application described above in this specification.
[0187] It should be noted that although several units or subunits of the device are mentioned in the above detailed description, this division is merely exemplary and not mandatory. In fact, according to the embodiments of the present application, the features and functions of two or more units described above can be embodied in one unit. Conversely, the features and functions of one unit described above can be further divided and embodied by multiple units.
[0188] In addition, although the operations of the method of the present application are described in a specific order in the drawings, this does not require or imply that these operations must be performed in that specific order, or that all the operations shown must be performed to achieve the desired result. Additionally or alternatively, some steps may be omitted, multiple steps may be combined into one step for execution, and / or one step may be decomposed into multiple steps for execution.
[0189] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0190] The present application is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram, and the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for implementing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0191] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device that implements the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0192] These computer program instructions may also be loaded onto a computer or other programmable data processing apparatus, so that a series of operation steps are executed on the computer or other programmable apparatus to produce a computer-implemented process, thereby providing instructions for implementing the steps specified in one process or a plurality of processes and / or blocks Figure 1 one process or a plurality of processes and / or blocks Figure 1 in one block or a plurality of blocks.
[0193] Obviously, those skilled in the art can make various changes and modifications to this application without departing from the spirit and scope of this application. Thus, if these modifications and variations of this application fall within the scope of the claims of this application and their equivalent technologies, this application is also intended to cover these changes and modifications.
Claims
1. An electronic contract signing method based on blockchain, characterized in that, Applied to the contract initiator, including: Encrypt the plaintext of the electronic contract to be signed using the symmetric key to obtain the ciphertext of the electronic contract to be signed; Encrypt the symmetric key using the public key of each contract signatory of the electronic contract to be signed to generate a list of key envelopes, where the list of key envelopes includes: the key envelopes of each contract signatory; Invoke a smart contract to store the ciphertext and the list of key envelopes in the blockchain ledger; Obtain the signed electronic contracts returned by each contract signatory in the blockchain ledger to obtain the target electronic contract; the signed electronic contract is: after the corresponding contract signatory decrypts the ciphertext obtained from the blockchain ledger based on its key envelope and generates a corresponding digital signature for the plaintext.
2. The method according to claim 1, wherein The method further includes: Construct a signing whitelist for the electronic contract to be signed based on the CA certificate serial numbers of each contract signatory, where the signing whitelist is used to verify whether the invoker is an authorized contract signatory; Invoke the smart contract to store the signing whitelist in the blockchain ledger.
3. The method according to claim 1, characterized in that, The digital signatures of each contract signatory are generated based on the private key of the corresponding contract signatory.
4. The method according to claim 1, wherein The signed electronic contracts returned by each contract signatory in the blockchain ledger have passed the correctness verification; The correctness verification is a verification of the digital signatures of each contract signatory based on the public keys of each contract signatory.
5. A blockchain-based electronic contract signing method, characterized in that, Applied to the contract signatory, including: Invoke a smart contract to obtain the ciphertext of the electronic contract to be signed in the blockchain ledger and the key envelope of the contract signatory; Use the private key of the contract signatory to decrypt the key envelope of the contract signatory to obtain the symmetric key; Use the symmetric key to decrypt the ciphertext to obtain the plaintext of the electronic contract to be signed; Generate a digital signature for the plaintext to obtain the signed electronic contract of the contract signatory, and invoke the smart contract to store the signed electronic contract in the blockchain ledger.
6. The method according to claim 5, wherein The invoking a smart contract to obtain the ciphertext of the electronic contract to be signed in the blockchain ledger and the key envelope of the contract signatory includes: Send a contract query request for the electronic contract to be signed to the blockchain node; When the contract signatory is an authorized contract signatory, receive the ciphertext of the electronic contract to be signed in the blockchain ledger and the key envelope of the contract signatory returned by the blockchain node.
7. The method according to claim 6, characterized in that, The contract signatory is an authorized contract signatory is determined based on the CA certificate serial number of the contract signatory and the signing whitelist of the electronic contract to be signed, where the signing whitelist is composed of the CA certificate serial numbers of each contract signatory of the electronic contract to be signed.
8. The method according to claim 5, characterized in that, The generating a digital signature for the plaintext includes: Use the private key of the contract signatory to generate a digital signature for the plaintext.
9. The method according to claim 5, characterized in that, The invoking the smart contract to store the signed electronic contract in the blockchain ledger includes: Send the signed electronic contract to the blockchain node, so that after the blockchain node verifies the digital signature of the contract signer based on the public key of the contract signer, store the signed electronic contract in the blockchain ledger.
10. An electronic device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the computer program, the method described in any one of claims 1-9 is implemented.
11. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, the steps of the method described in any one of claims 1-9 are implemented.
Citation Information
Cited By
Cross-node electronic contract signing method and system based on distributed trust framework
CN120811781A
Cross-node electronic contract signing method and system based on distributed trust framework
CN120811781B