Reliable electronic signature system and method for matching business process

Through the combination of configuration modules, API interface SDK and electronic evidence extraction modules, the normalization and standardization issues of electronic signatures in business systems are solved, a complete electronic evidence chain is formed, and the reliability of electronic signatures and the integrity of legal evidence are improved.

CN120785541AActive Publication Date: 2025-10-14SICHUAN DIGITAL CERTIFICATE AUTHENTICATION MANAGEMENT CENT CO LTD

Patent Information

Application Number
CN202511292085.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-11
Publication Date
2025-10-14
Estimated Expiration
2045-09-11

AI Technical Summary

Technical Problem

Existing business systems lack standardized and normative methods when integrating electronic signature technology, resulting in non-standard key processes such as pre-signature notification and signature intention authentication, affecting the reliability and effectiveness of electronic signatures and failing to provide a complete and credible chain of evidence.

Method used

Provides a reliable electronic signature system that matches business processes, including a configuration module, an API interface SDK, and an electronic evidence extraction module. Through automatic storage of pre-signature notification, signature intention authentication, and post-signature notification links, it forms a complete electronic evidence chain that is adaptable to various business application environments.

Benefits of technology

It has achieved the normalization and standardization of the electronic signature process, ensured the collection and preservation of evidence of pre-signature notification, signature intention authentication and post-signature notification, improved the reliability of electronic signatures and the integrity of legal evidence, and avoided application defects and legal risks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120785541A_ABST
    Figure CN120785541A_ABST
Patent Text Reader

Abstract

The invention discloses a reliable electronic signature system and method for matching a business process, and relates to the technical field of information security, and the system comprises a configuration module which is used for configuring business processes, links and signature control information which need to be signed by an application system; the API interface SDK is used for providing electronic signature interfaces in different environments, obtaining signature configuration information through the SDK, and meanwhile, providing data for subsequent electronic evidence extraction through notification before signature, signature willingness authentication and automatic storage of electronic evidence after signature; the API interface background module is used for providing a support interface for the API interface and safely storing signature control parameters and electronic evidence data; providing a configuration data storage service interface for the configuration module; an electronic evidence query service interface is provided for the electronic evidence extraction module; the electronic evidence extraction module is used for analyzing and assembling to form comprehensive electronic evidence according to the stored electronic evidence; according to the invention, reliable electronic signature service can be provided for an application system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and in particular to a reliable electronic signature system and method for matching business processes. Background Art

[0002] Electronic signature technology is increasingly being used. It can confirm the signer's acceptance of the signed information, facilitating identity authentication, data tamper prevention, and repudiation prevention. However, electronic signature technology is a low-level security technology that requires standardized integration with business systems to ensure security throughout the entire business process. Currently, because various business systems integrate electronic signature technology as a low-level technical component, there is no standardized implementation method for key aspects of electronic signature technology, such as pre-signing risk notification and signature intent verification, which are critical to its reliability and effectiveness.

[0003] It can be seen that when business systems use electronic signature technology, they integrate electronic signature technology as a technical component, resulting in key processes such as notification before electronic signature and electronic intention authentication. Different business systems do not have standardized and normative methods to follow, which leads to non-standard and irregular situations when integrating electronic signature technology into application systems, resulting in flaws in the application of electronic signature technology (such as: failure to fully inform the electronic signatory of the signature content, resulting in the electronic signatory's subsequent denial), resulting in the final signature result being unreliable at the legal level when a dispute arises; at the same time, the demand for post-event proof is becoming increasingly strong in areas with high dispute incidence, and the awareness of users to initiate rights protection from different dimensions after their interests are damaged is becoming increasingly strong. Therefore, the component-based integration of electronic signature technology cannot provide business systems with a complete and reliable electronic evidence chain. Summary of the Invention

[0004] The present invention mainly solves the problems of electronic signature notification / risk warning, electronic signature intention authentication, electronic signature result storage and evidence extraction, and flexible matching of electronic signature services to different business processes in the electronic signature process of the business system. The purpose of the present invention is to provide a reliable electronic signature system and method that matches the business process. The present invention can configure signature control information according to the process links of electronic signature required by different business processes of the application system, and provide an API interface SDK that adapts to a variety of business application environments to provide reliable electronic signature services for the application system.

[0005] To achieve the above-mentioned purpose, the technical solution adopted by the present invention is: a reliable electronic signature system matching business processes, including: a configuration module, an API interface SDK, an API interface background module and an electronic evidence extraction module; wherein:

[0006] Configuration module, used to configure the business processes, links, and signature control information that require signatures in the application system;

[0007] API interface SDK is used to provide electronic signature interfaces in different environments. Signature configuration information is obtained through the SDK, thereby realizing reliable electronic signatures in corresponding business links. At the same time, through pre-signature notification, signature intention verification, and post-signature notification, the automatic storage of electronic evidence provides data for subsequent electronic evidence extraction;

[0008] The API interface backend module is used to provide support interfaces for the API interface and secure storage of signature control parameters and electronic evidence data. The support interfaces include application system access authentication, control parameter query services, and electronic evidence storage; it provides a configuration data storage service interface for the configuration module; and it provides an electronic evidence query service interface for the electronic evidence extraction module.

[0009] The electronic evidence extraction module is used to analyze and assemble the stored electronic evidence to form comprehensive electronic evidence.

[0010] The present invention also provides a reliable electronic signature method for matching business processes, which is implemented using the reliable electronic signature system for matching business processes as described above. The method includes the following steps:

[0011] Step 1: Configure the application access signature control parameter values, configure the specific business links that require electronic signatures according to different business processes in the application system, and configure the signature configuration information for the specific business links;

[0012] Step 2: The business system calls the electronic signature interface through the API interface SDK. The API interface SDK notifies the user before signing based on the signing configuration information in the corresponding business link, authenticates the signature intention based on the signature intention expression authentication method, notifies the user after the signature is completed based on the configuration, and stores the electronic signature behavior evidence. This process is repeated until the process is completed.

[0013] Step 3: When electronic evidence is needed, extract the electronic evidence based on the business process identifier and assemble the electronic evidence.

[0014] As a further improvement of the present invention, the step 1 specifically includes the following steps:

[0015] Step 1.1: Allocate application identification and application key to the access application system as the basis for application access identity authentication and security control mechanism;

[0016] Step 1.2: Create a business process for the application that requires electronic signature, including the business process code and name, as the basis for subsequent evidence extraction;

[0017] Step 1.3: Configure the process links that require electronic signatures for the corresponding business processes;

[0018] Step 1.4: Configure pre-signature notification, signature intention verification method, and post-signature notification control information for process links that require electronic signatures.

[0019] As a further improvement of the present invention, in step 1.4, the signature intention authentication method is PIN code authentication, face scanning authentication or SMS authentication.

[0020] As a further improvement of the present invention, the above 2 specifically includes the following steps:

[0021] Step 2.1: The API interface SDK determines whether the authentication of the application system is passed. If it is passed, it proceeds to step 2.2. If it is not passed, it returns to the application system and ends.

[0022] Step 2.2: The signer reviews the pre-signing notification content in the user interface and confirms or cancels the signature. The API interface SDK decides whether to proceed based on the user's specific interface operation results. If the user cancels the signature, the signing process ends and the cancellation result is returned to the application system. If the user confirms the signature, the process proceeds to step 2.3. At the same time, the API interface SDK records relevant log records. The API interface SDK calculates the hash value of the pre-signing notification content, the relevant pre-signing notification process log, and the user's operation result log, and records it as hash_bn.

[0023] Step 2.3: The API interface SDK initiates the signer identity authentication according to the signature intention authentication method, activates the corresponding authentication component based on the specific environment of the signer's client to complete the signer identity authentication, and logs the entire signer identity authentication process as evidence; the signer completes the signer identity authentication according to the authentication process in the signature intention authentication method, and the API interface SDK determines the signer identity authentication result. If the authentication fails, it returns the specific error information of the business system and ends the signing process; if the authentication passes, it proceeds to step 2.4; at the same time, the API interface SDK records the relevant log records of the signer identity authentication process and the relevant identity authentication evidence information, and calculates the hash value, recorded as hash_au;

[0024] Step 2.4: The signer checks the signature and informs the user interface. The API interface SDK records the relevant signature and notification evidence and calculates the hash value of the signature and notification evidence, recorded as hash_pn. The API interface backend stores the signature evidence information and, when storing the signature evidence, timestamps the signature evidence with the server's digital certificate.

[0025] As a further improvement of the present invention, the above 2.1 specifically includes the following steps:

[0026] Step 2.1.1: The signatory performs an electronic signature in the application system. In this case, the signatory is operating a business process in a business process instance of the application system.

[0027] Step 2.1.2: The application system prepares the signature text and related signature control parameter values. The specific signature control parameter value list includes: application ID, random number, timestamp, process unique ID, process instance unique ID, process instance code, process instance name, link unique ID, signature text, pre-signature notification content parameter value, post-signature notification content parameter value, and calculates the signature value of the signature control parameter value.

[0028] Step 2.1.3: The application system calls the signature interface of the API interface to perform electronic signature;

[0029] Step 2.1.4: The API SDK calculates the hash value hash_arg of the SM3 algorithm, which includes the call parameters, random number, and timestamp. The API backend verifies the correctness of the application system identity and the call parameters.

[0030] Step 2.1.5. The API interface backend finds the corresponding application key based on the application system's application ID and decrypts the signature value of the parameter value calculated by the application system. The decryption result is the parameter hash value hash_arg', which is compared with the parameter hash value hash_arg. If they are equal, the verification passes; otherwise, the verification fails.

[0031] As a further improvement of the present invention, the step 2.2 specifically includes the following steps:

[0032] Step 2.2.2, the API interface SDK calls the API interface backend service to obtain signature control parameters based on the application ID, process unique ID, and link unique ID;

[0033] Step 2.2.3. The API interface backend queries the configuration information stored in the signature control parameter data structure based on the application ID, process unique ID, and link unique ID, and queries the signature control parameter information for pre-signature notification, signature intention authentication method, and post-signature notification, and returns it to the API interface SDK;

[0034] Step 2.2.4, the API interface SDK determines whether there is pre-signature notification information. If so, it generates a pre-signature notification user interface based on the notification template, customized UI, and pre-signature notification content parameter values, and displays it to the signer.

[0035] As a further improvement of the present invention, the step 2.4 specifically includes the following steps:

[0036] Step 2.4.1. The API SDK calculates the hash value of the original signature, which is recorded as hash_or.

[0037] Step 2.4.2: The API SDK determines whether there is post-signature notification information. If so, it generates a post-signature notification user interface based on the notification template, customized UI, and post-signature notification content parameter values, and displays it to the signer. The API SDK also records relevant log records.

[0038] Step 2.4.3. The API interface SDK uses the user's digital certificate private key to sign hash_bn, hash_au, hash_pn, and hash_or, respectively, to obtain the pre-signature evidence signature value, the signature value of the identity authentication process during signing, the post-signature evidence signature value, and the signature value of the original text. At this time, the API interface SDK uses the specific signer's digital certificate private key to sign according to the specific environment of the signer's client.

[0039] Step 2.4.4: The application system receives the original signature value and saves it;

[0040] Step 2.4.5. The API interface backend stores signature evidence information, including evidence information of the content notified before signing and the signature value of the evidence notified before signing, evidence information of the signatory's identity authentication during signing and the signature value, evidence information of the content notified after signing and the signature value of the evidence notified after signing, and the signature value of the original signature. At the same time, when storing the signature evidence, the digital certificate of the server is stamped with a timestamp to prove the storage time of the evidence, and the stamped timestamp is stamped for the entire signature evidence record.

[0041] As a further improvement of the present invention, the step 3 specifically includes the following steps:

[0042] Step 3.1: The API interface backend extracts the corresponding signature evidence list of all process nodes under a specific process instance through the application ID, process unique ID, and process instance unique ID; the evidence list is sorted in chronological order based on the timestamp;

[0043] Step 3.2: The API interface backend parses the query results and retrieves the corresponding information based on the signature control parameter data structure.

[0044] Step 3.3: The API interface backend parses each piece of data, including pre-signature notification evidence, signature authentication evidence, and post-signature notification evidence, and returns the final result.

[0045] The present invention divides an electronic signature behavior at a process node in the business process into three important links: "pre-signature notification, signature intention authentication, and post-signature notification", and treats the three links as a complete transaction of a signature behavior, perfectly mapping the "before, during, and after" electronic signature business management and control mechanism, and preserving the relevant electronic signature evidence of "pre-signature notification, signature intention authentication, and post-signature notification", ultimately forming a complete signature behavior evidence chain of "before, during, and after", avoiding related legal risks.

[0046] The present invention uses signature control parameters to match the links that require electronic signatures in different business processes (procedures) of the business system, and can configure pre-signature notification, signature intention authentication method, and post-signature notification for each signature link in the process to refine a signature behavior, and achieve the goals of signatory-friendly interaction and flexible configuration of signature process control through parameter configuration.

[0047] The present invention provides a unified one-time signature behavior calling interface service for the application system through the API interface SDK, and in the API interface SDK, it can generate a notification user interface adapted to the signer's client environment according to the signature control parameters of the electronic signature link, and generate notification content information adapted to the needs of the application system, which can effectively avoid the related problems of unclear notification content, inconsistent notification interface, inability to record the signer's confirmation behavior of the notification content, and inability to collect and preserve evidence of the signer's confirmation behavior of the notification content.

[0048] The present invention provides the application system with a signature intention authentication method that adapts to the needs of a single signature behavior through the API interface SDK. It can flexibly match the signature intention authentication method adopted by the risk level of a single signature behavior, and can perform signer client environment detection on this basis to adopt a more flexible signature intention authentication method; at the same time, the entire signature intention authentication process of the signer is recorded to form signature intention authentication behavior evidence, effectively solving the problem that the signer's signature intention authentication behavior evidence cannot be collected and preserved.

[0049] The present invention can effectively collect the signature behavior data of the signature link of an overall business process to form electronic evidence of signature behavior, and divide a signature behavior evidence into signature behavior evidence of "notification before signing, authentication of signature intention, and notification after signing"; and record the electronic signature behavior evidence in the actual process nodes passed by a specific process instance of an overall business process, perfectly matching the business process processing process; at the same time, the present invention can not only extract a specific signature behavior evidence, but also extract the electronic evidence of the entire business processing process, forming a complete evidence chain of the business processing process.

[0050] The beneficial effects of the present invention are:

[0051] The present invention solves the problem that in the process of using electronic signatures in an application system, it is impossible to flexibly configure and match the electronic signature transaction process of pre-signature notification, signature intention authentication, and post-signature notification of a specific business process link in the process of electronic signature, and solves the problem of evidence collection and extraction of pre-signature notification, signature intention authentication, and post-signature notification in the process of electronic signature. Therefore, the application of the method of the present invention can provide a more reliable electronic signature process for the application system and the signatory, avoid the non-standard and non-standard situation when the application system integrates the electronic signature technology, and avoid defects in the application of the electronic signature technology. BRIEF DESCRIPTION OF THE DRAWINGS

[0052] Figure 1 This is a schematic diagram of a signature system according to an embodiment of the present invention;

[0053] Figure 2 This is a flowchart of a signature method according to an embodiment of the present invention;

[0054] Figure 3 A flowchart for configuring application access signature control parameters in an embodiment of the present invention;

[0055] Figure 4 This is a schematic diagram of the signature control parameter data structure in an embodiment of the present invention;

[0056] Figure 5-1 This is the first flow chart of the business system implementing electronic signature through API interface call in an embodiment of the present invention;

[0057] Figure 5-2 This is the second flow chart of the business system implementing electronic signature through API interface call in an embodiment of the present invention;

[0058] Figure 6 This is a schematic diagram of the signature evidence storage data structure in an embodiment of the present invention;

[0059] Figure 7 This is a flowchart of electronic evidence extraction in an embodiment of the present invention. DETAILED DESCRIPTION

[0060] The embodiments of the present invention are described in detail below with reference to the accompanying drawings.

[0061] Example:

[0062] like Figure 1As shown, a reliable electronic signature system 100 for matching business processes includes a configuration module 101, an API interface SDK 102, an API interface backend module 103, and an electronic evidence extraction module 104. The configuration module 101 configures the business processes, links, signature control, and other information required for signatures in the application system. The API interface SDK 102 provides electronic signature interfaces for different environments, obtains signature configuration information through the SDK, and thus realizes reliable electronic signatures in corresponding business links. At the same time, through pre-signature notification, signature intention authentication, and post-signature notification, the system automatically stores electronic evidence, providing data for subsequent electronic evidence extraction. The API interface backend module 103 is used to provide a supporting interface for the API interface and secure storage of signature control parameters and electronic evidence data. The supporting interface includes application system access authentication, control parameter query service, and electronic evidence storage. It provides a configuration data storage service interface for the configuration module and an electronic evidence query service interface for the electronic evidence extraction module. The electronic evidence extraction module 104 analyzes and assembles the stored electronic evidence to form comprehensive electronic evidence.

[0063] like Figure 2 As shown, this embodiment also provides a reliable electronic signature method matching a business process, including the following steps:

[0064] S10: Configure application access control parameters, configure specific business links that require electronic signatures according to different business processes in the application system, and configure signature configuration information for specific business links.

[0065] S20: The business system calls the electronic signature interface through the API interface SDK. The API interface SDK notifies the corresponding business link before signing according to the signing configuration information, performs signature authentication according to the signature intention expression authentication method, notifies according to the configuration after the signature is completed, and stores the electronic signature behavior evidence. Repeat this process until a process is completed.

[0066] S30: When electronic evidence is needed, extract the electronic evidence based on the business process identifier and assemble the electronic evidence.

[0067] The signature method of this embodiment is further described below:

[0068] S10 Configure application access signature control parameters: For the process of configuring application access signature control parameters, see Figure 3 , the signature control parameter data structure that needs to be configured is shown in Figure 4 , Figure 3 The process is described as follows:

[0069] S1001: Allocate (app_id, app_secret) to apps (accessing the application system) as the basis for application access identity authentication and security control mechanism.

[0070] S1002: Create a process (business process) that requires electronic signature for the application, including (process_code, process_name) as an important basis for subsequent evidence extraction.

[0071] S1003: Configure nodes (process links) that require electronic signatures for the corresponding business processes.

[0072] S1004: Configure before_sign (notification before signing) control information for nodes (process links) that need to use electronic signatures.

[0073] S1005: Configure sign_auth (signature intention authentication method) control information for nodes (process links) that need to use electronic signatures.

[0074] S1006: Configure post_sign (notify after signing) for nodes (process links) that require electronic signatures.

[0075] Figure 4 This is the signature control parameter data structure, detailed description is as follows:

[0076] apps (access application system) stores all access application systems. app_id (application identifier) ​​is the unique identifier of the access application system. app_secret (application key) is important information for verifying user identity and ensuring security when the access application system makes API interface calls. The two are combined to verify the identity of the access application system.

[0077] Process (business process) and nodes (process links) are used to store the business processes within the application system and the process links that require electronic signatures under the corresponding processes;

[0078] before_sign (pre-signature notice) stores pre-signature notice control information required for the electronic signature process. if_notice (yes / no notice) indicates whether notice information will appear before signing. notice_template (notice template) uses a text template to replace parameters when making a notice, ultimately forming the notice content. custom_ui (customized UI) can store corresponding customized UI information according to the needs of the application system.

[0079] sign_auth (signature intention authentication method) stores the identity authentication method required for the corresponding process link when performing electronic signatures, such as PIN code authentication, face scan authentication, SMS authentication, etc. This information controls which identity authentication method the API interface uses to authenticate the signer's identity when performing electronic signatures;

[0080] post_sign (notify after signing) is similar to before_sign (notify before signing), so I will not go into details here.

[0081] The S20 business system implements electronic signatures through API interface calls: when the signer operates within the application system and performs electronic signatures at a certain stage of a specific business process, the business system calls the electronic signature interface of the API interface SDK to implement electronic signatures. For the specific process, see Figure 5-1 、 Figure 5-2 The data structure of the relevant electronic evidence stored when an electronic signature is successfully completed is shown in Figure 6 , the process is described as follows:

[0082] S2001: The signatory performs electronic signature in the application system operation. At this time, the signatory operates a business link of a business process instance of the application system.

[0083] S2002: The application system prepares the signature text and related signature control parameter values. The specific signature control parameter value list includes: application identifier (app_id), random number (nonce), ts (timestamp), process unique identifier (process_id), process instance unique identifier (process_instance), process instance code (instance_code), process instance name (instance_name), link unique identifier (node_id), signature text (contents), parameter value of content notified before signing (before_args), parameter value of content notified after signing (post_args), and signature value of the above parameter values ​​calculated by HMAC_SM3 algorithm (the specific signing process can be implemented through API interface SDK).

[0084] S2003: The application system calls the signature interface of the API interface to perform electronic signature.

[0085] S2004: The API interface SDK calculates the parameter hash value hash_arg of the SM3 algorithm of the calling parameters, random number, and timestamp, and verifies the correctness of the application system identity and the calling parameters through the API interface background.

[0086] S2005: The API interface backend finds the corresponding application key (app_secret) based on the app_id of the application system, decrypts the signature value of the parameter value calculated by the application system, and the decryption result is the parameter hash value hash_arg', which is compared with the parameter hash value hash_arg. If they are equal, the verification passes, otherwise the verification fails.

[0087] S2006: The API interface SDK determines whether the identity authentication of the application system is passed. If it is passed, it proceeds to S2007; if not, it returns to the application system and ends.

[0088] S2007: The API interface SDK calls the API interface background service to obtain signature control parameters based on the application identifier (app_id), process unique identifier (process_id), and link unique identifier (node_id).

[0089] S2008: The API interface backend queries the signature control parameter data structure based on app_id, process_id, and node_id ( Figure 4 ) to query the configuration information stored in before_sign (notification before signing), sign_auth (signature intention authentication method), and post_sign (notification after signing) signature control parameter information and return to the API interface SDK.

[0090] S2009: When the API interface SDK determines that "if_notice (yes / no notification)" of before_sign is "yes", it generates the before-sign notification user interface based on notice_template (notice template), custom_ui (customized UI), and the before-sign notification content parameter value (before_args), and displays it to the signer. The API interface SDK records relevant log records during this process.

[0091] S2010: The signer checks the notification content in the pre-signing notification user interface and confirms / cancels the signature.

[0092] S2011: The API interface SDK decides whether to proceed with subsequent processing based on the user's specific interface operation results. When the user "cancels", the signing process ends and the "user cancels" result is returned to the application system; when the user "confirms", it enters S2012; during this process, the API interface SDK records relevant log records.

[0093] S2012: The API interface SDK calculates the hash value (hash_bn) of the pre-signature notification content, the relevant pre-signature notification process log, and the user's operation result log.

[0094] S2013: The API interface SDK starts the signer identity authentication according to sign_auth (signature intention authentication method). This process will enable the corresponding authentication components based on the specific environment of the signer client to complete the signer identity authentication. The entire signer identity authentication process has corresponding log records as evidence.

[0095] S2014: The signer completes the signer identity authentication according to the authentication process in the signature intention authentication method.

[0096] S2015: The API interface SDK determines the signer's identity authentication result. If the authentication fails, it returns a specific error message to the business system and ends the signing process; if the authentication passes, it enters S2016.

[0097] S2016: The API interface SDK records the log information related to the signer's identity authentication process and related identity authentication evidence information, and calculates the hash value (hash_au) of the above information.

[0098] S2017: The API interface SDK calculates the hash value (hash_or) of the signature original text (contents).

[0099] S2018: When the API SDK determines that "if_notice (yes / no notification)" of post_sign is "yes", it generates the post-signature notification user interface based on notice_template (notice template), custom_ui (customized UI), and the post-signature notification content parameter value (post_args), and displays it to the signer. The API interface records relevant log records during this process.

[0100] S2019: The signer checks the signature and informs the user interface.

[0101] S2020: The API interface SDK records the relevant signature and notification evidence and calculates the hash value (hash_pn) of the signature and notification evidence.

[0102] S2021: The API interface SDK calls the user's digital certificate private key to sign hash_bn, hash_au, hash_pn, and hash_or respectively to obtain the evidence signature value (sign_bn) notified before signing, the evidence signature value of the identity authentication process during signing (sign_au), the evidence signature value (sign_pn) notified after signing, and the signature value of the original text (sign_or); at this time, the API interface SDK calls the specific signer's digital certificate private key to sign according to the specific environment of the signer's client.

[0103] S2022: The application system receives the signature value (sign_or) of the original signature and saves it.

[0104] S2023: The API interface backend stores signature evidence information, including evidence information of the content notified before signing and the signature value of the evidence notified before signing (sign_bn), evidence information of the signatory's identity authentication during signing and the signature value of the evidence notified after signing (sign_au), evidence information of the content notified after signing and the signature value of the evidence notified after signing (sign_pn), and the signature value of the original signature (sign_or). At the same time, when storing signature evidence, a timestamp is added through the digital certificate of the server to prove the storage time of the evidence, and the timestamp is added to the entire signature evidence record.

[0105] During the entire signing process, the API interface SDK treats a signing activity as a transaction.

[0106] The signature evidence storage data structure is detailed as follows:

[0107] Sign_evidence (signature evidence) stores all signature evidence information, including: app_id (application), which represents the specific application system where the evidence is stored; process_id (process), which represents the business process for which the evidence is stored; process_instance (process instance identifier), which stores the identifier of the specific process instance, used to distinguish different process instances under the same process_id; instance_code (process instance code), which is the attribute value that uniquely corresponds to the process instance process_instance, for easy data query; instance_name (process instance name), which is the attribute value that uniquely corresponds to the process instance process_instance, for easy data query; node_id (node), which is used to distinguish nodes with the same A process link under a process_id; sign_subject (signer), the user stores the specific information of the signer, which is usually the signer's digital certificate when a digital certificate signature is used; sign (signature value), is the signature value of the original signature; timestamp (timestamp), is used to store the time when the evidence is stored, and is tamper-proof through timestamp technology; before_evidence (evidence before signing), is used to store the evidence information notified before signing and the signature value of the corresponding evidence information; auth_evidence (signature authentication evidence), is used to store the identity authentication evidence information when the signer signs and the signature value of the corresponding evidence information; post_evidence (evidence after signing), is used to store the evidence information notified after signing and the signature value of the corresponding evidence information.

[0108] S30 Electronic evidence extraction process: When it is necessary to extract signature electronic evidence, the corresponding electronic evidence can be extracted through the electronic evidence extraction process. For the specific process, see Figure 7 , described as follows:

[0109] S3001: The API interface backend can extract the corresponding signature evidence list of all process nodes under a specific process instance (process_instance) through app_id, process_id, and process_instance; the evidence list is sorted in chronological order according to the timestamp.

[0110] S3002: The API interface backend parses the query results and queries the corresponding information (such as process_code, process_name, instance_code, instance_name, node_code, node_name, etc.) according to the "signature control parameter data structure".

[0111] S3003: The API interface backend parses before_evidence (evidence before signing), auth_evidence (evidence of signature authentication), and post_evidence (evidence after signing) for each piece of data and returns the final result.

[0112] The above-described embodiments merely represent specific implementations of the present invention. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present invention. It should be noted that a person skilled in the art would be able to make numerous variations and improvements without departing from the spirit of the present invention, and all such variations and improvements fall within the scope of protection of the present invention.

Claims

1. A reliable electronic signature system that matches business processes, characterized by: include: Configuration module, API interface SDK, API interface background module and electronic evidence extraction module; among which: Configuration module, used to configure the business processes, links, and signature control information that require signatures in the application system; API interface SDK is used to provide electronic signature interfaces in different environments. Signature configuration information is obtained through the SDK, thereby realizing reliable electronic signatures in corresponding business links. At the same time, through pre-signature notification, signature intention verification, and post-signature notification, the automatic storage of electronic evidence provides data for subsequent electronic evidence extraction; The API interface backend module is used to provide support interfaces for the API interface and secure storage of signature control parameters and electronic evidence data. The support interfaces include application system access authentication, control parameter query services, and electronic evidence storage; it provides a configuration data storage service interface for the configuration module; and it provides an electronic evidence query service interface for the electronic evidence extraction module. The electronic evidence extraction module is used to analyze and assemble the stored electronic evidence to form comprehensive electronic evidence.

2. A reliable electronic signature method matching business processes, characterized in that: The reliable electronic signature system for matching business processes according to claim 1 is used for implementation, wherein the method comprises the following steps: Step 1: Configure the application access signature control parameter values, configure the specific business links that require electronic signatures according to different business processes in the application system, and configure the signature configuration information for the specific business links; Step 2: The business system calls the electronic signature interface through the API interface SDK. The API interface SDK notifies the user before signing based on the signing configuration information in the corresponding business link, authenticates the signature intention based on the signature intention expression authentication method, notifies the user after the signature is completed based on the configuration, and stores the electronic signature behavior evidence. This process is repeated until the process is completed. Step 3: When electronic evidence is needed, extract the electronic evidence based on the business process identifier and assemble the electronic evidence.

3. The reliable electronic signature method for matching business processes according to claim 2 is characterized in that: The step 1 specifically includes the following steps: Step 1.1: Allocate application identification and application key to the access application system as the basis for application access identity authentication and security control mechanism; Step 1.2: Create a business process for the application that requires electronic signature, including the business process code and name, as the basis for subsequent evidence extraction; Step 1.3: Configure the process links that require electronic signatures for the corresponding business processes; Step 1.4: Configure pre-signature notification, signature intention verification method, and post-signature notification control information for process links that require electronic signatures.

4. The reliable electronic signature method for matching business processes according to claim 3 is characterized in that: In step 1.4, the signature intention authentication method is PIN code authentication, face scanning authentication or SMS authentication.

5. The reliable electronic signature method for matching business processes according to claim 2 is characterized in that: The step 2 specifically includes the following steps: Step 2.1: The API interface SDK determines whether the authentication of the application system is passed. If it is passed, it proceeds to step 2.

2. If it is not passed, it returns to the application system and ends. Step 2.2: The signer reviews the pre-signing notification content in the user interface and confirms or cancels the signature. The API interface SDK decides whether to proceed based on the user's specific interface operation results. If the user cancels the signature, the signing process ends and the cancellation result is returned to the application system. If the user confirms the signature, the process proceeds to step 2.

3. At the same time, the API interface SDK records relevant log records. The API interface SDK calculates the hash value of the pre-signing notification content, the relevant pre-signing notification process log, and the user's operation result log, and records it as hash_bn. Step 2.3: The API interface SDK initiates the signer identity authentication according to the signature intention authentication method, activates the corresponding authentication component based on the specific environment of the signer's client to complete the signer identity authentication, and logs the entire signer identity authentication process as evidence; the signer completes the signer identity authentication according to the authentication process in the signature intention authentication method, and the API interface SDK determines the signer identity authentication result. If the authentication fails, it returns the specific error information of the business system and ends the signing process; if the authentication passes, it proceeds to step 2.4; at the same time, the API interface SDK records the relevant log records of the signer identity authentication process and the relevant identity authentication evidence information, and calculates the hash value, recorded as hash_au; Step 2.4: The signer checks the signature and informs the user interface. The API interface SDK records the relevant signature and notification evidence and calculates the hash value of the signature and notification evidence, recorded as hash_pn. The API interface backend stores the signature evidence information and, when storing the signature evidence, timestamps the signature evidence with the server's digital certificate.

6. The reliable electronic signature method for matching business processes according to claim 5, characterized in that: The step 2.1 specifically includes the following steps: Step 2.1.1: The signatory performs an electronic signature in the application system. In this case, the signatory is operating a business process in a business process instance of the application system. Step 2.1.2: The application system prepares the signature text and related signature control parameter values. The specific signature control parameter value list includes: application ID, random number, timestamp, process unique ID, process instance unique ID, process instance code, process instance name, link unique ID, signature text, pre-signature notification content parameter value, post-signature notification content parameter value, and calculates the signature value of the signature control parameter value. Step 2.1.3: The application system calls the signature interface of the API interface to perform electronic signature; Step 2.1.4: The API SDK calculates the hash value hash_arg of the SM3 algorithm, which includes the call parameters, random number, and timestamp. The API backend verifies the correctness of the application system identity and the call parameters. Step 2.1.

5. The API interface backend finds the corresponding application key based on the application system's application ID and decrypts the signature value of the parameter value calculated by the application system. The decryption result is the parameter hash value hash_arg', which is compared with the parameter hash value hash_arg. If they are equal, the verification passes; otherwise, the verification fails.

7. The reliable electronic signature method for matching business processes according to claim 6 is characterized in that: The step 2.2 specifically includes the following steps: Step 2.2.2, the API interface SDK calls the API interface backend service to obtain signature control parameters based on the application ID, process unique ID, and link unique ID; Step 2.2.

3. The API interface backend queries the configuration information stored in the signature control parameter data structure based on the application ID, process unique ID, and link unique ID, and queries the signature control parameter information for pre-signature notification, signature intention authentication method, and post-signature notification, and returns it to the API interface SDK; Step 2.2.4, the API interface SDK determines whether there is pre-signature notification information. If so, it generates a pre-signature notification user interface based on the notification template, customized UI, and pre-signature notification content parameter values, and displays it to the signer.

8. The reliable electronic signature method for matching business processes according to claim 7 is characterized in that: The step 2.4 specifically includes the following steps: Step 2.4.

1. The API SDK calculates the hash value of the original signature, which is recorded as hash_or. Step 2.4.2: The API SDK determines whether there is post-signature notification information. If so, it generates a post-signature notification user interface based on the notification template, customized UI, and post-signature notification content parameter values, and displays it to the signer. The API SDK also records relevant log records. Step 2.4.

3. The API interface SDK uses the user's digital certificate private key to sign hash_bn, hash_au, hash_pn, and hash_or, respectively, to obtain the pre-signature evidence signature value, the signature value of the identity authentication process during signing, the post-signature evidence signature value, and the signature value of the original text. At this time, the API interface SDK uses the specific signer's digital certificate private key to sign according to the specific environment of the signer's client. Step 2.4.4: The application system receives the original signature value and saves it; Step 2.4.

5. The API interface backend stores signature evidence information, including evidence information of the content notified before signing and the signature value of the evidence notified before signing, evidence information of the signatory's identity authentication during signing and the signature value, evidence information of the content notified after signing and the signature value of the evidence notified after signing, and the signature value of the original signature. At the same time, when storing the signature evidence, the digital certificate of the server is stamped with a timestamp to prove the storage time of the evidence, and the stamped timestamp is stamped for the entire signature evidence record.

9. The reliable electronic signature method for matching business processes according to claim 8, characterized in that: The step 3 specifically includes the following steps: Step 3.1: The API interface backend extracts the corresponding signature evidence list of all process nodes under a specific process instance through the application ID, process unique ID, and process instance unique ID; the evidence list is sorted in chronological order based on the timestamp; Step 3.2: The API interface backend parses the query results and retrieves the corresponding information based on the signature control parameter data structure. Step 3.3: The API interface backend parses each piece of data, including pre-signature notification evidence, signature authentication evidence, and post-signature notification evidence, and returns the final result.

Citation Information

Patent Citations

  • Method and system for achieving user-informed digital signature by using mobile terminal

    CN102780561A

  • Method and system for realizing electronic signature

    CN104158668A

  • Continuous signature method and system based on electronic signature middleware

    CN113285809A

  • Data evidence storage system oriented to field of credit investigation big data

    CN115225346A

  • Electronic file secure transmission method and system based on electronic signature, and medium

    CN116015945A

Cited By

  • Electronic signature system and method based on biological feature recognition and authentication

    CN121530594A

  • Electronic signature system and method based on biometric recognition authentication

    CN121530594B