Method for realizing online contract signing based on mobile terminal electronic signature technology
By generating and storing unique credentials on mobile devices, and combining this with hash function processing to generate credentials, the security and credibility issues of online contract signing are resolved. This achieves non-repudiation and traceability of contracts, thereby improving the security of contract signing and management flexibility.
Patent Information
- Application Number
- CN202511904299.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-17
- Publication Date
- 2026-03-20
AI Technical Summary
Existing online contract signing methods are inadequate in terms of security and credibility, are susceptible to tampering, forgery, or denial, and lack unique identifiers and reliable storage mechanisms, making contract traceability and verification difficult.
By generating unique credentials on the mobile device and binding them to the electronic contract, and storing them in a secure storage device, the system uses a hash function to process terminal status information, contract semantic features, and event identifiers to generate credentials, ensuring the non-repudiation and traceability of the signing event. The system then verifies and transmits the contract through the secure storage device.
It improves the security and credibility of electronic contract signing, prevents contract data from being tampered with, ensures the uniqueness and traceability of contracts, and enhances the system's resistance to attacks and the flexibility of contract management.
Smart Images

Figure CN121706148A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of data processing and relates to a method for online contract signing based on mobile electronic signature technology. Background Technology
[0002] With the rapid development of internet technology, online contract signing is gradually replacing traditional paper contract signing, becoming a crucial part of business activities. The application of mobile electronic signature technology allows users to sign contracts anytime, anywhere, improving convenience and efficiency. However, existing online contract signing methods still have shortcomings in terms of security and reliability. For example, contracts are susceptible to tampering, forgery, or denial during the signing process, leading to questions about the legal validity of the contract. Furthermore, current technology lacks a unique identifier and reliable storage mechanism for signing events, making post-signing traceability and verification difficult. Therefore, a more secure and reliable online contract signing method is needed to prevent contract data from being tampered with. Summary of the Invention
[0003] In view of this, in order to solve the above problems, the present invention provides a method for online contract signing based on mobile electronic signature technology.
[0004] To achieve the above objectives, the present invention provides the following technical solution: In a first aspect, a method for online contract signing based on mobile electronic signature technology is provided, characterized in that it is applied to a first electronic terminal, and the method includes: responding to a first user performing a signing operation on an electronic contract at a first time, the first electronic terminal determining the first electronic contract to be signed, the first user performing a signing operation on the first electronic contract at a first time being a first event; the first electronic terminal determining the credential of the first event, the credential of the first event being unique; the first electronic terminal binding the credential of the first event with the first electronic contract to be signed and sending it to a secure storage device.
[0005] Therefore, by generating unique credentials and binding them to the electronic contract and storing them on a secure storage device, the non-repudiation and traceability of the signing event are ensured; that is, each contract has one and only one unique event credential. This method improves the security and credibility of electronic contract signing and prevents contract data from being tampered with.
[0006] Optionally, the first electronic terminal determines the credentials of the first event by: assigning a first event identifier to the first event; obtaining at least one relevant information of the first electronic terminal at the first time: communication parameters, attitude information or operating status; and extracting the semantic features of the electronic contract from the electronic contract; and processing the at least one relevant information of the first electronic terminal at the first time, the semantic features of the electronic contract and the first event identifier to obtain the credentials of the first event.
[0007] Therefore, by combining event identifiers, terminal status information (such as communication parameters, attitude information, or operating status), and contract semantic features to generate credentials, the complexity and uniqueness of the credentials are enhanced. This makes the credentials more difficult to forge or copy, improves the verifiability and tamper-proofness of signing events, and enhances the system's resistance to attacks by utilizing multi-factor information.
[0008] Optionally, the first electronic terminal processes at least one relevant piece of information at the first moment, the semantic features of the electronic contract, the first event identifier, and the credentials of the first event to satisfy the following relationship: P1=H(H(D1)| | H(T1) | | H(S1)); In this system, || represents a join operation, H represents hash processing, D1 represents at least one piece of relevant information from the first electronic terminal at the first moment, T1 represents the semantic features of the electronic contract, S1 represents the first event identifier, and P1 represents the credential of the first event. Therefore, using a hash function to process the join information to generate credentials ensures the integrity and irreversibility of the credentials, preventing forgery or tampering. This computational relationship improves the security and efficiency of credential generation, simplifies the verification process, enhances the overall reliability of the system, and supports rapid verification.
[0009] Optionally, the first user acts as Party B in the electronic contract. The method further includes: a first electronic terminal receiving a contract retrieval request from a second electronic terminal, the contract retrieval request including the address of the second electronic terminal, and the second user corresponding to the second electronic terminal being Party A in the electronic contract; the first electronic terminal, based on the contract retrieval request, sending a cooperation push request to a secure storage device, the cooperation push request including credentials for a first event and the address of the second electronic terminal; the secure storage device is configured to: when the secure storage device verifies the credentials for the first event included in the cooperation push request against the pre-obtained bound credentials for the first event and the signed first electronic contract, securely send the signed first electronic contract to the second electronic terminal based on the address of the second electronic terminal. Thus, by sending the contract to Party A after verifying the credentials through the secure storage device, secure distribution and transmission of the contract are achieved. This method ensures that only legitimate parties can obtain the contract, preventing the contract from being stolen or tampered with during transmission, enhancing the security and controllability of contract distribution, and improving the efficiency of contract signing.
[0010] Optionally, after the first time, the method further includes: in response to the first user performing a signing operation on the electronic contract at the second time, the first electronic terminal determines the signed second electronic contract, and the first user performing a signing operation on the first electronic contract at the second time constitutes a second event; the first electronic terminal determines the credentials of the second event, which are unique; the first electronic terminal binds the information indicating the second time, the credentials of the second event, and the signed second electronic contract and sends them to a secure storage device; the secure storage device is configured to: update the signed first electronic contract using the signed second electronic contract if the secure storage device verifies that the credentials of the second event and the credentials of the first event satisfy a preset relationship based on the information indicating the second time. In this way, multiple signing and updating of contracts are supported, and the continuity and consistency of contract versions are ensured by generating new credentials and updating the contract after verification. This method prevents unauthorized modifications, maintains the historical record of contracts, enhances the flexibility of contract management, and improves the adaptability and security of the system.
[0011] Optionally, the first electronic terminal determines the credential for the second event, including: the first electronic terminal determining a second event identifier for the second event; at least one relevant piece of information related to the first electronic terminal and the second time: communication parameters, attitude information, or operating status; and new semantic features of the electronic contract. The first electronic terminal processes the credential for the first event, the at least one relevant piece of information related to the first electronic terminal and the second time, the new semantic features of the electronic contract, and the second event identifier to obtain the credential for the second event. In this way, the first credential is introduced when generating the second signing credential, establishing a chain relationship between events and enhancing the relevance and traceability of multiple signing events. This method ensures the transparency of the contract update process, prevents event disconnection, and improves security.
[0012] Optionally, the first electronic terminal determines a second event identifier for the second event, and at least one relevant piece of information related to the first electronic terminal and the second time: communication parameters, attitude information, or operating status, and a new semantic feature of the electronic contract. This includes: the first electronic terminal determining the time increment of the second time compared to the first time; the first electronic terminal determining, based on the time increment, variable factors corresponding to each of the at least one relevant piece of information at the first time, variable factors corresponding to the semantic features of the electronic contract, and variable factors corresponding to the first event identifier; the first electronic terminal determining at least one relevant piece of information related to the second time based on the at least one relevant piece of information at the first time and the variable factors corresponding to each of the at least one relevant piece of information at the first time; the first electronic terminal determining a new semantic feature of the electronic contract based on the semantic features of the electronic contract and the variable factors corresponding to the semantic features of the electronic contract; and the first electronic terminal determining a second event identifier for the second event based on the first event identifier and the variable factors corresponding to the first event identifier. Thus, by calculating variable factors based on the time increment and dynamically generating terminal information, contract features, and event identifiers, the uniqueness and timeliness of each signed document are ensured. This method reflects the impact of time variations, improves the anti-collision capability of credentials, and maintains the temporal relationship between events, thereby enhancing the robustness of the system.
[0013] Optionally, at least one relevant piece of information of the first electronic terminal at the first time, the variable factors corresponding to each of the at least one relevant piece of information of the first electronic terminal at the first time, and at least one relevant piece of information of the first electronic terminal related to the second time satisfy the following relationship: D2 = D1 + ΔD; Wherein, D2 is at least one relevant information related to the first electronic terminal and the second time, D1 is at least one relevant information of the first electronic terminal at the first time, and Δ_D is the variable factor corresponding to each of the at least one relevant information of the first electronic terminal at the first time; The semantic features of electronic contracts, the variable factors corresponding to the semantic features of electronic contracts, and the new semantic features of electronic contracts satisfy the following relationship: T2 = T1 + Δ_T; Where T2 is the new semantic feature of the electronic contract, T1 is the semantic feature of the electronic contract, and Δ_T is the variable factor corresponding to the semantic feature of the electronic contract. The first event identifier, the variable factor corresponding to the first event identifier, and the second event identifier of the second event satisfy the following relationship: S2 = S1 + Δ_S; Where S2 is the identifier of the second event, S1 is the identifier of the first event, and Δ_S is the variable factor corresponding to the identifier of the first event.
[0014] Therefore, updating information reduces computational complexity and improves credential generation efficiency. This method ensures the accuracy and consistency of information updates, reduces system resource consumption, and guarantees the reliability of credential generation.
[0015] Optionally, the following relationship is satisfied among the credentials of the first event, at least one relevant piece of information related to the first electronic terminal and the second time, the new semantic features of the electronic contract, the identifier of the second event, and the credentials of the second event: P2=H(H(D2)| | H(T2) | | H(S2) | | H(P1)); In this method, || represents a join operation, H represents hash processing, D2 represents at least one piece of relevant information related to the first electronic terminal and the second time, T2 represents the new semantic feature of the electronic contract, S2 represents the second event identifier, P1 represents the credential of the first event, and P2 represents the credential of the second event. Thus, by introducing the hash of the first credential into the generation of the second credential, a hash chain structure is formed, ensuring the continuity and immutability of event credentials. This method enhances overall data security.
[0016] Optionally, the secure storage device is configured to: determine the verification credential for the second event based on the information indicating the second time and the credential for the first event; if the verification credential for the second event is the same as the credential for the second event, then update the signed first electronic contract using the signed second electronic contract. In this way, the secure storage device provides a fast and effective verification mechanism by calculating the verification credential and comparing it with the received credential, ensuring the security of contract updates. Furthermore, since most of the parameters used to generate the credential for the second event, such as the second event identifier, at least one relevant information of the first electronic terminal related to the second time (communication parameters, attitude information, or operating status), and the new semantic features of the electronic contract are not sent by the first electronic terminal to the secure storage device, but are instead generated automatically by the secure storage device based on the same rules as the first electronic terminal, information security is further enhanced.
[0017] Secondly, a system for online contract signing based on mobile electronic signature technology is provided, the system being configured to perform the method described in the first aspect.
[0018] The objectives and other advantages of this invention can be realized and obtained through the following description. Attached Figure Description
[0019] To make the objectives, technical solutions, and advantages of the present invention clearer, the preferred embodiments of the present invention will be described in detail below with reference to the accompanying drawings, wherein: Figure 1 A schematic diagram of the system for online contract signing based on mobile electronic signature technology provided by the present invention; Figure 2 A flowchart of a method for online contract signing based on mobile electronic signature technology provided by the present invention; Figure 3 This is a schematic diagram of the structure of a processing device provided by the present invention. Detailed Implementation
[0020] The following specific examples illustrate the implementation of the present invention. Those skilled in the art can easily understand other advantages and effects of the present invention from the content disclosed in this specification. The present invention can also be implemented or applied through other different specific embodiments, and various details in this specification can be modified or changed based on different viewpoints and applications without departing from the spirit of the present invention. It should be noted that the illustrations provided in the following embodiments are only schematic representations of the basic concept of the present invention. In the absence of conflict, the following embodiments and features can be combined with each other. The accompanying drawings are for illustrative purposes only, representing schematic diagrams only, not actual physical images, and should not be construed as limiting the present invention. To better illustrate the embodiments of the present invention, some parts in the drawings may be omitted, enlarged, or reduced, and do not represent the actual product dimensions. It is understandable that those skilled in the art may omit certain well-known structures and their descriptions in the drawings.
[0021] like Figure 1 As shown, a system for online contract signing based on mobile electronic signature technology is provided. The system includes: a first electronic terminal and a secure storage device.
[0022] The first electronic terminal can be a terminal with user interaction and communication functions, or a chip or chip system that can be installed on the terminal. This first electronic terminal can also be referred to as an access terminal, user unit, user station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, terminal, wireless communication device, user agent, or user device. In the embodiments of this application, the terminal device can be a mobile phone, tablet computer, computer with wireless transceiver function, virtual reality (VR) terminal device, augmented reality (AR) terminal device, wireless terminal in industrial control, wireless terminal in self-driving, wireless terminal in remote medical care, wireless terminal in smart grid, wireless terminal in transportation safety, wireless terminal in smart city, wireless terminal in smart home, vehicle terminal, RSU with terminal function, etc. The terminal device of this application may also be an on-board module, on-board component, on-board chip, or on-board unit that is built into a vehicle as one or more components or units. The vehicle can implement the method provided in this application through the built-in on-board module, on-board component, on-board chip, or on-board unit.
[0023] Secure storage devices can reside in a private network or subnet that is physically isolated from the external internet or protected by strict firewall policies. Firewall rules only allow inbound connections from specific IPs and ports (such as HTTPS 443) of the Zone 2 application server and prohibit any other direct external access. This is the system's "vault," focused on high-security data storage, credential verification, and cryptographic operations. Secure storage devices can be dedicated hardware security module (HSM) clusters, such as cryptographic processors providing physical-level security, whose private keys do not appear outside the HSM; all encryption, decryption, signing, and hashing operations are performed internally within the hardware. Alternatively, secure storage devices can be software-based secure storage services (running in isolated virtual machines or containers), such as a set of microservices deployed on a secure zone intranet server. It uses software cryptographic libraries (such as OpenSSL, Bouncy Castle) and strict access control lists (ACLs) to implement security features.
[0024] like Figure 2 As shown, a method for online contract signing based on mobile electronic signature technology is provided. This method is applied to the aforementioned system, and the specific process of this method is as follows: S201, in response to the first user performing a signing operation on the electronic contract at the first moment, the first electronic terminal confirms the first electronic contract that has been signed. The first user performing a signing operation on the first electronic contract at the first moment is a first event.
[0025] For example, the first electronic terminal, such as a mobile app, displays the final version of the first electronic contract to be signed to the first user. Its interface clearly displays the contract content, accompanied by explicit legal prompts, such as: "You are about to make a legally binding electronic signature on the 'XXX Contract.' Once signed, it indicates that you agree to all the terms of the contract." The "Sign" button / interactive area is specially designed (e.g., highlighted) and may be configured to require secondary confirmation (e.g., a pop-up dialog box asking "Are you sure you want to sign?"). The first user, fully aware of the legal consequences, actively performs the signing operation at the first moment (timestamp recorded by the system backend server or a trusted time source on the terminal, accurate to milliseconds). This operation typically involves: clicking the "Sign" or "Confirm" button, handwriting a signature in the designated area (via touchscreen), completing biometric verification such as fingerprint recognition, facial recognition, or voiceprint recognition, and entering a pre-set signature password or dynamic verification code.
[0026] In response to the user's above action, the operating system or application of the first electronic terminal captures the complete context of this action and defines it as a first event. Based on this, the operating system immediately locks the currently displayed electronic contract content to prevent anyone from tampering with the content during or after the signing process. This means that the system obtains the final, immutable data snapshot of the contract seen by the user at the moment the "sign" button is pressed.
[0027] S202, the first electronic terminal determines the credential of the first event, and the credential of the first event is unique.
[0028] The first electronic terminal can assign a first event identifier to the first event to uniquely identify it.
[0029] The first electronic terminal acquires at least one piece of relevant information at the first time: communication parameters, attitude information, or operating status. The communication parameters can be Layer 2 / Layer 3 signaling parameters of the first electronic terminal at the first time (such as the C-RNTI established for this radio bearer, timing advance (TA), channel quality indicator (CQI) at a specific moment, etc.). These parameters are dynamically changing, but unique for the first event because they are restricted to parameters at the first time. The attitude information can be the pitch angle and yaw angle of the first electronic terminal. The operating status can be the memory utilization rate, processor utilization rate, battery level, etc. of the first electronic terminal.
[0030] Furthermore, the first electronic terminal can also extract semantic features from electronic contracts. For example, it can extract the most representative keywords as semantic features by calculating the TF-IDF value of each word in the contract. In practice, a professional dictionary in the field of contracts can be built, word frequencies can be calculated, and the N keywords with the highest weights (such as "penalty for breach of contract," "delivery deadline," "intellectual property," etc.) can be selected as semantic features.
[0031] The first electronic terminal can process at least one relevant piece of information from the first electronic terminal at a given time, the semantic features of the electronic contract, and the first event identifier to obtain the credential for the first event. Thus, by combining the event identifier, terminal status information (such as communication parameters, attitude information, or operational status), and contract semantic features to generate the credential, the complexity and uniqueness of the credential are enhanced. This makes the credential more difficult to forge or copy, improves the verifiability and tamper-proof nature of the signing event, and enhances the system's resistance to attacks by utilizing multi-factor information.
[0032] In one possible implementation, the above processing is hashing, such as hash 256. Therefore, the relationship between at least one relevant information of the first electronic terminal at the first time, the semantic features of the electronic contract, the processing of the first event identifier, and the credentials of the first event is satisfied: P1=H(H(D1)||H(T1)||H(S1)). In this system, || represents a join operation, H represents hash processing, D1 represents at least one piece of relevant information from the first electronic terminal at the first moment, T1 represents the semantic features of the electronic contract, S1 represents the first event identifier, and P1 represents the credential of the first event. Therefore, using a hash function to process the join information to generate credentials ensures the integrity and irreversibility of the credentials, preventing forgery or tampering. This computational relationship improves the security and efficiency of credential generation, simplifies the verification process, enhances the overall reliability of the system, and supports rapid verification.
[0033] S203, the first electronic terminal binds the credentials of the first event with the signed first electronic contract and sends them to the secure storage device.
[0034] Therefore, by generating unique credentials and binding them to the electronic contract and storing them on a secure storage device, the non-repudiation and traceability of the signing event are ensured; that is, each contract has one and only one unique event credential. This method improves the security and credibility of electronic contract signing and prevents contract data from being tampered with.
[0035] Optionally, where the first user acts as Party B in the electronic contract, the method further includes the following: Step S301: The first electronic terminal receives a contract acquisition request from the second electronic terminal. The contract acquisition request includes the address of the second electronic terminal, and the second user corresponding to the second electronic terminal is the party A of the electronic contract.
[0036] Step S302: The first electronic terminal sends a cooperative push request to the secure storage device according to the contract acquisition request. The cooperative push request includes the credentials of the first event and the address of the second electronic terminal.
[0037] Therefore, the secure storage device can be configured such that: when the secure storage device verifies the credentials of the first event included in the cooperation push request against the pre-obtained credentials of the bound first event and the signed first electronic contract (i.e., S203), if the secure storage device determines whether the credentials of the first event obtained in S203 are the same as those obtained in step S302, and if they are the same, it securely sends the signed first electronic contract to the second electronic terminal based on the address of the second electronic terminal. For example, the secure storage device can establish a secure session with the second electronic terminal using the address of the second electronic terminal, and then send the signed first electronic contract to the second electronic terminal through the secure session. In this way, by sending the contract to the client after verifying the credentials through the secure storage device, secure distribution and transmission of the contract are achieved. This method ensures that only legitimate parties can obtain the contract, prevents the contract from being stolen or tampered with during transmission, enhances the security and controllability of contract distribution, and improves the efficiency of contract signing.
[0038] It should also be understood that a secure session is established between the secure storage device and the first electronic terminal. Step S2 involves obtaining a contract request transmitted through the secure session to prevent the credentials of the first event and the address of the second electronic terminal from being stolen and tampered with.
[0039] Optionally, after the first time, the method further includes the following steps: Step S401: In response to the first user performing a signing operation on the electronic contract at a second time, the first electronic terminal determines the second electronic contract to be signed. The first user performing a signing operation on the first electronic contract at a second time is a second event.
[0040] It should be understood that the implementation of step S401 is similar in principle to that of S201, and can be understood by referring to it, so it will not be repeated here. In addition, if the user of the second electronic terminal believes that the signed first electronic contract needs to be re-signed, then step S401 can be executed on this basis.
[0041] Step S402: The first electronic terminal determines the credentials of the second event, and the credentials of the second event are unique.
[0042] For example, the first electronic terminal determines the second event identifier of the second event, and at least one relevant piece of information related to the second event: communication parameters, attitude information, or operating status, as well as the new semantic features of the electronic contract. The first electronic terminal processes the credentials of the first event, the at least one relevant piece of information related to the second event, the new semantic features of the electronic contract, and the second event identifier to obtain the credentials of the second event. In this way, the first credential is introduced when generating the second signing credential, establishing a chain relationship between events and enhancing the relevance and traceability of multiple signing events. This method ensures the transparency of the contract update process, prevents event disconnection, and improves security.
[0043] Specifically, the first electronic terminal can determine the time increment of the second time relative to the first time. For example, if the first time is t1 and the second time is t2, the time increment can be t2 / t1, where / means division.
[0044] The first electronic terminal can determine, based on the time increment, the variable factors corresponding to at least one relevant piece of information of the first electronic terminal at the first time, the variable factors corresponding to the semantic features of the electronic contract, and the variable factors corresponding to the first event identifier. For example, various time increments and the variable factors of at least one relevant piece of information of the first electronic terminal (such as communication parameters, attitude information, or operating status) can have a one-to-one predefined or preconfigured mapping relationship. Therefore, the first electronic terminal can determine, based on the determined time increment, the variable factors corresponding to each of the at least one relevant piece of information of the first electronic terminal at the first time mapped by that time increment. In addition, the variable factors of the semantic features corresponding to the time increment can be the repetition frequency of high-frequency words. Various time increments and the repetition frequency of their respective high-frequency words have a one-to-one predefined or preconfigured mapping relationship. Therefore, the first electronic terminal can determine, based on the determined time increment, the variable factors corresponding to the semantic features of the electronic contract mapped by that time increment, that is, which high-frequency words in the semantic features of the electronic contract need to have their repetition frequency adjusted to the frequency corresponding to the time increment. Various time increments and event identifiers of various lengths have a one-to-one predefined or preconfigured mapping relationship. Therefore, the first electronic terminal can determine the variable factor corresponding to the first event identifier mapped to the determined time increment, that is, the length to which the first event identifier should be adjusted.
[0045] Therefore, the first electronic terminal determines at least one piece of relevant information related to the second time based on at least one piece of relevant information of the first electronic terminal at the first time and the variable factors corresponding to each piece of relevant information of the first electronic terminal at the first time. For example, at least one piece of relevant information of the first electronic terminal at the first time, the variable factors corresponding to each piece of relevant information of the first electronic terminal at the first time, and at least one piece of relevant information of the first electronic terminal related to the second time satisfy the following relationship: D2=D1+Δ_D; where D2 is at least one piece of relevant information of the first electronic terminal related to the second time, D1 is at least one piece of relevant information of the first electronic terminal at the first time, and Δ_D is the variable factor corresponding to each piece of relevant information of the first electronic terminal at the first time.
[0046] The first electronic terminal can determine the new semantic features of an electronic contract based on its semantic features and the corresponding variable factors. For example, the semantic features of an electronic contract, the corresponding variable factors, and the new semantic features satisfy the following relationship: T2 = T1 + Δ_T; where T2 is the new semantic feature of the electronic contract, and T1 is the number of repetitions of high-frequency words in the semantic features of the electronic contract, which is adjusted to the number of repetitions corresponding to the time increment.
[0047] Furthermore, the first electronic terminal can also determine the second event identifier of the second event based on the first event identifier and the corresponding variable factor. The first event identifier, the corresponding variable factor, and the second event identifier of the second event satisfy the following relationship: S2 = S1 + Δ_S; where S2 is the second event identifier, S1 is the first event identifier, Δ_S is the variable factor corresponding to the first event identifier, and S1 + Δ_S represents adjusting the first event identifier to the length corresponding to the time increment, such as by padding or truncation, to obtain the second event identifier. Therefore, updating information reduces computational complexity and improves credential generation efficiency. This method ensures the accuracy and consistency of information updates, reduces system resource consumption, and ensures the reliability of credential generation.
[0048] In this way, by calculating variable factors based on time increments and dynamically generating terminal information, contract characteristics, and event identifiers, the uniqueness and timeliness of each signing credential are ensured. This method reflects the impact of time changes, improves the anti-collision capability of credentials, and maintains the temporal relationship between events, thereby enhancing the robustness of the system.
[0049] Optionally, in the above processing, the credentials of the first event, at least one relevant piece of information related to the first electronic terminal and the second time, the new semantic features of the electronic contract, the identifier of the second event, and the credentials of the second event satisfy the following relationship: P2=H(H(D2)| | H(T2) | | H(S2) | | H(P1)); In this method, || represents a join operation, H represents hash processing, D2 represents at least one piece of relevant information related to the first electronic terminal and the second time, T2 represents the new semantic feature of the electronic contract, S2 represents the second event identifier, P1 represents the credential of the first event, and P2 represents the credential of the second event. Thus, by introducing the hash of the first credential into the generation of the second credential, a hash chain structure is formed, ensuring the continuity and immutability of event credentials. This method enhances overall data security.
[0050] Step S403: The first electronic terminal sends the information indicating the second time, the credentials of the second event, and the signed second electronic contract to the secure storage device.
[0051] The secure storage device is configured such that, upon verification that the credentials for the second event and the credentials for the first event satisfy a preset relationship, it updates the signed first electronic contract using the signed second electronic contract. This enables support for multiple contract signings and updates, ensuring contract version continuity and consistency by generating new credentials and verifying them before updating the contract. This method prevents unauthorized modifications, maintains a historical record of contracts, enhances the flexibility of contract management, and improves system adaptability and security.
[0052] For example, the secure storage device is configured to: determine a verification credential for the second event based on information indicating the second time and the credentials of the first event (the verification credential for the second event is generated according to the same rules as the first electronic terminal; normally, since it is generated according to the same rules as the first electronic terminal, the verification credential for the second event should be the same as the credentials of the first event). Based on this, if the verification credential for the second event is the same as the credentials of the first event, the signed first electronic contract is updated using the signed second electronic contract. In this way, the secure storage device provides a fast and effective verification mechanism by calculating the verification credential and comparing it with the received credential, ensuring the security of contract updates. Furthermore, since most of the parameters used to generate the credentials for the second event, such as the second event identifier, at least one relevant piece of information related to the second time (communication parameters, attitude information, or operating status of the first electronic terminal), and the new semantic features of the electronic contract are not sent to the secure storage device by the first electronic terminal, but are instead generated automatically by the secure storage device based on the same rules as the first electronic terminal, information security is further enhanced.
[0053] In summary, by generating unique credentials and binding them to the electronic contract and storing them on a secure storage device, the non-repudiation and traceability of the signing event are ensured; that is, each contract has one and only one unique event credential. This method improves the security and credibility of electronic contract signing and prevents contract data from being tampered with.
[0054] Figure 3 This is a schematic diagram of the structure of a processing device provided in an embodiment of this application. Exemplarily, the processing device may be a terminal, or a chip (system) or other component or assembly that can be disposed on the terminal. Figure 3 As shown, the processing device 200 may include a processor 201. Optionally, the processing device 200 may also include a memory 202 and / or a transceiver 203. The processor 201 is coupled to the memory 202 and the transceiver 203, for example, via a communication bus.
[0055] The following is combined with Figure 3 A detailed description of each component of the processing equipment 200 is provided below: The processor 201 is the control center of the processing device 200. It can be a single processor or a collective term for multiple processing elements. For example, the processor 201 can be one or more central processing units (CPUs), application-specific integrated circuits (ASICs), or one or more integrated circuits configured to implement the embodiments of this application, such as one or more digital signal processors (DSPs), or one or more field-programmable gate arrays (FPGAs).
[0056] Optionally, the processor 201 can perform various functions of the processing device 200 by running or executing software programs stored in the memory 202 and calling data stored in the memory 202, such as performing the above-mentioned functions. Figure 2 The method shown.
[0057] In a specific implementation, as one example, the processor 201 may include one or more CPUs, for example... Figure 3 CPU0 and CPU1 are shown in the diagram.
[0058] In a specific implementation, as one example, the processing device 200 may also include multiple processors, for example... Figure 3The processor 201 shown is an example. Each of the processors 201 can be a single-core processor or a multi-core processor. Here, "processor" can refer to one or more devices, circuits, and / or processing cores used to process data (e.g., computer program instructions).
[0059] The memory 202 is used to store the software program that executes the solution of this application, and is controlled by the processor 201 to execute it. The specific implementation method can be referred to the above method embodiment, and will not be repeated here.
[0060] Optionally, the memory 202 may be a read-only memory (ROM) or other type of static storage device capable of storing static information and instructions, random access memory (RAM) or other type of dynamic storage device capable of storing information and instructions, or electrically erasable programmable read-only memory (EEPROM), compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed optical discs, laser discs, optical discs, digital universal optical discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer, but not limited thereto. The memory 202 may be integrated with the processor 201 or exist independently, and may be connected via the interface circuitry of the processing device 200. Figure 3 (Not shown in the image) is coupled to processor 201, but this embodiment does not specifically limit this.
[0061] Transceiver 203 is used for communication with other processing devices. For example, if processing device 200 is a terminal, transceiver 203 can be used to communicate with a network device or with another terminal device. As another example, if processing device 200 is a network device, transceiver 203 can be used to communicate with a terminal or with another network device.
[0062] Optionally, transceiver 203 may include a receiver and a transmitter. Figure 3 (Not shown separately). The receiver is used to implement the receiving function, and the transmitter is used to implement the transmitting function.
[0063] Optionally, the transceiver 203 can be integrated with the processor 201, or it can exist independently and be connected via the interface circuit of the processing device 200. Figure 3(Not shown in the image) is coupled to processor 201, but this embodiment does not specifically limit this.
[0064] Understandable Figure 3 The structure of the processing device 200 shown does not constitute a limitation on the processing device. Actual processing devices may include more or fewer components than shown, or combine certain components, or have different component arrangements.
[0065] Furthermore, the technical effects of the processing device 200 can be referred to the technical effects of the method described in the above method embodiments, and will not be repeated here.
[0066] It should be understood that the processor in the embodiments of this application can be a central processing unit (CPU), or it can be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or any conventional processor, etc.
[0067] It should also be understood that the memory in the embodiments of this application can be volatile memory or non-volatile memory, or may include both volatile and non-volatile memory. The non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. The volatile memory can be random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of random access memory (RAM) are available, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate synchronous DRAM (DDR SDRAM), enhanced synchronous DRAM (ESDRAM), synchronous linked DRAM (SLDRAM), and direct rambus RAM (DR RAM).
[0068] The above embodiments can be implemented, in whole or in part, by software, hardware (such as circuits), firmware, or any other combination thereof. When implemented using software, the above embodiments can be implemented, in whole or in part, as a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more sets of available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium. A semiconductor medium can be a solid-state drive.
[0069] It should be understood that the term "and / or" in this article is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. A and B can be singular or plural. Additionally, the character " / " in this article generally indicates an "or" relationship between the preceding and following related objects, but it can also represent an "and / or" relationship. Please refer to the context for a more accurate understanding.
[0070] In this application, "at least one" means one or more, and "more than one" means two or more. "At least one of the following" or similar expressions refer to any combination of these items, including any combination of a single item or a plurality of items. For example, at least one of a, b, or c can mean: a, b, c, ab, ac, bc, or abc, where a, b, and c can be a single item or multiple items.
[0071] It should be understood that in the various embodiments of this application, the order of the above-mentioned processes does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.
[0072] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0073] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0074] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.
[0075] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0076] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.
[0077] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0078] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A method for online contract signing based on mobile electronic signature technology, characterized in that, Applied to a first electronic terminal, the method includes: In response to the first user performing a signing operation on the electronic contract at the first moment, the first electronic terminal determines the first electronic contract to be signed, and the first user performing the signing operation on the first electronic contract at the first moment is a first event; The first electronic terminal determines the credentials for the first event, and the credentials for the first event are unique; The first electronic terminal binds the credentials of the first event with the signed first electronic contract and sends them to the secure storage device.
2. The method according to claim 1, characterized in that, The first electronic terminal determines the credentials for the first event, including: The first electronic terminal assigns a first event identifier to the first event, and the first electronic terminal obtains at least one relevant information of the first electronic terminal at the first time: communication parameters, posture information or operating status, and the first electronic terminal extracts the semantic features of the electronic contract from the electronic contract; The first electronic terminal processes at least one relevant information of the first electronic terminal at the first time, the semantic features of the electronic contract, and the first event identifier to obtain the credentials of the first event.
3. The method according to claim 2, characterized in that, The following relationship is satisfied between at least one relevant piece of information from the first electronic terminal at the first time, the semantic features of the electronic contract, the processed first event identifier, and the credentials of the first event: P1=H(H(D1)| | H(T1) | | H(S1)); Wherein, | represents a connection operation, H represents hash processing, D1 represents at least one relevant information of the first electronic terminal at the first time, T1 represents the semantic features of the electronic contract, S1 represents the first event identifier, and P1 represents the credentials of the first event.
4. The method according to any one of claims 1-3, characterized in that, The method further includes: (The first user is Party B in the electronic contract.) The first electronic terminal receives a contract acquisition request from the second electronic terminal. The contract acquisition request includes the address of the second electronic terminal, and the second user corresponding to the second electronic terminal is the party A of the electronic contract. The first electronic terminal sends a cooperation push request to the secure storage device according to the contract acquisition request. The cooperation push request includes the credentials of the first event and the address of the second electronic terminal. The secure storage device is configured to: when the secure storage device verifies the credentials of the first event included in the cooperation push request based on the pre-acquired bound credentials of the first event and the signed first electronic contract, the secure storage device securely sends the signed first electronic contract to the second electronic terminal according to the address of the second electronic terminal.
5. The method according to claim 1, characterized in that, The second time is after the first time, and the method further includes: In response to the first user performing a signing operation on the electronic contract at the second time, the first electronic terminal determines the second electronic contract to be signed, and the first user performing the signing operation on the first electronic contract at the second time is a second event; The first electronic terminal determines the credentials for the second event, and the credentials for the second event are unique; The first electronic terminal sends the information indicating the second time, the credentials of the second event, and the signed second electronic contract to the secure storage device; the secure storage device is configured to update the signed first electronic contract using the signed second electronic contract if the credentials of the second event and the credentials of the first event satisfy a preset relationship based on the information indicating the second time.
6. The method according to claim 5, characterized in that, The first electronic terminal determines the credentials for the second event, including: The first electronic terminal determines the second event identifier of the second event, and the first electronic terminal is related to at least one relevant information of the second time: communication parameters, attitude information or operating status, and new semantic features of the electronic contract; The first electronic terminal processes the credentials of the first event, at least one relevant information related to the first electronic terminal and the second time, the new semantic features of the electronic contract, and the second event identifier to obtain the credentials of the second event.
7. The method according to claim 6, characterized in that, The first electronic terminal determines a second event identifier for the second event, and the first electronic terminal is associated with at least one relevant piece of information related to the second time: communication parameters, attitude information, or operating status, as well as new semantic features of the electronic contract, including: The first electronic terminal determines the time increment of the second time relative to the first time; The first electronic terminal determines, based on the time increment, the variable factors corresponding to at least one relevant information item of the first electronic terminal at the first time, the variable factors corresponding to the semantic features of the electronic contract, and the variable factors corresponding to the first event identifier; The first electronic terminal determines at least one piece of relevant information related to the second time based on at least one piece of relevant information of the first electronic terminal at the first time and the variable factors corresponding to each of the at least one piece of relevant information of the first electronic terminal at the first time; the first electronic terminal determines a new semantic feature of the electronic contract based on the semantic feature of the electronic contract and the variable factors corresponding to the semantic feature of the electronic contract; and the first electronic terminal determines a second event identifier of the second event based on the first event identifier and the variable factors corresponding to the first event identifier.
8. The method according to claim 7, characterized in that, The at least one relevant information item of the first electronic terminal at the first time, the variable factors corresponding to each of the at least one relevant information item of the first electronic terminal at the first time, and the at least one relevant information item of the first electronic terminal related to the second time satisfy the following relationship: D2 = D1 + ΔD; Wherein, D2 is at least one relevant information item of the first electronic terminal related to the second time, D1 is at least one relevant information item of the first electronic terminal at the first time, and Δ_D is the variable factor corresponding to each of the at least one relevant information item of the first electronic terminal at the first time; The semantic features of the electronic contract, the variable factors corresponding to the semantic features of the electronic contract, and the new semantic features of the electronic contract satisfy the following relationship: T2 = T1 + Δ_T; Wherein, T2 is the new semantic feature of the electronic contract, T1 is the semantic feature of the electronic contract, and Δ_T is the variable factor corresponding to the semantic feature of the electronic contract; The first event identifier, the variable factor corresponding to the first event identifier, and the second event identifier of the second event satisfy the following relationship: S2 = S1 + Δ_S; Wherein, S2 is the second event identifier, S1 is the first event identifier, and Δ_S is the variable factor corresponding to the first event identifier.
9. The method according to claim 7, characterized in that, The following relationship is satisfied between the credentials of the first event, at least one relevant information related to the first electronic terminal and the second time, the new semantic features of the electronic contract, the second event identifier, and the credentials of the second event: P2=H(H(D2)| | H(T2) | | H(S2) | | H(P1)); Wherein, | represents a connection operation, H represents hash processing, D2 is at least one relevant information related to the first electronic terminal and the second time, T2 is the new semantic feature of the electronic contract, S2 is the second event identifier, P1 is the credential of the first event, and P2 is the credential of the second event.
10. The method according to claim 9, characterized in that, The secure storage device is configured to: determine the verification credentials of the second event based on the information indicating the second time and the credentials of the first event; if the verification credentials of the second event are the same as the credentials of the second event, then update the signed first electronic contract using the signed second electronic contract.