An electronic seal based on electronic handwritten signature technology

Through electronic handwritten signature technology, the user's identity is verified and a unique numbered electronic seal is generated, which solves the security loopholes in the existing electronic seal technology and the problems of forging signatures, and realizes a high-security and traceable signature process, which is in line with the use process of traditional seals.

CN113934993BActive Publication Date: 2025-08-01CHONGQING AOXIONG INFORMATION TECH
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202010667197.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-07-13
Publication Date
2025-08-01
Estimated Expiration
2040-07-13

AI Technical Summary

Technical Problem

The existing electronic seal technology has security loopholes in identity verification, which makes it difficult to ensure the true identity of the user. The traditional verification method is easily forged and cannot effectively prevent unauthorized seal signature behavior.

Method used

Electronic handwritten signatures are used as the main identity verification parameters, and the signature data of the seal makers and authorized persons are used as the basis for identification, and traceback information is added to the seal object, verification and management are carried out through the seal center to generate a unique numbered electronic seal to ensure the authenticity and authorization of the seal object.

Benefits of technology

It improves the security and user acceptance of electronic seals, reduces the storage risks of traditional encryption certification equipment, eliminates unauthorized seal signing behavior, meets the requirements of judicial evidence, and realizes the traceability and authenticity of the seal signing object.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113934993B_ABST
    Figure CN113934993B_ABST
Patent Text Reader

Abstract

An electronic seal based on electronic handwritten signature technology. The seal maker authorizes the seal center to collect and store evidence to generate the electronic seal and authorizes users to use the electronic seal. The electronic seal includes a seal impression, electronic handwritten signature data, signature object summary data, and a label. Among them, the active biometric feature of the electronic handwritten signature data is used as a verification basis for the use permission of the electronic seal. After the electronic seal generates a number for the signature object, identification data is appended to the already signed signature object. Using the electronic seal of the present invention reduces the custody risk of traditional encryption authentication devices, expresses the signature intention of the authorized seal user through signature, and the signature object can be traced through the appended information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security, and more specifically to an electronic seal based on electronic handwritten signature technology. Background Art

[0002] There are mainly two common electronic seal technologies. One is to call a digital certificate for signature after authenticating the user's will based on static features such as text messages, passwords, and face recognition. This solution has vulnerabilities in security because static recognition features are easily stolen or imitated. It cannot guarantee the true identity of the user when the electronic seal is called. If the mobile phone or password is stolen, the thief can easily obtain the authorization of the electronic seal through this means, and it is difficult to identify the authenticity of the electronic seal information generated in this way.

[0003] The other uses an encrypted certificate stored on a removable storage medium as the basis for the signature authorization of the electronic seal. However, this method usually requires a compatible computer as the terminal. Other intelligent devices such as mobile phones are difficult to be used as the signature authorization terminal due to interface compatibility and other issues. At the same time, without enabling two-factor authentication, it is also difficult to distinguish whether the user is a truly authorized user. Even if two-factor authentication is used, in the case where both terminals are stolen, this method is still ineffective.

[0004] CN 108206831 A discloses a method for implementing an electronic seal, but using a random code as the verification means is still difficult to determine the true identity of the user. Even if the private key is stored in a second password device such as a USB-KEY or an IC card, these devices still have the risk of being physically stolen. By receiving a random code or other auxiliary encryption measures through the client, rather than through the means of the user actively submitting identity verification, it is always difficult to avoid physical theft in identity verification, thus forging the identity of the signer.

[0005] On the other hand, the verification of the electronic seal itself usually uses traditional methods such as certificates. However, due to the particularity of electronic documents, it is easier for the electronic seal to be separated from the original signature object, and then through means such as password cracking to forge information such as the digest, forging the signature object. This results in a situation where the electronic seal is genuine, but the file of the signature object is forged. Summary of the Invention

[0006] The present invention provides an electronic seal that uses electronic handwritten signature as the main identity verification parameter, uses the biometric information of the signature data of the authorized seal user as the basis for identity recognition, and adds traceback information to the signature object.

[0007] The seal maker uses the electronic handwritten signature of the seal maker to authorize the seal center to collect and store evidence to generate an electronic seal, and authorizes the user to use the electronic seal.

[0008] The electronic seal includes a seal impression and a label containing the electronic handwritten signature data of the seal maker and the seal user, where the electronic handwritten signature data of the seal user serves as the verification basis for the use permission of the electronic seal.

[0009] After generating a number for the signed object, the electronic seal appends identification data to the signed object.

[0010] The signed object summary data includes the summary of the signed object and a segment of characters, which is encrypted and stored in the electronic seal to form ciphertext signed object summary data. The purpose of using special characters is to prevent the extraction of the summary data.

[0011] The electronic handwritten signature data includes the electronic handwritten signature data of the seal maker and the authorized seal user.

[0012] The label is a digital entity segment, including a label header and a label body. The seal impression includes a seal picture file. The electronic handwritten signature data of the seal maker is located in the label header, and the electronic handwritten signature data of the authorized seal user is located in the label body.

[0013] The identification data includes the summary of the signed object after signing and the ciphertext signed object summary data encrypted twice.

[0014] By saving both the electronic handwritten signature data of the seal maker and the authorized seal user, the complete generation process of the electronic seal is achieved. In scenarios where the authenticity of the electronic seal needs to be verified, the authenticity of the seal can be compared based on the electronic handwritten signature data of the seal maker saved in the seal center. On the other hand, the electronic handwritten signature data of the authorized seal user is compared to ensure that the authorized seal user confirmed receiving authorization and agreed to use the seal at that time.

[0015] To prevent the malicious misappropriation of the electronic seal for signing other unauthorized documents or data, resulting in the generation of forged signed objects that cannot be recognized or traced, it is particularly important to append encrypted information to the signed object to ensure that it can match the information saved in the electronic seal after decryption, thereby verifying the authenticity of the signed object and making the signed object meet the requirements of judicial evidence technically.

[0016] The label header includes the public key of the seal maker, the summary of the seal picture, the seal making time, and an additional seal integrity signature. The attached integrity signature of the label is signed with the private key of the seal maker.

[0017] The label body includes the seal type, seal name, list of public keys of authorized seal users, and time data.

[0018] The public key of the authorized seal user is generated after the authorized seal user accepts the authorization invitation from the seal maker and is added to the list of public keys of authorized seal users.

[0019] Only after the authorized seal user receives the authorization invitation will the public key information of the authorized seal user be added to the public key list, avoiding the risk that the authorized seal user denies their willingness to use the seal.

[0020] The seal impression is generated by the seal maker or the administrator authorized by the seal maker, and the hash algorithm is used to calculate the seal impression digest, and the seal impression digest is written into the label header. The digest value serves as the identity identifier of the data file, ensuring the uniqueness of the picture file formed after using the seal.

[0021] The electronic handwritten signature data of the seal maker and the authorized seal user also includes auxiliary information, and the collection of the auxiliary information is collected by the terminal when the seal maker applies to the seal center.

[0022] The auxiliary information includes sound, fingerprint, video and SMS verification code.

[0023] The auxiliary information provided by the present invention is used as verification. For example, sound, fingerprint, etc. are inherent features in human biometric features. However, some of these features cannot be used as the basis for judging the will of the party, and some, such as complete ones, represent the will of the party, which requires a large amount of storage space and a large amount of computing power in the comparison, such as sound data and video data, etc. There are many defects as the basic data for the comparison verification representing the will of the party. Electronic Signature as a An active behavioral feature in biometric features, which can fully represent the will of the party. After the recognition rate meets the comparison requirements, it is an excellent evidence for comparison verification and the expression of the will of the party.

[0024] When the authorized seal user applies to use the electronic seal, they sign on the terminal to generate the electronic handwritten signature data of the authorized seal user for that time. The terminal simultaneously records the auxiliary information and submits it to the seal center. The seal center compares the electronic handwritten signature data generated by the authorized seal user on the terminal for that time with the historical electronic handwritten signature data, and conducts a low-weight reference comparison on the comparison result of the auxiliary information. After the comparison is consistent, the authorized seal user is authorized to use it.

[0025] The label header, label body, and signature object digest data of the electronic seal are encrypted by the seal center, and when the authorized seal user uses the electronic seal to sign, it is written into the signature object by the terminal.

[0026] By using an electronic handwritten signature as an identification means, the authorized seal user reduces the custody risk of traditional encryption authentication devices, eliminates the risk of the electronic seal being stolen by unauthorized users once the authorization tool is lost, and the flexibility of the seal maker also avoids the large subscription fees incurred by the seal center's reliance on third parties. On the other hand, the signature is a judicially recognized expression of intention. By uploading the electronic handwritten signature data of the authorized seal user and passing the comparison with the historical data stored in the seal center, the risk of the authorized seal user denying the signature after stamping is reduced, which is closer to the procedure of traditional seal authorization. While ensuring the security of technology and verification means, it conforms to the usage process of traditional seals, improving user acceptance. And by adding additional data to the signed object, the original document before the electronic seal is signed can be traced, ensuring the integrity of evidence when the signed object is used judicially. BRIEF DESCRIPTION OF THE DRAWINGS

[0027] Figure 1 It is a schematic structural diagram of the electronic seal according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0028] The following detailed description further elaborates on the purpose, technical solution, and beneficial effects of the present invention. It should be understood that: The following is only the detailed description of the present invention and is not used to limit the protection scope of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.

[0029] The present invention provides an electronic signature that uses an electronic handwritten signature as the main identity verification parameter, uses the signature data of the seal user as the main identification basis for the seal user's identity, and generates an electronic signature.

[0030] The seal maker uses the electronic handwritten signature of the seal maker to authorize the seal center to collect and archive evidence to generate an electronic seal and authorizes the user to use the electronic seal;

[0031] The electronic seal includes a seal impression and a label including the electronic handwritten signature data of the seal maker and the seal user, wherein the electronic handwritten signature data of the seal user is used as the verification basis for the use permission of the electronic seal;

[0032] After the electronic seal generates a number for the signed object, identification data is appended to the signed object that has been signed. The seal center is the basic functional implementation unit for the production, verification, and management of the electronic seal.

[0033] After the electronic seal generates a number for the signed object, identification data is appended to the signed object that has been signed.

[0034] The summary data of the signature object includes the summary of the signature object and a section of characters, which are encrypted and stored in the electronic seal to form the ciphertext signature object summary data. Preferably, this section of characters is specific and random characters.

[0035] The specific random characters are a combination of English letters, numbers, and special symbols. Using special characters can prevent the extraction of summary data. This section of characters can be appended to the signature object summary data or randomly inserted into the signature object summary data, and is randomly generated and managed by the seal center.

[0036] The electronic handwritten signature data includes the electronic handwritten signature data of the seal maker and the electronic handwritten signature data of the authorized seal user. Preferably, the seal maker at the seal center is the legal person of the enterprise or an administrator with corresponding job responsibilities authorized by the legal person of the enterprise, and the creator of the seal center is the seal maker. In addition, the seal maker can also entrust a third-party service agency with legal effect.

[0037] The label is a section of digital entity, including a label header and a label body, and the seal impression includes a seal picture file. The electronic handwritten signature data of the seal maker is located in the label header, and the electronic handwritten signature data of the authorized seal user is located in the label body. The label header includes the public key of the seal maker, the summary of the seal picture, the seal making time, and an additional seal integrity signature. The label body includes the seal type, the seal name, the list of public keys of the authorized seal users, and the editing time.

[0038] The signature object is an electronic data document, such as electronic document formats like pdf and ofd, and common image electronic document formats like jpg and png can all be used as signature objects.

[0039] The identification data includes the summary of the signed signature object and the ciphertext signature object summary data encrypted twice. The encryption method of the signature object summary data and the second encryption method for appending the identification data use different methods to reduce the risk of cracking.

[0040] Preferably, the appended identification data is set at the end of the file of the signature object. Second preferably, it can also be set at the head of the file of the signature object. It can also be at any position in the file of the signature object.

[0041] Preferably, each generated electronic seal has a unique number, and it uniquely corresponds to the number of the signature object.

[0042] The electronic handwritten signature data includes the electronic handwritten signature data of the seal maker and the electronic handwritten signature data of the authorized seal user.

[0043] The seal name and seal type have a corresponding relationship. One seal name can only correspond to one seal type. Seal types include financial seals, invoice seals, corporate business seals, contract seals, transaction seals, etc., which are the seal types required in business operations involving the need to use seals. Under the same seal type, the seal name can be customized according to needs. At the same time, under one seal type, there can be multiple seal names corresponding to different business needs or uses.

[0044] Preferably, the determination of the editing time is completed by applying to a timestamp server. The timestamp server is usually provided by a third party to ensure the accuracy of the editing time.

[0045] The public key of the authorized seal user is generated after the authorized seal user accepts the authorization invitation from the seal maker and is added to the list of public keys of the authorized seal users.

[0046] Preferably, after obtaining the seal impression, enterprise users authorize other users to use it through electronic handwritten signature recognition technology: First, the user needs to fill in the information of the authorized seal user, fill in the authorization letter and confirm it through electronic handwritten signature. And the specific scenarios, handling matters, validity period, usage cycle, usage times, network IP addresses, etc. for the authorized seal user to use the electronic seal can be set. After confirmation, the authorization information is archived and an authorization invitation is initiated.

[0047] Only after the authorized seal user accepts the authorization invitation, the public key information of the authorized seal user will be added to the public key list, avoiding the risk that the authorized seal user denies their intention to use the seal.

[0048] The seal impression is generated by the seal maker or an administrator authorized by the seal maker, and the hash algorithm is used to calculate the seal impression digest, and the seal impression digest is written into the tag header. The hash value serves as the identity identifier of the data file, ensuring the uniqueness of the picture file formed after using the seal.

[0049] Preferably, after editing and confirming that the seal impression effect is correct, through electronic handwritten signature recognition technology, after verifying the user's identity information, the seal tag header can also be attached with marked information, version number, manufacturer ID, identification information, attribute information, picture data, custom data, creation time, validity period, name, type, etc. content descriptions, combined with the comprehensive feature data of the authorized seal user, and encrypted in combination with the seal maker's signature certificate to form a complete electronic seal impression, and the electronic seal impression is archived.

[0050] More preferably, as an enterprise user, in addition to the legal representative of the enterprise personally creating the seal impression as the seal maker, an administrator authorized by the legal representative can also edit the seal impression. After the legal representative of the enterprise uses electronic handwritten signature for identity recognition, the administrator combines the seal impression with the electronic handwritten signature information of the legal representative of the enterprise, auxiliary verification information, and the legal representative's signature certificate for encryption to form a complete electronic seal impression.

[0051] The electronic handwritten signature data of the seal maker and the authorized seal user also includes auxiliary information, which is collected by the terminal when the seal maker applies to the seal center.

[0052] Preferably, the terminal is a computer with a signature board, a camera, and a sound collection device. Secondarily preferably, a handheld mobile device such as a mobile phone is used as the terminal, and some of the required information can also be collected. Depending on the terminal, the basis for identifying the electronic handwritten signature is different. If the user uses a computer with a signature board as the terminal, the seal center uses the electronic handwritten signature data of the user on the signature board as the authorization identification basis. If the user uses a handheld mobile device such as a mobile phone as the terminal, the seal center uses the electronic handwritten signature data of the mobile device such as the mobile phone as the identification basis.

[0053] The auxiliary information includes sound, fingerprint, video, and SMS verification code. These information are only used for reference comparison, and the complete match is not used as the standard for passing the verification. When the auxiliary verification is the same but the signature is different, it provides reference information for manual authorization and the subsequent judgment upgrade of the electronic handwritten signature recognition.

[0054] After receiving the seal use application from the user, the seal center uses the following process for seal confirmation:

[0055] a. Use the electronic handwritten signature recognition technology to verify the electronic handwritten signature data of the authorized seal user to ensure that the request is sent by this authorized seal user and authenticate the validity of the identity of the authorized seal user.

[0056] b. Call the electronic seal created by the authorized seal user.

[0057] c. The terminal uses the private key of the authorized seal user corresponding to the certificate or public key of the authorized seal user in the seal object to sign the document data to be sealed, and the signature information and the data description information are synthesized into the seal information.

[0058] d. The terminal embeds the seal information, label information, seal impression, and valid timestamp into the specified position of the original document together.

[0059] Therefore, when the authorized seal user applies to use the electronic seal, signs on the terminal, generates the electronic handwritten signature data of the authorized seal user for this time, the terminal records the auxiliary information and submits it to the seal center at the same time. The seal center compares the electronic handwritten signature data of the authorized seal user generated on the terminal for this time with the historical electronic handwritten signature data, and conducts a low-weight reference comparison on the comparison result of the auxiliary information. After the comparison is consistent, the authorized seal user is authorized to use it.

[0060] The label is attached with an integrity signature, and the integrity signature is signed with the private key of the seal maker. The integrity signature is one of the bases for verifying the document data.

[0061] Preferably, the public key of the seal maker in the label header is taken to verify the label integrity signature. If the verification passes, the label is trusted.

[0062] The label header, label body, and signature object summary data of the electronic seal are encrypted by the seal center, and the authorized seal user is authorized to use the electronic seal to sign, which is written into the signature object by the terminal.

[0063] Preferably, encrypted communication is used for communication between the seal center and the terminal.

Claims

1. An electronic seal based on electronic handwritten signature technology, characterized in that: manufacturing The chapter person uses the electronic handwritten signature of the seal maker to authorize the seal center to collect, store, and generate an electronic seal, and authorizes the user to use the electronic seal; The electronic seal includes a seal impression and a label including the electronic handwritten signature data of the seal maker and the seal user, where the electronic handwritten signature data of the seal user is used as the verification basis for the use permission of the electronic seal; The electronic seal generates a number for the signed object and then appends identification data to the signed object; The identification data includes the digest of the signed object and a segment of characters, which are encrypted and stored in the electronic seal to form ciphertext signed object digest data; The label is a digital entity segment, including a label header and a label body, and the seal impression includes a seal picture file; The electronic handwritten signature data of the seal maker is located in the label header, and the label header also includes the public key of the seal maker, the seal picture digest, and the creation time; the electronic handwritten signature data of the authorized seal user is located in the label body, and the label body also includes the seal type, the seal name, and the editing time; The identification data also includes the digest of the signed object after signing and the ciphertext signed object digest data encrypted twice.

2. The electronic seal based on the electronic handwritten signature technology according to claim 1, characterized in that: The label is appended with an integrity signature, and the integrity signature is signed using the private key of the seal maker.

3. The electronic seal based on the electronic handwritten signature technology according to claim 2, wherein: The public key of the authorized seal user is generated after the authorized seal user accepts the authorization invitation from the seal maker and is added to the list of public keys of the authorized seal user.

4. The electronic seal based on the electronic handwritten signature technology according to any one of claims 1-3, characterized in that: The seal impression is generated by the seal maker or an administrator authorized by the seal maker. The seal impression digest is calculated using a hashing algorithm and recorded in the label header.

5. The electronic seal based on the electronic handwritten signature technology according to claim 4, characterized in that: The electronic handwritten signature data of the seal maker and the authorized seal user also includes auxiliary information, and the collection of the auxiliary information is collected by the terminal when the seal maker applies to the seal center.

6. The electronic seal based on the electronic handwritten signature technology according to claim 5, characterized in that: The auxiliary information includes sound, fingerprint, video, and SMS verification code.

7. The electronic seal based on the electronic handwritten signature technology according to claim 6, characterized in that: When the authorized seal user applies to use the electronic seal, signs on the terminal to generate the electronic handwritten signature data of the authorized seal user for this time. The terminal also records the auxiliary information and submits it to the seal center. The seal center compares the electronic handwritten signature data of the authorized seal user generated on the terminal for this time with the historical electronic handwritten signature data, and compares the comparison results of the auxiliary information. After the comparison is consistent, the authorized seal user is authorized to use.

8. The electronic seal based on the electronic handwritten signature technology according to claim 7, characterized in that: The label header, label body, and signed object digest data of the electronic seal are encrypted by the seal center. When the authorized seal user uses the electronic seal to sign, it is written to the signed object by the terminal.

Citation Information

Patent Citations

  • Method for implementation of electronic seal and server, client and readable storage medium

    CN108206831A

  • Method for using fingerprint signature and seal

    CN102043912A

  • Electronic seal authorization using system

    CN104537525A

  • Electronic signature verifying method and device

    CN1492365A