Digital signature verification method and device, computer device and storage medium

By performing dual verification on digitally signed documents and combining watermark fragments with the signature string, the problems of easy counterfeiting and difficult identification of digital signatures are solved, thus improving the security and accuracy of digital signatures.

CN114238874BActive Publication Date: 2025-12-30SHENZHEN COMTOP INFORMATION TECH
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202111353228.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-11-16
Publication Date
2025-12-30
Estimated Expiration
2041-11-16

AI Technical Summary

Technical Problem

Existing digital signature technology is not very secure, is easy to counterfeit and difficult to identify, and the risk increases especially when it is used in electronic documents.

Method used

By obtaining the verification digest of the file to be verified, it is segmented into watermark fragments and embedded into the physical seal pattern and signature string for dual verification. This includes integrating the seal watermark and signature digest according to the arrangement of the watermark fragments, and verifying them in combination with the physical seal pattern and signature string.

Benefits of technology

It enables dual verification of digital signatures, ensuring the accuracy and security of verification results, reducing the risk of summary information being tampered with, and preventing the misuse of physical seal patterns.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114238874B_ABST
    Figure CN114238874B_ABST
Patent Text Reader

Abstract

The application relates to a digital signature verification method and device, computer equipment and a storage medium. The method comprises the following steps: when a signature verification request is received, obtaining a to-be-verified file and a verification digest of the to-be-verified file; the to-be-verified file comprises a reorganized string and a hidden reorganized seal pattern; a physical seal pattern and a first part of watermark fragments are obtained according to the hidden reorganized seal pattern, and a signature string and a second part of watermark fragments are obtained according to the reorganized string; the first part of watermark fragments and the second part of watermark fragments are integrated according to the arrangement positions of the watermark fragments, a seal watermark is obtained, and a signature digest is obtained according to the seal watermark; a verification string is determined according to the physical seal pattern and the signature digest; the signature digest is subjected to first verification according to the verification digest, and the signature string is subjected to second verification according to the verification string; if the first verification and the second verification are both passed, it is determined that the digital signature is verified. The method can improve the security of the digital signature.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of digital signature technology, and in particular to a digital signature verification method, apparatus, computer equipment, and storage medium. Background Technology

[0002] Seals can authorize the signing of important documents such as contracts and agreements. Traditionally, this involves affixing a physical seal to paper documents. However, physical seals are easily counterfeited and difficult to authenticate. With the development of digital applications, more and more paper documents are being converted into electronic documents. Using electronic seals to sign electronic documents lowers the difficulty and barrier to counterfeiting physical seals, but further increases the risks and difficulties in authenticating electronic seals.

[0003] Therefore, current digital signature technology has security issues. Summary of the Invention

[0004] Therefore, it is necessary to provide a highly secure digital signature verification method, apparatus, computer equipment, and storage medium to address the aforementioned technical problems.

[0005] A digital signature verification method, the method comprising:

[0006] When a signature verification request is received, the document to be verified and the verification digest of the document to be verified are obtained; the document to be verified contains a reorganized string and a hidden reorganized seal pattern.

[0007] Based on the hidden and reorganized seal pattern, a physical seal pattern and a first part of the watermark fragment are obtained; and based on the reorganized string, a signature string and a second part of the watermark fragment are obtained.

[0008] By integrating the first part of the watermark fragments and the second part of the watermark fragments according to their arrangement positions, a seal watermark is obtained, and a signature summary is obtained based on the seal watermark.

[0009] The verification string is determined based on the physical seal pattern and the signature digest;

[0010] The signature digest is first verified based on the verification digest, and the signature string is second verified based on the verification string;

[0011] If both the first and second verifications pass, the digital signature is deemed to have passed verification.

[0012] In one embodiment, before the step of obtaining the document to be verified and its verification digest when a signature verification request is received, the method further includes:

[0013] When a verification registration request is received, the verification username and password are saved in the list of registered verification users so that the verification terminal can log in and connect to the signature server using the verification username and password; the verification registration request includes the verification username and password.

[0014] In one embodiment, before the step of saving the verification username and login password of the verified user in the list of registered verified users when a verification registration request is received, the method further includes:

[0015] When a signature request is received, the document to be signed and a signature summary of the document to be signed are obtained; the document to be signed contains a physical seal image.

[0016] The seal watermark is obtained based on the signature summary, the seal watermark is divided into 2N watermark fragments, and the arrangement position of each watermark fragment is determined; where N≥1;

[0017] The signature string is obtained based on the signature summary and the physical seal pattern, and the current signature count is determined based on the physical seal pattern;

[0018] Based on the current number of signatures, the 2N watermark fragments are divided into a first part of watermark fragments and a second part of watermark fragments. The first part of watermark fragments is embedded into the physical seal pattern to obtain a reconstructed seal pattern. The second part of watermark fragments is embedded into the signature string to obtain a reconstructed string.

[0019] The signed document is obtained by hiding the reorganized seal pattern in the document to be signed.

[0020] In one embodiment, dividing the 2N watermark fragments into a first part of watermark fragments and a second part of watermark fragments based on the current number of signatures includes:

[0021] Obtain the average value m of the non-first digits among the current signature counts;

[0022] If the mean m is an even number, then the number of the first part of watermark fragments is determined to be N+1 / 2m, and the number of the second part of watermark fragments is determined to be N-1 / 2m.

[0023] If the mean m is odd, then the number of the first part of the watermark fragments is determined to be N-1 / 2(m-1), and the number of the second part of the watermark fragments is determined to be N+1 / 2(m-1).

[0024] In one embodiment, obtaining the signed document by hiding the reorganized seal pattern in the document to be signed includes:

[0025] The reorganizing string is overlaid on the reorganizing stamp pattern, and the reorganizing string obscures more than 2 / 3 of the reorganizing stamp pattern.

[0026] In one embodiment, before the step of obtaining the document to be signed and the signature summary of the document to be signed when a signature request is received, the method further includes:

[0027] When a signature registration request is received, the signature username and signature login password are saved in the list of registered signature users, so that the signature terminal can connect to the signature server based on the signature username and signature login password; the signature registration request includes the signature username and signature login password.

[0028] In one embodiment, the method further includes:

[0029] When the signature request is received, the feature information of the physical seal pattern and the signature authority of the signature terminal are obtained; the feature information includes the type of the physical seal pattern;

[0030] Determine whether the feature information matches the signature authorization;

[0031] If there is no match, the digital signature process is stopped.

[0032] A digital signature verification device, the device comprising:

[0033] The verification digest acquisition module is used to acquire the document to be verified and the verification digest of the document to be verified when a signature verification request is received; the document to be verified contains a reconstructed string and a hidden reconstructed seal pattern;

[0034] The signature string acquisition module is used to obtain the physical seal pattern and the first part of the watermark fragment based on the hidden and reorganized seal pattern, and to obtain the signature string and the second part of the watermark fragment based on the reorganized string.

[0035] The signature summary acquisition module is used to integrate the first part of the watermark fragments and the second part of the watermark fragments according to the arrangement position of the watermark fragments to obtain the seal watermark, and to obtain the signature summary based on the seal watermark;

[0036] The verification string acquisition module is used to determine the verification string based on the physical seal pattern and the signature digest;

[0037] The verification module is configured to perform a first verification on the signature digest based on the verification digest, and a second verification on the signature string based on the verification string;

[0038] The judgment module is used to determine that the digital signature has passed verification if both the first verification and the second verification are passed.

[0039] A computer device includes a memory and a processor, the memory storing a computer program, and the processor executing the computer program performing the following steps:

[0040] When a signature verification request is received, the document to be verified and the verification digest of the document to be verified are obtained; the document to be verified contains a reorganized string and a hidden reorganized seal pattern.

[0041] Based on the hidden and reorganized seal pattern, a physical seal pattern and a first part of the watermark fragment are obtained; and based on the reorganized string, a signature string and a second part of the watermark fragment are obtained.

[0042] By integrating the first part of the watermark fragments and the second part of the watermark fragments according to their arrangement positions, a seal watermark is obtained, and a signature summary is obtained based on the seal watermark.

[0043] The verification string is determined based on the physical seal pattern and the signature digest;

[0044] The signature digest is first verified based on the verification digest, and the signature string is second verified based on the verification string;

[0045] If both the first and second verifications pass, the digital signature is deemed to have passed verification.

[0046] A computer-readable storage medium having a computer program stored thereon, the computer program performing the following steps when executed by a processor:

[0047] When a signature verification request is received, the document to be verified and the verification digest of the document to be verified are obtained; the document to be verified contains a reorganized string and a hidden reorganized seal pattern.

[0048] Based on the hidden and reorganized seal pattern, a physical seal pattern and a first part of the watermark fragment are obtained; and based on the reorganized string, a signature string and a second part of the watermark fragment are obtained.

[0049] By integrating the first part of the watermark fragments and the second part of the watermark fragments according to their arrangement positions, a seal watermark is obtained, and a signature summary is obtained based on the seal watermark.

[0050] The verification string is determined based on the physical seal pattern and the signature digest;

[0051] The signature digest is first verified based on the verification digest, and the signature string is second verified based on the verification string;

[0052] If both the first and second verifications pass, the digital signature is deemed to have passed verification.

[0053] The aforementioned digital signature verification method, apparatus, computer equipment, and storage medium, upon receiving a signature verification request, acquire the file to be verified and its verification digest; obtain the physical seal pattern and a first watermark fragment based on the hidden and reconstructed seal pattern; obtain the signature string and a second watermark fragment based on the reconstructed string; integrate the first and second watermark fragments according to their arrangement to obtain a seal watermark; obtain the signature digest based on the seal watermark; determine the verification string based on the physical seal pattern and signature digest; perform a first verification on the signature digest based on the verification digest; and perform a second verification on the signature string based on the verification string. If both the first and second verifications pass, the digital signature is deemed verified. This dual verification based on the signature digest and signature string of the file to be verified ensures the accuracy of the digital signature verification result and improves the security of the digital signature. Attached Figure Description

[0054] Figure 1 This is a diagram illustrating the application environment of a digital signature verification method in one embodiment.

[0055] Figure 2 This is a flowchart illustrating a digital signature verification method in one embodiment;

[0056] Figure 3 This is a schematic diagram of a document to be signed containing a physical seal pattern in one embodiment;

[0057] Figure 4 This is a schematic diagram of a signed document containing a hidden physical seal pattern and a signature string in one embodiment;

[0058] Figure 5 This is a flowchart illustrating a digital signature method in one embodiment;

[0059] Figure 6 This is a flowchart illustrating a digital signature authentication method in one embodiment;

[0060] Figure 7 This is a structural block diagram of a digital signature verification device in one embodiment;

[0061] Figure 8 This is an internal structural diagram of a computer device in one embodiment. Detailed Implementation

[0062] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0063] The digital signature verification method provided in this application can be applied to, for example... Figure 1 In the application environment shown, the verification terminal 102 communicates with the signature server 104 via a network. The verification terminal 102 can be, but is not limited to, various personal computers, laptops, smartphones, tablets, and portable wearable devices. The signature server 104 can be implemented using a standalone server or a server cluster consisting of multiple servers.

[0064] In one embodiment, such as Figure 2 As shown, a digital signature verification method is provided, which can be applied to... Figure 1 Taking the signature server in China as an example, the following steps are included:

[0065] Step S210: When a signature verification request is received, obtain the document to be verified and the verification summary of the document to be verified; the document to be verified contains the reorganized string and the hidden reorganized seal pattern.

[0066] In practice, the signature server can store a list of registered and verified users. A verification terminal can send a verification registration request to the signature server, which may include the verification username and password. When the signature server receives the verification registration request, it can save the verification username and password in the list of registered and verified users. Subsequently, when the verification terminal needs to connect to the signature server, it can log in and connect using the verification username and password. Specifically, when the verification username and password entered by the verification terminal match the verification username and password stored in the list of registered and verified users, the signature server allows the verification terminal to log in and connect.

[0067] The verification terminal can also send a verification request to the signature server. The verification request may include a file to be verified containing a reconstructed string and a hidden reconstructed seal pattern. Upon receiving a verification request from the verification terminal, the signature server can obtain the file to be verified from the verification request. The verification request may also contain a verification digest of the file to be verified, which the signature server can obtain from the verification request. The verification digest can be generated based on the MD5 hash algorithm.

[0068] Step S220: Based on the hidden reorganized stamp pattern, obtain the physical stamp pattern and the first part of the watermark fragment; and based on the reorganized string, obtain the signature string and the second part of the watermark fragment.

[0069] In the specific implementation, the signature server can obtain the hidden reorganized seal pattern, and extract the physical seal pattern and a portion of watermark fragments from the hidden reorganized seal pattern as the first part of the watermark fragments; the signature server can also obtain the reorganized string, and extract the signature string and another portion of the watermark fragments from the reorganized string as the second part of the watermark fragments.

[0070] Step S230: Integrate the first part of the watermark fragments and the second part of the watermark fragments according to their arrangement positions to obtain the seal watermark, and obtain the signature summary based on the seal watermark.

[0071] Step S240: Determine the verification string based on the physical seal pattern and the signature summary.

[0072] In practice, the arrangement of watermark fragments can be preset. The signature server can obtain the arrangement of each watermark fragment, integrate the first part of the watermark fragments and the second part of the watermark fragments according to the arrangement, and obtain the seal watermark. The signature server can obtain the signature digest according to the seal watermark, and can also generate a verification string through the physical seal pattern and the signature digest.

[0073] Step S250: Perform a first verification on the signature digest based on the verification digest, and perform a second verification on the signature string based on the verification string.

[0074] Step S260: If both the first and second verifications pass, the digital signature is deemed to have passed verification.

[0075] In practice, the signature server can perform the first verification by comparing the verification digest with the signature digest, and the second verification by comparing the verification string with the signature string. If both sets of comparisons are the same, that is, the verification digest is the same as the signature digest and the verification string is the same as the signature string, then the verification can be determined to be successful.

[0076] The aforementioned digital signature verification method, upon receiving a signature verification request, obtains the file to be verified and its verification digest. It then obtains the physical seal pattern and a first watermark fragment based on the hidden and reconstructed seal pattern. The method further obtains the signature string and a second watermark fragment based on the reconstructed string. Finally, it integrates the first and second watermark fragments according to their arrangement to obtain the seal watermark. The method also obtains the signature digest based on the seal watermark, determines the verification string based on the physical seal pattern and the signature digest, performs a first verification on the signature digest, and a second verification on the signature string based on the verification string. If both verifications pass, the digital signature is deemed verified. This dual verification based on the signature digest and signature string of the file to be verified ensures the accuracy of the digital signature verification result and improves the security of the digital signature.

[0077] In one embodiment, prior to step S210, the method further includes:

[0078] Step S209: When a verification registration request is received, the verification username and verification user login password are saved in the list of registered verification users so that the verification terminal can log in and connect to the signature server based on the verification username and verification user login password; the verification registration request includes the verification username and verification user login password.

[0079] In practice, the signature server can store a list of registered and verified users. A verification terminal can send a verification registration request to the signature server, which may include the verification username and password. When the signature server receives the verification registration request, it can save the verification username and password in the list of registered and verified users. Subsequently, when the verification terminal needs to connect to the signature server, it can log in and connect using the verification username and password. Specifically, when the verification username and password entered by the verification terminal match the verification username and password stored in the list of registered and verified users, the signature server allows the verification terminal to log in and connect.

[0080] In this embodiment, by saving the verification username and password in the list of registered verification users when a verification registration request is received, only registered users can be allowed to log in to the signature server, preventing unauthorized users from logging in and ensuring the security of digital signature verification.

[0081] In one embodiment, prior to step S209, the method further includes:

[0082] Step S204: When a signature request is received, obtain the document to be signed and the signature summary of the document to be signed; the document to be signed contains a physical seal image;

[0083] Step S205: Obtain the seal watermark based on the signature summary, divide the seal watermark into 2N watermark fragments, and determine the arrangement position of each watermark fragment; where N≥1;

[0084] Step S206: Obtain the signature string based on the signature summary and the physical seal pattern, and determine the current signature count based on the physical seal pattern;

[0085] Step S207: Divide the 2N watermark fragments into a first part of watermark fragments and a second part of watermark fragments according to the current number of signatures. Embed the first part of watermark fragments into the physical seal pattern to obtain the reorganized seal pattern. Embed the second part of watermark fragments into the signature string to obtain the reorganized string.

[0086] Step S208: Obtain the signed document by hiding and rearranging the seal pattern in the document to be signed.

[0087] In practice, the signature server can store a list of registered signature users. A signature terminal can send a signature registration request to the signature server, which may include the signature username and password. When the signature server receives the registration request, it can save the username and password in the list of registered signature users. Subsequently, when the signature terminal needs to connect to the signature server, it can log in and connect using the username and password. Specifically, when the username and password entered by the signature terminal match those stored in the list of registered signature users, the signature server allows the terminal to log in and connect.

[0088] It should be noted that the signature registration request can also include the signature permissions of the signing user.

[0089] The signing terminal can also send a signing request to the signing server. The signing request may include, for example, Figure 3The document shown contains a physical seal pattern and is awaiting signature. When the signature server receives a signature request from a signature terminal, it can obtain the feature information of the physical seal pattern and the signature permissions of the signature terminal. The feature information can include the type of physical seal pattern. Taking corporate signatures as an example, the physical seals used by a company include the legal representative seal, financial seal, contract seal, company seal, and invoice seal. In actual corporate management, each of these physical seals has different legal effect and is affixed by different managers within the company. For example, financial personnel can affix the financial seal and invoice seal, while the legal representative can affix the legal representative seal and company seal. Therefore, for corporate management, different managers should have different signature permissions, meaning each signature terminal should have different signature permissions. For instance, the feature information of the physical seal pattern can include the legal representative seal, financial seal, contract seal, company seal, and invoice seal. When the user of the signature terminal is a financial personnel, the signature permission can be to use the financial seal and invoice seal.

[0090] After obtaining the feature information and signing permissions, it can be determined whether the feature information meets the signing permissions. If not, the signing will be rejected; if it does, the next step will be executed. For example, when the feature information of the physical seal pattern is a contract seal, and the signing permissions are financial seal and invoice seal, it can be determined that the feature information does not meet the signing permissions, and the signing will be rejected. Thus, after setting the signing permissions, when financial personnel log in to the corresponding signing terminal, they can only digitally sign documents with physical financial seal patterns and physical invoice seal patterns, while they cannot digitally sign documents with physical legal person seal patterns and physical official seal patterns. This ensures the accuracy and security of the overall document and physical seal patterns during the signing process.

[0091] It should be noted that the signature request may also include a signature summary of the document to be signed.

[0092] When the signature information meets the signing permissions, the signing server can obtain the signature digest of the document to be signed and generate a seal watermark based on the digest information. The signature digest can be generated based on the MD5 digest algorithm. The seal watermark is divided into 2N (N≥1) watermark fragments, and a corresponding arrangement position is loaded into each watermark fragment. For example, the arrangement position can be generated according to the order of the watermark fragments and loaded into each watermark fragment. The signing server can generate a signature string based on the signature digest and the physical seal pattern, and determine the current signing count of the physical seal based on the physical seal pattern. Based on the current signing count and a preset algorithm, the 2N watermark fragments are randomly divided into two parts. One part is embedded into the physical seal pattern at a preset position to obtain a reconstructed seal pattern, and the other part is embedded into the signature string at a preset position to obtain a reconstructed string. Afterwards, the signed document can be obtained by hiding the reconstructed seal pattern in the document to be signed.

[0093] The preset algorithm can be as follows: remove the first digit of the current signature count and take the average m of the remaining digits; when the average m is even, the number of the two parts of watermark fragments are N-1 / 2m and N+1 / 2m respectively, and embed the watermark fragments with a quantity of N+1 / 2m into the physical seal pattern; when the average m is odd, the number of the two parts of watermark fragments are N-1 / 2(m-1) and N+1 / 2(m-1) respectively, and embed the watermark fragments with a quantity of N+1 / 2(m-1) into the signature string.

[0094] When hiding the physical seal pattern on the signature server, the signature string can be overlaid on the physical seal pattern to obscure more than 2 / 3 of it. For example, it can form a pattern like... Figure 4 The state shown.

[0095] In this embodiment, when a signature request is received, the document to be signed and its signature summary are obtained. A watermark is obtained from the signature summary, and the watermark is divided into 2N watermark fragments. The arrangement position of each watermark fragment is determined. A signature string is obtained based on the signature summary and the physical seal pattern. The current signature count is determined based on the physical seal pattern. Based on the current signature count, the 2N watermark fragments are divided into a first part and a second part. The first part of the watermark fragments is embedded into the physical seal pattern to obtain a reconstructed seal pattern. The second part of the watermark fragments is embedded into the signature string to obtain a reconstructed string. By hiding the reconstructed seal pattern in the document to be signed, the signed document is obtained. This method of hidden identification can protect the physical seal pattern and effectively prevent the abuse of the physical seal pattern.

[0096] Furthermore, splitting the summary information and embedding it separately into the physical seal pattern and signature string can reduce the risk of the summary information being tampered with.

[0097] Furthermore, when specifically splitting the summary information, the distribution pattern of its watermark fragments is also combined with the number of times the current physical seal has been signed, which can further improve the security of summary information, physical seal pattern and string information.

[0098] In one embodiment, step S207 includes: obtaining the average value m of the non-first digits in the current signature count; if the average value m is even, then determining the number of the first watermark fragments as N+1 / 2m and the number of the second watermark fragments as N-1 / 2m; if the average value m is odd, then determining the number of the first watermark fragments as N-1 / 2(m-1) and the number of the second watermark fragments as N+1 / 2(m-1).

[0099] In the specific implementation, when randomly dividing 2N watermark fragments into two parts, the first digit of the current signature count can be removed, and the remaining digits can be used as non-first digits. The average of the non-first digits, m, is taken. When the average m is even, the number of watermark fragments in the two parts are N-1 / 2m and N+1 / 2m, respectively. The watermark fragments with a quantity of N+1 / 2m can be used as the first part of the watermark fragments and embedded into the physical seal pattern, and the watermark fragments with a quantity of N-1 / 2m can be used as the second part of the watermark fragments and embedded into the signature string. When the average m is odd, the number of watermark fragments in the two parts are N-1 / 2(m-1) and N+1 / 2(m-1), respectively. The watermark fragments with a quantity of N-1 / 2(m-1) can be used as the first part of the watermark fragments and embedded into the physical seal pattern, and the watermark fragments with a quantity of N+1 / 2(m-1) can be used as the second part of the watermark fragments and embedded into the signature string.

[0100] In this embodiment, by obtaining the average value m of the non-first digit in the current signature count, if the average value m is even, the number of the first watermark fragments is determined to be N+1 / 2m, and the number of the second watermark fragments is determined to be N-1 / 2m. If the average value m is odd, the number of the first watermark fragments is determined to be N-1 / 2(m-1), and the number of the second watermark fragments is determined to be N+1 / 2(m-1). By splitting the watermark fragments, the signature digest can be split, reducing the risk of signature digest being tampered with and improving the security of digital signatures.

[0101] In one embodiment, step S208 includes: covering the reorganization string on the reorganization stamp pattern and causing the reorganization string to obscure more than 2 / 3 of the reorganization stamp pattern.

[0102] In practice, when the signature server hides the physical seal pattern, the signature string can be overlaid on the physical seal pattern to obscure more than 2 / 3 of it, forming a shape like... Figure 4 The state shown.

[0103] In this embodiment, by covering the reorganization string on the reorganization stamp pattern and making the reorganization string obscure more than 2 / 3 of the reorganization stamp pattern, the physical stamp pattern can be protected, the abuse of the physical stamp pattern can be avoided, and the security of digital signature can be further improved.

[0104] In one embodiment, prior to step S204, the method further includes:

[0105] Step S203: When a signature registration request is received, the signature username and signature login password are saved in the list of registered signature users so that the signature terminal can connect to the signature server based on the signature username and signature login password; the signature registration request includes the signature username and signature login password.

[0106] In a specific implementation, the signature server can also store a list of registered signature users. A signature terminal can send a signature registration request to the signature server, which may include the signature username and password. When the signature server receives the registration request, it can save the username and password in the list of registered signature users. Subsequently, when the signature terminal needs to connect to the signature server, it can log in and connect using the username and password. Specifically, when the username and password entered by the signature terminal match those stored in the list of registered signature users, the signature server allows the signature terminal to log in and connect.

[0107] In this embodiment, by saving the signature username and signature user login password in the list of registered signature users when a signature registration request is received, only registered users can be allowed to log in to the signature server, preventing unauthorized users from logging in and ensuring the security of digital signatures.

[0108] In one embodiment, the above-mentioned digital signature verification method further includes: when a signature request is received, obtaining feature information of the physical seal pattern and the signature authority of the signature terminal; the feature information includes the type of physical seal pattern; determining whether the feature information matches the signature authority; if they do not match, stopping the digital signature process.

[0109] In practical implementation, when the signature server receives a signature request from a signature terminal, it can obtain the feature information of the physical seal pattern and the signature permissions of the signature terminal. The feature information can include the type of physical seal pattern. Taking corporate signatures as an example, the physical seals used by a company include the legal representative seal, financial seal, contract seal, company seal, and invoice seal. In actual corporate management, each of these physical seals has different legal effect and is affixed by different managers within the company. For example, financial personnel can affix the financial seal and invoice seal, while the legal representative can affix the legal representative seal and company seal. Therefore, for corporate management, different managers should have different signature permissions, meaning each signature terminal should have different signature permissions. For instance, the feature information of the physical seal pattern can include the legal representative seal, financial seal, contract seal, company seal, and invoice seal. When the user of the signature terminal is a financial personnel, the signature permission can be to use the financial seal and invoice seal.

[0110] After obtaining the feature information and signing permissions, it can be determined whether the feature information meets the signing permissions. If not, the signing will be rejected; if it does, the next step will be executed. For example, when the feature information of the physical seal pattern is a contract seal, and the signing permissions are financial seal and invoice seal, it can be determined that the feature information does not meet the signing permissions, and the signing will be rejected. Thus, after setting the signing permissions, when financial personnel log in to the corresponding signing terminal, they can only digitally sign documents with physical financial seal patterns and physical invoice seal patterns, while they cannot digitally sign documents with physical legal person seal patterns and physical official seal patterns. This ensures the accuracy and security of the overall document and physical seal patterns during the signing process.

[0111] In this embodiment, when a signature request is received, the feature information of the physical seal pattern and the signature authority of the signing terminal are obtained. It is then determined whether the feature information and the signature authority match. If they do not match, the digital signature is stopped. During the signing process, the feature information of the physical seal pattern can be used to determine whether the signing user meets the signature authority requirements. This further avoids the problem of malicious signature forgery and ensures the security of subsequent signing and verification.

[0112] To facilitate a deeper understanding of the embodiments of this application by those skilled in the art, a specific example will be used for illustration below.

[0113] Figure 5 A flowchart illustrating a digital signature method is provided. Based on... Figure 5 Digital signatures can specifically include the following steps:

[0114] A1. The signature server receives a signature registration request sent by the signature terminal, and the signature registration request includes the signature username, the signature user's login password, and the signature user's signature permissions.

[0115] A2. Based on the signature registration request, the signature server saves the signature username and signature user login password in the list of registered signature users.

[0116] A3. The signing terminal logs in and connects to the signing server using the signing username and signing user login password.

[0117] A4. The signature server receives the signature request sent by the signature terminal, and the signature request includes, for example: Figure 3 The document shown contains a physical seal pattern and is awaiting signature.

[0118] A5. The signature server obtains the feature information of the physical seal pattern and the signature permissions of the signature terminals. Specifically, the feature information includes the type of physical seal pattern. Taking corporate signatures as an example: the physical seals used by a company include the legal representative seal, financial seal, contract seal, company seal, and invoice seal. In actual corporate management, each of these physical seals has different legal effects and is affixed by different managers within the company. For example, financial personnel can affix the financial seal and invoice seal, etc., while the legal representative of the company can affix the legal representative seal and company seal, etc. Therefore, in terms of corporate management, different managers should be assigned different signature permissions. In this invention, this means that each signature terminal has different signature permissions.

[0119] A6. Determine if the feature information meets the signing permissions. If not, refuse the signing; otherwise, proceed to step A7. As shown above, after setting signing permissions, finance personnel logging into the corresponding signing terminal can only digitally sign documents containing physical financial seal or physical invoice seal patterns. Documents containing physical legal representative seal or physical company seal patterns cannot be digitally signed. This ensures the accuracy and security of the overall document and physical seal patterns during the signing process.

[0120] A7. The signature server obtains the signature digest of the document to be signed and generates a seal watermark based on the digest information; specifically, the signature digest is generated based on the MD5 digest algorithm.

[0121] A8. Divide the seal watermark into 2N watermark fragments, and load the corresponding arrangement position in each watermark fragment, where N≥1.

[0122] A9. The signature server generates a signature string based on the signature digest and the physical seal pattern, and determines the current signature count of the physical seal based on the physical seal pattern.

[0123] A10. Based on the current number of signatures and the preset algorithm, randomly divide the 2N watermark fragments into two parts. One part is embedded into the physical seal pattern at a preset position to obtain the reconstructed seal pattern, and the other part is embedded into the signature string at a preset position to obtain the reconstructed string.

[0124] The above-mentioned preset algorithm is as follows: remove the first digit of the current signature count and take the average m of the remaining digits; when the average m is even, the number of the two parts of watermark fragments are N-1 / 2m and N+1 / 2m respectively, and the watermark fragments with a number of N+1 / 2m are embedded into the physical seal pattern; when the average m is odd, the number of the two parts of watermark fragments are N-1 / 2(m-1) and N+1 / 2(m-1) respectively, and the watermark fragments with a number of N+1 / 2(m-1) are embedded into the signature string.

[0125] A11. Hide and rearrange the stamp pattern to obtain the signed document.

[0126] Specifically, when the signature server hides the physical seal pattern, the signature string is overlaid on the physical seal pattern to obscure more than 2 / 3 of it, thus forming... Figure 4 The state shown.

[0127] Figure 6 A flowchart illustrating a digital signature authentication method is provided. Based on... Figure 6 Digital signature authentication may include the following steps:

[0128] B1. The signature server receives the verification registration request sent by the verification terminal, and the verification registration request includes the verification username and the verification user login password.

[0129] B2. Based on the verification registration request, the signature server saves the verification username and the verification user's login password in the list of registered verification users.

[0130] B3. The verification terminal logs in and connects to the signature server by verifying the username and password.

[0131] B4. The signature server receives the verification request sent by the verification terminal, and the verification request includes the file to be verified containing the reorganized string and the hidden reorganized seal pattern.

[0132] B5. The signature server obtains the verification digest of the document to be verified.

[0133] B6. The signature server obtains the hidden reorganized seal pattern and extracts the physical seal pattern and a portion of the watermark fragments from the hidden reorganized seal pattern.

[0134] B7. The signature server obtains the reconstructed string and extracts the signature string and another watermark fragment from the reconstructed string.

[0135] B8. Obtain the arrangement position of each watermark fragment, and integrate the two watermark fragments according to the arrangement position to obtain the stamp watermark.

[0136] B9. The signature server obtains the signature digest based on the seal watermark and generates a verification string using the physical seal pattern and the signature digest.

[0137] B10. Compare the verification digest with the signature digest and the verification string with the signature string, and pass the verification if both sets of comparisons are the same.

[0138] During the transmission of signed documents and the overall verification process, the physical seal pattern is hidden, which effectively prevents the leakage of the physical seal pattern. Moreover, the use of hidden identification to protect the physical seal pattern can effectively prevent the abuse of the physical seal pattern.

[0139] Furthermore, by comparing the signature string and the verification string, it is possible to effectively verify whether the signed document and the physical seal pattern have been tampered with. Dual verification based on the document's digest information and string information effectively ensures the accuracy and security of the verification. Specifically, the digest information is split and embedded separately into the physical seal pattern and the signature string, further reducing the risk of digest information tampering. Moreover, the watermark fragment distribution pattern during digest information splitting is combined with the current number of times the physical seal has been signed, thereby further enhancing the security of the digest information, physical seal pattern, and string information.

[0140] In addition, during the signing process, the system determines whether the user has the necessary signing permissions based on the characteristics of the physical seal pattern. This further prevents the problem of maliciously counterfeiting signatures and ensures the security of subsequent signing and verification.

[0141] It should be understood that, although Figure 2 , 5 The steps in flowchart 6 are shown sequentially as indicated by the arrows, but these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order in which these steps are performed; they can be executed in other orders. Furthermore, Figure 2 , 5 At least some of the steps in 6 may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but may be executed at different times. The execution order of these steps or stages is not necessarily sequential, but may be executed in turn or alternately with other steps or at least some of the steps or stages in other steps.

[0142] In one embodiment, such as Figure 7 As shown, a digital signature verification device is provided, including: a verification digest acquisition module 710, a signature string acquisition module 720, a signature digest acquisition module 730, a verification string acquisition module 740, a verification module 750, and a judgment module 760, wherein:

[0143] The verification digest acquisition module 710 is used to acquire the document to be verified and the verification digest of the document to be verified when a signature verification request is received; the document to be verified contains a reorganized string and a hidden reorganized seal pattern;

[0144] The signature string acquisition module 720 is used to obtain the physical seal pattern and the first part of the watermark fragment based on the hidden and reorganized seal pattern, and to obtain the signature string and the second part of the watermark fragment based on the reorganized string.

[0145] The signature summary acquisition module 730 is used to integrate the first part of the watermark fragments and the second part of the watermark fragments according to the arrangement position of the watermark fragments to obtain the seal watermark, and to obtain the signature summary according to the seal watermark.

[0146] The verification string acquisition module 740 is used to determine the verification string based on the physical seal pattern and the signature summary;

[0147] The verification module 750 is configured to perform a first verification on the signature digest based on the verification digest, and a second verification on the signature string based on the verification string;

[0148] The judgment module 760 is used to determine that the digital signature has passed verification if both the first verification and the second verification are passed.

[0149] In one embodiment, the digital signature verification device further includes:

[0150] The verification and registration module is used to save the verification username and password in the list of registered verification users when a verification and registration request is received, so that the verification terminal can log in and connect to the signature server according to the verification username and password; the verification and registration request includes the verification username and password.

[0151] In one embodiment, the digital signature verification device further includes:

[0152] The signature summary acquisition module is used to acquire the document to be signed and the signature summary of the document to be signed when a signature request is received; the document to be signed contains a physical seal pattern;

[0153] The seal watermark segmentation module is used to obtain the seal watermark based on the signature summary, segment the seal watermark into 2N watermark fragments, and determine the arrangement position of each watermark fragment; where N≥1;

[0154] The signature count acquisition module is used to obtain the signature string based on the signature summary and the physical seal pattern, and to determine the current signature count based on the physical seal pattern;

[0155] The watermark fragment embedding module is used to divide the 2N watermark fragments into a first part of watermark fragments and a second part of watermark fragments according to the current number of signatures, and to embed the first part of watermark fragments into the physical seal pattern to obtain a reconstructed seal pattern, and to embed the second part of watermark fragments into the signature string to obtain a reconstructed string;

[0156] The signing module is used to obtain a signed document by hiding the reorganized seal pattern in the document to be signed.

[0157] In one embodiment, the watermark fragment embedding module is further configured to obtain the average value m of the non-first digits in the current signature count; if the average value m is even, the number of the first part of watermark fragments is determined to be N+1 / 2m, and the number of the second part of watermark fragments is determined to be N-1 / 2m; if the average value m is odd, the number of the first part of watermark fragments is determined to be N-1 / 2(m-1), and the number of the second part of watermark fragments is determined to be N+1 / 2(m-1).

[0158] In one embodiment, the aforementioned signature module is further configured to cover the reorganized string on the reorganized stamp pattern, and to make the reorganized string obscure more than 2 / 3 of the reorganized stamp pattern.

[0159] In one embodiment, the digital signature verification device further includes:

[0160] The signature registration module is used to save the signature username and signature user login password in the list of registered signature users when a signature registration request is received, so that the signature terminal can connect to the signature server according to the signature username and signature user login password; the signature registration request includes the signature username and signature user login password.

[0161] In one embodiment, the digital signature verification device further includes:

[0162] The permission acquisition module is used to acquire the feature information of the physical seal pattern and the signing permission of the signing terminal when the signing request is received; the feature information includes the type of the physical seal pattern;

[0163] The judgment module is used to determine whether the feature information matches the signature authority;

[0164] The stop signing module is used to stop the digital signing process if there is a mismatch.

[0165] Specific limitations regarding the digital signature verification device can be found in the limitations of the digital signature verification method above, and will not be repeated here. Each module in the aforementioned digital signature verification device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in the processor of the computer device in hardware form or independent of it, or stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to each module.

[0166] In one embodiment, a computer device is provided, which may be a server, and its internal structure diagram may be as follows: Figure 8 As shown, the computer device includes a processor, memory, and a network interface connected via a system bus. The processor provides computing and control capabilities. The memory includes a non-volatile storage medium and internal memory. The non-volatile storage medium stores an operating system, computer programs, and a database. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage medium. The database stores digital signature verification data. The network interface communicates with external terminals via a network connection. When executed by the processor, the computer program implements a digital signature verification method.

[0167] Those skilled in the art will understand that Figure 8 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0168] In one embodiment, a computer device is provided, including a memory and a processor. The memory stores a computer program, which, when executed by the processor, causes the processor to perform the steps of the digital signature verification method described above. The steps of the digital signature verification method described here may be steps from one of the digital signature verification methods in the various embodiments described above.

[0169] In one embodiment, a computer-readable storage medium is provided, storing a computer program that, when executed by a processor, causes the processor to perform the steps of the digital signature verification method described above. The steps of the digital signature verification method described here may be steps from one of the digital signature verification methods in the various embodiments described above.

[0170] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the methods described above. Any references to memory, storage, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, or optical storage, etc. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc.

[0171] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0172] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the invention patent. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this patent application should be determined by the appended claims.

Claims

1. A method of verifying a digital signature, characterized by, The method comprises: When receiving a signature request, obtaining a to-be-signed file and a signature digest of the to-be-signed file; the to-be-signed file contains a physical seal pattern; According to the signature digest, a seal watermark is obtained, the seal watermark is divided into 2N watermark fragments, and the arrangement position of each watermark fragment is determined; wherein N≥1; According to the signature digest and the physical seal pattern, a signature string is obtained, and according to the physical seal pattern, a current signature number is determined; According to the current signature number, the 2N watermark fragments are divided into a first part of watermark fragments and a second part of watermark fragments, the first part of watermark fragments is embedded into the physical seal pattern to obtain a reorganized seal pattern, and the second part of watermark fragments is embedded into the signature string to obtain a reorganized string; By hiding the reorganized seal pattern in the to-be-signed file, a signed file is obtained; When receiving a signature verification request, obtaining a to-be-verified file and a verification digest of the to-be-verified file; the to-be-verified file contains a reorganized string and a hidden reorganized seal pattern; According to the hidden reorganized seal pattern, a physical seal pattern and a first part of watermark fragments are obtained, and according to the reorganized string, a signature string and a second part of watermark fragments are obtained; According to the watermark fragment arrangement position, the first part of watermark fragments and the second part of watermark fragments are integrated to obtain a seal watermark, and according to the seal watermark, a signature digest is obtained; According to the physical seal pattern and the signature digest, a verification string is determined; According to the verification digest, a first verification of the signature digest is performed, and according to the verification string, a second verification of the signature string is performed; If the first verification and the second verification are both passed, it is determined that the digital signature passes the verification.

2. The method of claim 1, wherein, Before the step of obtaining a to-be-verified file and a verification digest of the to-be-verified file when receiving a signature verification request, the method further comprises: When receiving a verification registration request, saving a verification user name and a verification user login password in a registered verification user list, so that a verification terminal logs in and connects a signature server according to the verification user name and the verification user login password; the verification registration request contains the verification user name and the verification user login password.

3. The method of claim 1, wherein, The step of dividing the 2N watermark fragments into a first part of watermark fragments and a second part of watermark fragments according to the current signature number comprises: Obtaining the average value m of non-first digits in the current signature number; If the average value m is even, the number of the first part of watermark fragments is determined as N+1 / 2m, and the number of the second part of watermark fragments is determined as N-1 / 2m; If the average value m is odd, the number of the first part of watermark fragments is determined as N-1 / 2(m-1), and the number of the second part of watermark fragments is determined as N+1 / 2(m-1).

4. The method of claim 1, wherein, The step of obtaining a signed file by hiding the reorganized seal pattern in the to-be-signed file comprises: Covering the reorganized string on the reorganized seal pattern, and making the reorganized string block more than 2 / 3 of the reorganized seal pattern.

5. The method of claim 1, wherein, The step of obtaining the to-be-sealed file and the sealing abstract of the to-be-sealed file when receiving the sealing request further comprises: When receiving a sealing registration request, saving a sealing user name and a sealing user login password in a registered sealing user list, so that a sealing terminal connects a sealing server according to the sealing user name and the sealing user login password; the sealing registration request comprises the sealing user name and the sealing user login password.

6. The method of claim 1, wherein, The method further comprises: When receiving the sealing request, obtaining feature information of the physical seal pattern and a sealing permission of a sealing terminal; the feature information comprises a type of the physical seal pattern; Determining whether the feature information matches the sealing permission; If not, stopping the digital sealing.

7. A digital signature verification apparatus characterized by comprising: The device comprises: A sealing abstract obtaining module, configured to obtain a to-be-sealed file and a sealing abstract of the to-be-sealed file when receiving a sealing request; the to-be-sealed file comprises a physical seal pattern; A seal watermark segmentation module, configured to obtain a seal watermark according to the sealing abstract, segment the seal watermark into 2N watermark fragments, and determine an arrangement position of each watermark fragment; wherein N≥1; A sealing number of times obtaining module, configured to obtain a sealing string according to the sealing abstract and the physical seal pattern, and determine a current sealing number of times according to the physical seal pattern; A watermark fragment embedding module, configured to divide the 2N watermark fragments into a first part of watermark fragments and a second part of watermark fragments according to the current sealing number of times, embed the first part of watermark fragments into the physical seal pattern to obtain a reorganized seal pattern, and embed the second part of watermark fragments into the sealing string to obtain a reorganized string; A sealing module, configured to obtain a sealed file by hiding the reorganized seal pattern in the to-be-sealed file; A verification abstract obtaining module, configured to obtain a to-be-verified file and a verification abstract of the to-be-verified file when receiving a sealing verification request; the to-be-verified file comprises a reorganized string and a hidden reorganized seal pattern; A sealing string obtaining module, configured to obtain a physical seal pattern and a first part of watermark fragments according to the hidden reorganized seal pattern, and obtain a sealing string and a second part of watermark fragments according to the reorganized string; A sealing abstract obtaining module, configured to integrate the first part of watermark fragments and the second part of watermark fragments according to the arrangement position of the watermark fragments to obtain a seal watermark, and obtain a sealing abstract according to the seal watermark; A verification string obtaining module, configured to determine a verification string according to the physical seal pattern and the sealing abstract; A verification module, configured to perform a first verification on the sealing abstract according to the verification abstract, and perform a second verification on the sealing string according to the verification string; A judging module, configured to determine that the digital sealing passes the verification if both the first verification and the second verification pass.

8. The apparatus of claim 7, wherein, The device further comprises: The authentication registration module is configured to, when receiving an authentication registration request, save an authentication user name and an authentication user login password in a registered authentication user list, so that an authentication terminal logs in and connects to a signature server according to the authentication user name and the authentication user login password. 9.A computer device, comprising a memory and a processor, wherein the memory stores a computer program, and the computer device is configured to perform the method according to any one of claims 1-8 when the computer program is executed by the processor. The computer program, when executed by the processor, implements the steps of the method of any one of claims 1 to 6.

10. A computer-readable storage medium having stored thereon a computer program, characterized in that, The computer program, when executed by the processor, implements the steps of the method of any one of claims 1 to 6.

Citation Information

Patent Citations

  • Double authentication-based word document electronic seal system and method

    CN101894238A

  • Identifying method and system of digital signature and seal

    CN102647423A

  • Electronic evidence preservation method based on threshold digital signature

    CN102855425A