Authentication method, terminal, signature pen and system

By introducing the first signature module and the second signature module in the handwritten signature authentication system, the signature data is used to calculate the signature data using the key, and the signature information is sent to the authentication server for verification, the problem of insufficient security in the existing handwritten signature technology is solved, and the security and credibility of signature authentication are improved.

CN114528533BActive Publication Date: 2025-05-16HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202011196096.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-10-31
Publication Date
2025-05-16
Estimated Expiration
2040-10-31

AI Technical Summary

Technical Problem

The existing handwritten signature authentication technology has insufficient security. Attackers can use the obtained user handwritten signature template data to forge signatures, illegally obtain user privacy data, and threaten the security of user property.

Method used

An authentication method is adopted to obtain confidential data and handwritten signature related data through the service module, calculate the data to be signed, and send it to the first signature module and the second signature module. These modules use the first key and the second key respectively generated to perform signature calculation on the signature data, and generate the first signature information and the second signature information. Then, the business module sends these signature information to the authentication server for authentication to ensure the authenticity and security of handwritten signatures.

Benefits of technology

Through this method, it is ensured that the input device of handwritten signature handwriting is safe and trustworthy. The input user is a legal user, and the handwritten signature handwriting is a legal signature information of the legal user, thereby improving the security of handwritten signatures and the credibility of the certification results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114528533B_ABST
    Figure CN114528533B_ABST
Patent Text Reader

Abstract

The present application provides an authentication method, terminal, signature pen and system, which can improve the security of handwritten signature authentication. The method combines handwritten signature with digital signature. After the signature pen obtains the data to be signed corresponding to the data information of the handwritten signature of the user, the signature pen uses the second key related to the user identity to digitally sign the data to be signed corresponding to the data information of the handwritten signature, and then sends the generated second signature information to the terminal. The terminal uses the first key corresponding to the device identification to digitally sign the data to be signed, and then sends the generated first signature information, the second signature information, and the relevant data of the handwritten signature to the authentication server for authentication. When all authentications are passed, it can be ensured that the input device of the handwritten signature handwriting is a safe and reliable device, the input user is a legal user, and the handwritten signature handwriting is also the legal signature information of the legal user, thereby improving the security of the handwritten signature.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of terminal technology, and in particular to an authentication method, a terminal, a signature pen and a system. Background Art

[0002] The pen signature technology has become an important technology for confirming the user's identity in the virtual environment of the network system. The pen signature technology refers to the user using a pen to input a handwritten signature on the touch panel of the terminal for signature authentication. The terminal obtains the relevant data of the handwritten signature through the touch panel and sensor, and compares it with the handwritten signature template data to identify the authenticity of the handwritten signature. Among them, the relevant data of the handwritten signature may include the image of the handwritten signature and the pressure of the pen on the touch panel and other information.

[0003] At present, when an attacker illegally obtains the user's handwritten signature template data, he may use the handwritten signature template data to forge the user's handwritten signature, thereby illegally passing the handwritten signature authentication. When the attacker passes the illegal authentication, he can illegally obtain the user's private data, thereby threatening the user's property safety. It can be seen that the current handwritten signature authentication method still has the problem of insufficient security. Summary of the invention

[0004] The present application provides an authentication method, terminal, signature pen and system for solving the problem of insufficient security of current handwritten signature technology.

[0005] In a first aspect, an embodiment of the present application provides an authentication method, which can be applied to a terminal including a business module, and the method includes: the business module obtains confidential data and relevant data of a handwritten signature; then the business module calculates the confidential data and relevant data of the handwritten signature to obtain data to be signed; the business module sends the data to be signed to a first signature module and a second signature module, wherein the first signature module is used to use a first key to sign the data to be signed to obtain first signature information, and the second signature module is used to use a second key to sign the data to be signed to obtain second signature information; the business module obtains the first signature information and the second signature information from the first signature module and the second signature module; the business module sends an authentication request message to an authentication server, the authentication request message includes confidential data and relevant data of a handwritten signature, the first signature information and the second signature information; the business module receives an authentication response message from the authentication server, the authentication response message is used to indicate the authentication result of the authentication server authenticating the handwritten signature based on the confidential data and relevant data of the handwritten signature, the first signature information and the second signature information.

[0006] In another possible scenario, the above-mentioned business module may also send confidential data and handwritten signature related data, first signature information and second signature information to the business modules of other terminals. The business modules of other terminals send authentication request messages to the authentication server, so that the business modules of other terminals obtain authentication results.

[0007] In the embodiment of the present application, confidential data and handwritten signature related data, first signature information and second signature information are used. When all are authenticated, it can be ensured that the input device of the handwritten signature handwriting is a safe and reliable device, the input user is a legitimate user, and the handwritten signature handwriting is also the legitimate signature information of the legitimate user, thereby improving the security of the handwritten signature.

[0008] In a possible design, the first signature module, the second signature module and the business module are all in the same terminal device. That is, the embodiment of the present application is applicable to the scenario where the first signature information and the second signature information can be generated on the same terminal, and the user can successfully complete the handwritten signature through one terminal, and the legitimacy of the signature result can be guaranteed.

[0009] In a possible design, the method also includes: the first signature module obtains the device identification of the device used by the user's handwritten signature, and generates a first key based on the device identification; the first signature module uses the first key to perform a signature calculation on the data to be signed to obtain first signature information; the second signature module obtains the user's identity identification, and generates a second key based on the user's identity identification; the second signature module uses the second key to perform a signature calculation on the data to be signed to obtain second signature information.

[0010] In the embodiment of the present application, the terminal can bind the handwritten signature data to the signature information of the device that inputs the handwritten signature and the signature information of the user who inputs the handwritten signature in the above manner during the handwritten signature process, thereby ensuring the legitimacy of the signature result.

[0011] In one possible design, the second signature module uses the second key to perform a signature calculation on the data to be signed to obtain the second signature information, including: the second signature module uses the user's identity identifier to verify the user's identity; when the verification is passed, the second signature module uses the second key to perform a signature calculation on the data to be signed to obtain the second signature information. In this method, the handwritten signature data is bound to the signature information of the user who inputs the handwritten signature.

[0012] In a possible design, the first signature module and the business module are in the same terminal device, and the second signature module is in a signature pen. This method can be applied to the scenario where a user uses a dedicated signature pen to sign on an electronic device, which improves the convenience of handwritten signatures and can ensure the legitimacy of handwritten signature results.

[0013] In a possible design, the business module is a trusted application that has been authorized by the trusted execution environment.

[0014] In one possible design, the business module generates a signature-containing document including confidential data and handwritten signature-related data, and displays the signature-containing document on a display screen. This method helps users view the signature results, and can achieve the binding of the electronic document to be signed and the handwritten signature data, so as to facilitate the subsequent generation of the first signature information and the second signature information.

[0015] In a possible design, the pen for inputting handwritten signatures includes a device switch; the method further includes: when the device switch is turned on, the terminal establishes a communication connection with the pen. The method helps to improve the security of handwritten signatures and helps to reduce the power consumption of handwritten signatures.

[0016] In a second aspect, an embodiment of the present application provides a terminal, comprising a processor and a memory, wherein the memory is used to store one or more computer programs; when the one or more computer programs stored in the memory are executed by the processor, the first electronic device is able to implement any possible design method of the first aspect above.

[0017] In a third aspect, an embodiment of the present application further provides a device, which includes a module / unit for executing any possible design method of the first aspect. These modules / units can be implemented by hardware, or by executing corresponding software implementations by hardware.

[0018] In a fourth aspect, an embodiment of the present application provides a signature pen, comprising: a sensor unit, a processor, and a communication unit;

[0019] The sensor unit is used to detect the motion track information and pressure information of the signature pen when the user signs on the touch panel of the terminal with the signature pen;

[0020] The processor is configured to use the second key in the second signature module to perform signature calculation on the data to be signed from the terminal to obtain second signature information;

[0021] The second signature information is sent to the terminal through the communication unit.

[0022] In the embodiment of the present application, the method can be applicable to the scenario where the user uses a dedicated signature pen to sign on an electronic device, thereby improving the convenience of handwritten signatures and ensuring the legitimacy of the handwritten signature results.

[0023] In a fifth aspect, an embodiment of the present application further provides a device, which includes a module / unit for executing any possible design method of the fourth aspect above. These modules / units can be implemented by hardware, or by executing corresponding software implementations by hardware.

[0024] In a sixth aspect, an embodiment of the present application also provides a signature authentication system, comprising a terminal as in the second aspect, and a signature pen as in the fifth aspect.

[0025] In the seventh aspect, an embodiment of the present application also provides a computer-readable storage medium, wherein the computer-readable storage medium includes computer program instructions. When the computer program instructions are executed on a terminal, the terminal executes any possible design method of the first aspect mentioned above.

[0026] In an eighth aspect, an embodiment of the present application further provides a method comprising a computer program product, which, when executed on a terminal, enables the terminal to execute any possible design of the first aspect.

[0027] In the ninth aspect, an embodiment of the present application further provides a chip, which is coupled to a memory and is used to execute a computer program stored in the memory to execute any possible design method of any of the above aspects.

[0028] For the technical effects that can be achieved by the various designs in any of the second to ninth aspects above, please refer to the description of the technical effects that can be achieved by the various designs in the first aspect above, and no further details will be given here. BRIEF DESCRIPTION OF THE DRAWINGS

[0029] Figure 1 A schematic diagram of a communication scenario provided in an embodiment of the present application;

[0030] Figure 2 A schematic diagram of the structure of a signature pen provided in an embodiment of the present application;

[0031] Figure 3 A schematic diagram of a terminal hardware structure provided in an embodiment of the present application;

[0032] Figure 4 A schematic diagram of a terminal software structure provided in an embodiment of the present application;

[0033] Figure 5A A schematic diagram of an interactive method for handwritten signature authentication provided in an embodiment of the present application;

[0034] Figure 5B Another interactive diagram of a handwritten signature authentication method provided in an embodiment of the present application;

[0035] Figure 6 A set of interface schematic diagrams provided for embodiments of the present application;

[0036] Figure 7 A schematic diagram of an interface provided for an embodiment of the present application;

[0037] Fig. 8A A schematic diagram of a handwritten signature scenario provided in an embodiment of the present application;

[0038] Figure 8B Another interactive diagram of a handwritten signature authentication method provided in an embodiment of the present application;

[0039] 9A to 9C Another set of interface schematic diagrams provided for embodiments of the present application;

[0040] Fig.10 A schematic diagram of an interface provided for an embodiment of the present application;

[0041] Fig.11 A schematic diagram of another handwritten signature method flow chart provided in an embodiment of the present application;

[0042] Fig.12 A schematic diagram of a first device structure provided in an embodiment of the present application;

[0043] Fig.13 A schematic diagram of a second device and the structure of the second device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0044] Below, some terms in the embodiments of the present application are explained to facilitate understanding by those skilled in the art.

[0045] 1) The APP involved in the embodiments of the present application, referred to as application, is a software program that can realize one or more specific functions. Usually, multiple applications can be installed in a terminal device. For example, a signature application, a camera application, a mailbox application, etc. The signature application in the embodiments of the present application refers to an application that supports users to handwrite signatures on electronic files opened in the application.

[0046] 2) Trusted execution environment (TEE) is an isolated execution environment. TEE runs in parallel with rich execution environment (REE) and provides security services for REE. It can achieve isolated access and protection for software and hardware security resources and applications under REE.

[0047] The software and hardware resources accessible by TEE are separated from REE. TEE provides a secure execution environment for authorized security software (trusted application (TA)), while also protecting the confidentiality, integrity and access rights of the resources and data of trusted applications.

[0048] A security element (SE) can be a security module that combines software, hardware and related protocols, and can be embedded in smart card-level applications, such as embedded SE, pluggable memory card, etc. Trusted application (TA) and Applet are programs running in SE.

[0049] 3) Digital signature refers to the use of a key to encrypt data to ensure the authenticity of electronic documents or messages in digital communications. Digital signatures are often used in e-commerce, software distribution, financial transactions and other situations that rely on forgery or tampering detection technology.

[0050] 4) Handwritten signature refers to the user entering a handwritten signature on the touch panel of the terminal through a signature pen or finger for signature authentication. The terminal obtains the relevant data of the handwritten signature through the touch panel and sensor, and compares it with the handwritten signature template data to identify the authenticity of the handwritten signature.

[0051] The technical solutions in the embodiments of the present application will be described below in conjunction with the drawings in the embodiments of the present application. In the description of the embodiments of the present application, the terms "first" and "second" are used for descriptive purposes only and cannot be understood as indicating or implying relative importance or implicitly indicating the number of technical features indicated. Thus, the features defined as "first" and "second" may explicitly or implicitly include one or more of the features. In the description of the embodiments of the present application, unless otherwise specified, "multiple" means two or more.

[0052] The authentication method provided in the embodiment of the present application can be applied to Figure 1 The multiple devices shown are interconnected based on a communication network. Figure 1 In the scenario shown, the signature pen 200, the terminal 100 and the authentication server 300 can exchange data through the communication network, such as interactive pictures, electronic files, and data related to handwritten signatures.

[0053] In the embodiment of the present application, after the terminal 100 obtains the relevant data of the handwritten signature input by the user using the signature pen 200, for example, Figure 1The terminal 100 obtains the image information of the name signed by the user with the signature pen and the pressure of the signature pen on the touch panel. The terminal 100 combines the relevant data of the handwritten signature with the signed electronic file to obtain a signed file. The trusted application in the terminal 100 then performs a device digital signature on the hash value of the signed file (such as using the device ID of the terminal 100 to digitally sign the signed file), and performs a user identity digital signature on the hash value of the signed file (such as using the user ID to digitally sign the signed file). The terminal 100 sends the device digital signature, identity digital signature, and the signed file after the signature is calculated to the authentication server 300 (or other verification device). The server 300 verifies the device digital signature, identity digital signature, and the signed file after the signature is calculated. When all verifications are passed, it confirms that the user's handwritten signature is credible.

[0054] Exemplarily, the method provided in the embodiment of the present application can be applied to electronic document signing in banking or e-commerce. It should be noted that the signature pen 200 in the embodiment of the present application can also be replaced by other devices with handwriting function.

[0055] The communication network may be a local area network, or a wide area network transferred through a relay device, or a network composed of a local area network and a wide area network. When the communication network is a local area network, exemplarily, the communication network may be a short-distance communication network such as a wifi hotspot network, a wifi P2P network, a Bluetooth network, a zigbee network, or a near field communication (NFC) network. When the communication network is a wide area network, exemplarily, the communication network may be a third-generation wireless telephone technology (3G) network, a fourth-generation mobile communication technology (4G) network, a fifth-generation mobile communication technology (5G) network, a future-evolved public land mobile network (PLMN) or the Internet, etc.

[0056] See also Figure 2 , is a structural diagram of a signature pen 200 provided in an embodiment of the present application, which mainly includes: a processor 201, a memory 202 and a wireless communication module 203.

[0057] The memory 202 generally includes internal memory and external memory. The internal memory may be random access memory (RAM), double data rate random access memory (DDR RAM), read only memory (ROM) or cache memory (CACHE), etc. The external memory may be a hard disk, an optical disk, a universal serial bus (USB), a flash memory (FLASH), a floppy disk or a tape drive, etc. The memory 202 is used to store computer programs (including various firmware, operating systems, etc.) and relevant data of handwritten signatures input by users, etc.

[0058] The processor 201 is used to read the computer program in the memory 202 and then execute the computer program. Optionally, the processor 201 may include one or more general-purpose processors, and may also include one or more digital signal processors (DSPs) to perform related operations to implement the authentication method provided in the embodiment of the present application.

[0059] The wireless communication module 203 can send and receive information through wireless communication networks of various formats, including but not limited to wireless local area networks (WLAN), wireless fidelity (Wi-Fi) networks, Bluetooth (BT) networks, global navigation satellite systems (GNSS), frequency modulation (FM) systems, near field communication (NFC) systems, infrared (IR) technology, etc. The wireless communication module 203 can be one or more devices integrating at least one communication processing module. The wireless communication module 203 receives electromagnetic waves via an antenna, modulates and filters the electromagnetic wave signals, and sends the processed signals to the processor 201. The wireless communication module 203 can also receive the signal to be sent from the processor 201, modulate the frequency, amplify it, and convert it into electromagnetic waves for radiation through the antenna. In an embodiment of the present application, the wireless communication module 203 may be a Bluetooth module. For example, the signature pen 200 receives the hash value of the signature file sent by the terminal 100 through the wireless communication module 203; or the signature pen 200 sends the second signature information, such as user identity signature data, to the terminal 100 through the wireless communication module 203.

[0060] Optionally, the signature pen may further include: a sensor, a power supply, an antenna, etc. In the embodiment of the present application, the sensor may be a pressure sensor, and the pressure sensor may detect the pressure exerted by the signature pen 200 on the touch panel of the terminal 100 .

[0061] It is to be understood that the structure shown in the embodiment of the present application does not constitute a specific limitation on the signature pen 200. Figure 2 More or fewer components shown in the figure may be combined with two or more components, or may have different component configurations. For example, the signature pen 200 may also include components such as a switch, an indicator light (which may indicate the power level or working status of the signature pen 200 ), and the like. Figure 2 The various components shown in the drawings may be implemented in hardware, software, or a combination of hardware and software, including one or more signal processing or application specific integrated circuits.

[0062] The terminal in the embodiment of the present application can be a mobile phone, a tablet computer, a computer with wireless transceiver function, a virtual reality (VR) device, an augmented reality (AR) device, a wireless device in industrial control, a wireless device in self-driving, a wireless device in remote medical, a wireless device in smart grid, a wireless device in transportation safety, a wireless device in smart city, a wireless device in smart home, etc. See Figure 3 , is a schematic diagram of the hardware structure of a terminal 100 provided in an embodiment of the present application.

[0063] The terminal 100 may include a processor 310, an external memory interface 320, an internal memory 321, a universal serial bus (USB) interface 330, a charging management module 340, a power management module 341, a battery 342, an antenna 1, an antenna 2, a mobile communication module 350, a wireless communication module 360, an audio module 370, a speaker 370A, a receiver 370B, a microphone 370C, an earphone interface 370D, a sensor module 380, a button 390, a motor 391, an indicator 392, a camera 393, a display screen 394, and a subscriber identification module (SIM) card interface 395, etc. The sensor module 380 may include a pressure sensor 380A, a gyroscope sensor 380B, an air pressure sensor 380C, a magnetic sensor 380D, an acceleration sensor 380E, a distance sensor 380F, a proximity light sensor 380G, a fingerprint sensor 380H, a temperature sensor 380J, a touch sensor 380K, an ambient light sensor 380L, a bone conduction sensor 380M, and the like.

[0064] It is to be understood that the structure illustrated in the embodiment of the present application does not constitute a specific limitation on the terminal 100. In other embodiments of the present application, the terminal 100 may include more or fewer components than shown in the figure, or combine certain components, or split certain components, or arrange the components differently. The components shown in the figure may be implemented in hardware, software, or a combination of software and hardware.

[0065] The processor 310 may include one or more processing units, for example, the processor 310 may include an application processor (AP), a modem processor, a graphics processor (GPU), an image signal processor (ISP), a controller, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU), etc. Different processing units may be independent devices or integrated into one or more processors.

[0066] The terminal 100 implements the display function through a GPU, a display screen 394, and an application processor. The GPU is a microprocessor for image processing, which connects the display screen 394 and the application processor. The GPU is used to perform mathematical and geometric calculations for graphics rendering. The processor 310 may include one or more GPUs that execute program instructions to generate or change display information.

[0067] The terminal 100 can realize the shooting function through the ISP, the camera 393, the video codec, the GPU, the display screen 394 and the application processor.

[0068] The SIM card interface 395 is used to connect a SIM card. The SIM card can be connected to and separated from the terminal 100 by inserting the SIM card interface 395 or pulling it out from the SIM card interface 395. The terminal 100 can support 1 or N SIM card interfaces, where N is a positive integer greater than 1. The SIM card interface 395 can support Nano SIM cards, Micro SIM cards, SIM cards, and the like. Multiple cards can be inserted into the same SIM card interface 395 at the same time. The types of the multiple cards can be the same or different. The SIM card interface 395 can also be compatible with different types of SIM cards. The SIM card interface 395 can also be compatible with external memory cards. The terminal 100 interacts with the network through the SIM card to implement functions such as calls and data communications. In some embodiments, the terminal 100 uses an eSIM, i.e., an embedded SIM card.

[0069] The wireless communication function of the terminal 100 can be implemented by antenna 1, antenna 2, mobile communication module 350, wireless communication module 360, modulation and demodulation processor and baseband processor. Antenna 1 and antenna 2 are used to transmit and receive electromagnetic wave signals. Each antenna in the terminal 100 can be used to cover a single or multiple communication frequency bands. Different antennas can also be reused to improve the utilization of the antenna. For example, antenna 1 can be reused as a diversity antenna of a wireless local area network. In some other embodiments, the antenna can be used in combination with a tuning switch.

[0070] The mobile communication module 350 can provide solutions for wireless communications including 2G / 3G / 4G / 5G applied on the terminal 100. The mobile communication module 350 may include at least one filter, a switch, a power amplifier, a low noise amplifier (LNA), etc. The mobile communication module 350 can receive electromagnetic waves from the antenna 1, and filter, amplify, and process the received electromagnetic waves, and transmit them to the modulation and demodulation processor for demodulation. The mobile communication module 350 can also amplify the signal modulated by the modulation and demodulation processor, and convert it into electromagnetic waves for radiation through the antenna 1. In some embodiments, at least some of the functional modules of the mobile communication module 350 can be set in the processor 310. In some embodiments, at least some of the functional modules of the mobile communication module 350 can be set in the same device as at least some of the modules of the processor 310.

[0071] The wireless communication module 360 ​​can provide wireless communication solutions including wireless local area networks (WLAN) (such as wireless fidelity (Wi-Fi) networks), bluetooth (BT), global navigation satellite system (GNSS), frequency modulation (FM), near field communication (NFC), infrared radiation (IR) technology, etc., applied on the terminal 100. The wireless communication module 360 ​​can be one or more devices integrating at least one communication processing module. The wireless communication module 360 ​​receives electromagnetic waves via the antenna 2, modulates the frequency of the electromagnetic wave signal and filters it, and sends the processed signal to the processor 310. The wireless communication module 360 ​​can also receive the signal to be sent from the processor 310, modulate the frequency of it, amplify it, and convert it into electromagnetic waves for radiation through the antenna 2.

[0072] In some embodiments, the antenna 1 of the terminal 100 is coupled to the mobile communication module 350, and the antenna 2 is coupled to the wireless communication module 360, so that the terminal 100 can communicate with the network and other devices through wireless communication technology. The wireless communication technology may include global system for mobile communications (GSM), general packet radio service (GPRS), code division multiple access (CDMA), wideband code division multiple access (WCDMA), time-division code division multiple access (TD-SCDMA), long term evolution (LTE), BT, GNSS, WLAN, NFC, FM, and / or IR technology, etc.

[0073] Understandably, Figure 3 The components shown do not constitute a specific limitation on the terminal 100. The terminal 100 may also include more or fewer components than shown in the figure, or combine some components, or separate some components, or arrange the components differently. Figure 3 The combination / connection relationship between the components can also be adjusted and modified.

[0074] The software system of the signature pen 200 or the terminal 100 may adopt a layered architecture, an event-driven architecture, a micro-core architecture, a micro-service architecture, or a cloud architecture. The present application embodiment takes the Android system of the layered architecture as an example to illustrate the software structure of the signature pen 200 or the terminal 100.

[0075] like Figure 4 2 is a software structure diagram of the signature pen 200 of the present application embodiment. The software modules and / or codes of the software architecture can be stored in the memory 202. When the processor 201 runs the software modules or codes, the authentication method provided by the present application embodiment is executed. Figure 4 It is a software structure block diagram of the terminal 100 of the embodiment of the present application. The software modules and / or codes of the software architecture can be stored in the internal memory 321. When the internal processor 321 runs the software module or code, the authentication method provided by the embodiment of the present application is executed.

[0076] The layered architecture divides the software into several layers, each with clear roles and division of labor. The layers communicate with each other through software interfaces. In some embodiments, the Android system is divided into four layers, from top to bottom: the application layer, the application framework layer, the Android runtime and system library, and the kernel layer.

[0077] The application layer can include a series of application packages.

[0078] like Figure 4 As shown, the application package may include applications such as phone, camera, gallery, calendar, call, map, navigation, WLAN, Bluetooth, music, video, short message, etc.

[0079] The application framework layer provides an application programming interface (API) and a programming framework for the applications in the application layer. The application framework layer includes some predefined functions.

[0080] like Figure 4 As shown, the application framework layer may include a window manager, a content provider, a view system, a phone manager, a resource manager, a notification manager, and the like.

[0081] The window manager is used to manage window programs. The window manager can obtain the display screen size, determine whether there is a status bar, lock the screen, capture the screen, etc.

[0082] Content providers are used to store and retrieve data and make it accessible to applications. The data may include videos, images, audio, calls made and received, browsing history and bookmarks, phone books, etc.

[0083] The view system includes visual controls, such as controls for displaying text, controls for displaying images, etc. The view system can be used to build applications. A display interface can be composed of one or more views. For example, a display interface including a text notification icon can include a view for displaying text and a view for displaying images.

[0084] The phone manager is used to provide communication functions of the terminal 100, such as management of call status (including connection, disconnection, etc.).

[0085] The resource manager provides various resources for applications, such as localized strings, icons, images, layout files, video files, and so on.

[0086] The notification manager enables applications to display notification information in the status bar. It can be used to convey notification-type messages and can disappear automatically after a short stay without user interaction. For example, the notification manager is used to notify download completion, message reminders, etc. The notification manager can also be a notification that appears in the system top status bar in the form of a chart or scroll bar text, such as notifications of applications running in the background, or a notification that appears on the screen in the form of a dialog window. For example, it can prompt text information in the status bar, emit a prompt sound, vibrate, or flash an indicator light.

[0087] Android Runtime includes core libraries and virtual machines. Android runtime is responsible for scheduling and management of the Android system.

[0088] The core library consists of two parts: one part is the function that needs to be called by the Java language, and the other part is the Android core library.

[0089] The application layer and the application framework layer run in a virtual machine. The virtual machine executes the Java files of the application layer and the application framework layer as binary files. The virtual machine is used to perform functions such as object life cycle management, stack management, thread management, security and exception management, and garbage collection.

[0090] The system library may include multiple functional modules, such as surface manager, media library, 3D graphics processing library (such as OpenGL ES), 2D graphics engine (such as SGL), etc.

[0091] The surface manager is used to manage the display subsystem and provide the fusion of 2D and 3D layers for multiple applications.

[0092] The media library supports playback and recording of a variety of commonly used audio and video formats, as well as static image files, etc. The media library can support a variety of audio and video encoding formats, such as: MPEG4, H.264, MP3, AAC, AMR, JPG, PNG, etc.

[0093] The 3D graphics processing library is used to implement 3D graphics drawing, image rendering, compositing, and layer processing.

[0094] A 2D graphics engine is a drawing engine for 2D drawings.

[0095] The kernel layer is the layer between hardware and software. The kernel layer includes at least display driver, camera driver, audio driver, and sensor driver. Among them, hardware can refer to various sensors, such as the acceleration sensor, gyroscope sensor, touch sensor, pressure sensor, etc. involved in the embodiments of the present application.

[0096] In order to solve the problems raised in the background technology, an embodiment of the present application provides an authentication method, which not only authenticates the user's handwritten signature, but also authenticates the device and user identity used by the user when entering the handwritten signature. Only after all verifications are passed, it is confirmed that the user's handwritten signature is credible, thereby improving the reliability of the signature authentication result to solve the problem of insufficient security of current handwritten signature technology.

[0097] The following first introduces the method provided in the embodiment of the present application by way of example in different scenarios.

[0098] Scene 1

[0099] Figure 5A A flow chart of a signature authentication method is shown. In the first scenario, the process of a user using a signature pen to authenticate the signature of an electronic document on a mobile phone is taken as an example. The mobile phone includes a signature application, a security application in TEE, a first signature module, a second signature module and a collection module. The first signature module refers to a signature module used to authenticate the identity of the device, and the second signature module refers to a signature module used to authenticate the identity of the user. The key used by the first signature module is called a device key, and the key used by the second signature module is called an identity key. Specifically, the signature authentication method may include the following steps:

[0100] S501 to S503, the signature application of the mobile phone responds to the user's operation, triggers the signature application to open the electronic file that the user needs to sign and authenticate, the signature application transmits the electronic file that needs to be signed and authenticated to the trusted application, and the trusted application displays the file layer of the electronic file to be signed and authenticated.

[0101] For example, in combination Figure 6 For example, when the mobile phone detects that the user operates the signature application control 601, the operation may be a click operation or other voice command, etc. In response to the operation, the mobile phone displays the following Figure 6 When the mobile phone detects that the user operates the open document control 611 in the signature application, the mobile phone displays the following Figure 6 The interface 620 shown in (c) in FIG. 6 is a trusted user interface (TUI). For example, the document content of the electronic file "Rental Contract" is displayed in the interface 620. The display layer where the document content is located is defined as the electronic file layer to be signed in the TUI, and is generally in read-only mode, that is, the user is not allowed to modify the document content.

[0102] In a possible embodiment, if the current interface 620 does not fully display the entire content of the "Rental Contract", the user can continue to click the next page control 621 in the operation interface 620. In response to the user's operation, the mobile phone can also display the following: Figure 6 The interface 630 shown in (d) in the figure is defined as another electronic file layer to be signed in the TUI and is also in read-only mode. The remaining document content of the electronic file "Rental Contract" is displayed in the interface 630. It should be noted that this embodiment only illustrates that the electronic file is divided into two pages. In other possible situations, the electronic file can also be divided into one or more pages. This embodiment does not limit the number of pages.

[0103] S504 to S505, the trusted application of the mobile phone receives the user's operation, such as receiving the user's operation of clicking the start signing control, and the trusted application displays the signature layer of the electronic document to be signed and authenticated.

[0104] Continuing with the above example, when the phone detects that the user acts as follows Figure 6 When the start signature control 631 in the interface 630 shown in (d) is operated, the mobile phone displays the following Figure 6 Interface 640 is shown in (e), wherein interface 640 can be positioned as a signature layer in the TUI, which is in input mode, that is, the user can use a pen to input a handwritten signature in the signature layer or use finger sliding to input a handwritten signature.

[0105] From S506 to S507, the trusted application of the mobile phone receives the relevant data of the handwritten signature entered by the user using a pen (or the user using his finger) on the signature layer, and the trusted application of the mobile phone merges the two layers, generates and displays a signature-containing file including the relevant data of the electronic file and the handwritten signature, and generates a hash value of the signature-containing file.

[0106] Continuing with the above example, users can use a handwritten pen to Figure 6 In the interface 640 shown in (e), for example, the user handwrites the user's name "Wang Wu". When the mobile phone detects that the user acts on the confirmation control 641 in the interface 640, the mobile phone displays the following Figure 6 The interface 650 shown in (f) in FIG. 6 is defined as a signature file layer in the TUI, which is generally in read-only mode. The interface 650 includes the content of the electronic file "Rental Contract" and the user's handwritten signature information. When the mobile phone detects that the user acts on the confirmation control 651 in the interface 650, the mobile phone generates and displays the signature file including the relevant data of the electronic file and the handwritten signature, and generates a hash value of the signature file.

[0107] Specifically, the signature file is subjected to hash calculation or message-digest algorithm (MD) or secure hash algorithm (SHA) calculation to obtain a first calculation value, such as using MD5 algorithm, MD4 algorithm, MD3 algorithm or other algorithms to obtain a hash value.

[0108] It should be noted that other random algorithms may also be used to generate random numbers for signature files, which is not limited in this embodiment.

[0109] S508 to S509, when the trusted application of the mobile phone receives the user's confirmation that the handwritten signature operation is completed, the trusted application of the mobile phone sends the hash value of the signature file to the first signature module and the second signature module of the mobile phone.

[0110] Continuing with the previous example, when the phone detects that the user is acting on Figure 6 When the confirmation control 651 in the interface 650 shown in (f) is clicked, the trusted application of the mobile phone transmits the hash value of the signature file to the first signature module and the second signature module of the mobile phone.

[0111] S510, in the first authentication mode, a device key is used to digitally sign a hash value of a signature file.

[0112] Exemplarily, the first signature module in the TEE or SE of the mobile phone uses the device key of the mobile phone used by the user to sign to digitally sign the hash value of the signature file.

[0113] Among them, the mobile phone device key can be generated by executing a key algorithm on the device identifier of the mobile phone. For example, the device identifier may include at least one of an international mobile subscriber identification number (IMSI), a permanent equipment identifier (PEI), a subscriber permanent identifier (SUPI), a subscriber concealed identifier (SUCI), a temporary mobile subscriber identity (TMSI), an IP multimedia public identity (IMPU), a media access control (MAC) address, an IP address, a mobile phone number, or a globally unique temporary UE identity (GUTI). For example, the terminal identifier only includes IMSI, or only includes PEI and SUPI, or only includes PEI, TMSI and IMPU, or includes IMSI, PEI, SUPI, SUCI, TMSI, IMPU, MAC address, IP address, mobile phone number and GUTI. Among them, PEI is the fixed identifier of the terminal device; IMSI is the unique permanent identifier of the user in the LTE system; SUPI is the permanent identifier of the user in the 5G system; SUCI is the user identifier obtained after signing SUPI.

[0114] S511, the first signature module feeds back the device identity digital signature to the trusted application of the mobile phone.

[0115] Exemplarily, the first signature module in the TEE or SE of the mobile phone feeds back the digital signature of the device identity to the trusted application of the mobile phone.

[0116] S512, the second signature module triggers the collection module to collect the user's biometric features to facilitate user identity authentication.

[0117] From S513 to S514, the collection module collects the user's biometric features and sends the user's biometric features to the second signature module.

[0118] S515, the second signature module performs a biometric feature comparison and generates a verification result. If the verification is successful, S516 is executed, otherwise the signature authentication failure is returned.

[0119] It should be noted that the above steps S512 to S515 are optional steps. For the above steps S512 to S515, for example, when the mobile phone detects that the user acts on Figure 6 When the confirmation control 651 in the interface 650 shown in (f) is pressed, the mobile phone displays the following Figure 7 Assume that the default authentication method provided by the signature application is the fingerprint verification method in interface 700, then the user can click Figure 7 The "click to perform fingerprint verification" control 701 shown is used to input the user's fingerprint information for user identity authentication. If the authentication is successful, S516 is continued to be executed, otherwise the signature authentication failure is returned.

[0120] For example, users can also click Figure 7 The "More" control 702 shown in the figure, after that, the interface 700 will add input boxes such as "Password Verification", "Face Recognition Verification" and "Cancel". If the user clicks "Password Verification", the password information can be entered for user identity authentication; or, if the user clicks "Face Recognition Verification", the face information can be entered for user identity authentication. For example, if the user chooses to enter face information, it is equivalent to the selected acquisition module being the camera 393, or if the user chooses to enter fingerprint information, it is equivalent to the selected acquisition module being the fingerprint sensor 380H, and so on. After the user selects the corresponding acquisition module, the signature application can trigger the corresponding acquisition module to work, thereby collecting the user's related signature information.

[0121] It should be noted that when the user chooses to use biometrics for authentication, the collection module will be triggered to collect the user's biometrics. If the user chooses to use a password (such as a lock screen password) for authentication, the collection module will not be triggered to collect the user's biometrics. At this time, the second signature module only needs to perform key comparison to generate a verification result.

[0122] S516: The second signature module uses the user identity key to digitally sign the hash value.

[0123] In one possible case, the user identity key can be generated by executing a key algorithm on the user identity identifier. For example, if the user chooses to use biometrics for verification, the user identity identifier can be the user's biometrics collected by the collection module. In another possible case, if the user uses a pen for signature authentication, the user identity identifier can also be the device identifier of the pen. Because the device identifiers of different users' pens are different, the device identifier of the pen can be used to uniquely refer to the user identifier. In other possible cases, if the user uses a finger to input a handwritten signature, or the user uses a password for authentication, the user identity identifier can be the account ID of the user's login signature application, or the user ID of the user's login to the mobile phone operating system, etc.

[0124] S517, the second signature module returns the user identity digital signature to the trusted application of the mobile phone.

[0125] S518, the trusted application of the mobile phone returns the signature file, the user identity digital signature and the device identity digital signature to the signing application.

[0126] Optionally, when the mobile phone receives the above-mentioned signed document, user identity digital signature and device identity digital signature, the user on the mobile phone side has completed the handwritten signature process. The user on the mobile phone side can actively send the above-mentioned signed document, user identity digital signature and device identity digital signature to another electronic device (such as a computer of a real estate agency), or the mobile phone automatically sends the above information to the bound other electronic device to complete the handwritten signature authentication process. Figure 5B As shown, specifically, the authentication process of the handwritten signature also includes the following steps:

[0127] S519, the signature application sends the signature file, the user identity digital signature and the device identity digital signature to another electronic device.

[0128] S520, another electronic device sends the signature file, the user identity digital signature and the device identity digital signature to the signature application server.

[0129] S521, the signature application server uses a pre-stored template to verify the signed document, the user identity digital signature and the device identity digital signature.

[0130] Exemplarily, the signature application server uses the same hash function as the mobile phone side to calculate the first hash value for the received signed file, and uses the pre-stored public key related to the user identity to decrypt the user identity digital signature to obtain a second hash value. If the first hash value is the same as the second hash value, the user identity digital signature is deemed to be legal. In addition, the signature application server uses the public key related to the device identifier (such as IMSI) to decrypt the device identity digital signature to obtain a third hash value. If the first hash value is the same as the third hash value, the device identity digital signature is deemed to be legal. In addition, the signature application server uses the pre-stored handwritten signature image template and the pressure data template to match the signed file. If the match is successful, the signed file is deemed to be legal. When it is determined that the user identity digital signature, the device identity digital signature and the signed file are all legal, the signature application server confirms that the verification is successful. Otherwise, it confirms that the verification is unsuccessful.

[0131] S522, the signature application server returns the signature authentication result to the signature application of the other electronic device.

[0132] In this way, a user of another electronic device can view the result of success or failure of the signature authentication from the display interface.

[0133] It should be noted that the process of the second signature module authenticating the user's biometric features in the above S513 to S515 can occur before the user's handwritten signature, such as before S506; or, it can occur before the device identity digital signature, such as before S510. In addition, the device identity digital signature process can also occur after the user identity digital signature process, that is, S510 to S511 can occur after S517.

[0134] In this embodiment, it is applicable to the scenario where the first signature module and the second signature module are both in the same device (such as a mobile phone). In this scenario, the user can use a signature pen to write a signature or use a finger to touch and input a handwritten signature. The user can complete the handwritten signature anytime and anywhere by carrying a terminal (such as a mobile phone, PAD) that can run the above method, and the security of the handwritten signature authentication can be guaranteed. Because only when the signature application server (or other authentication servers) recognizes that the user identity digital signature, the device identity digital signature and the signature-containing document are all legal, the signature is successfully authenticated, which can ensure that the input device of the handwritten signature handwriting is a safe and reliable device, the input user is a legal user, and the handwritten signature handwriting is also the legal signature information of the legal user, thereby improving the security of the handwritten signature. The purpose of this embodiment combined with digital verification is to verify whether the data transmission process has been tampered with. Since the signature data is calculated by the confidential data (such as the device identification, the user identification) and the handwritten signature handwriting, the signature verification can verify whether the confidential data or the handwritten signature handwriting has been tampered with during the transmission to the trusted application server. The method effectively improves the problem of insufficient security of current handwritten signature technology, improves the credibility of handwritten signature authentication results, and avoids the problem of attackers illegally obtaining the user's handwritten signature template data to forge the user's handwritten signature and illegally pass the handwritten signature authentication.

[0135] In the above scenario 1, if the user can use a signature pen to sign by hand, the signature pen and the mobile phone can be connected via Bluetooth. Of course, they can also communicate via other short-range communication protocols other than the Bluetooth communication protocol, including but not limited to WiFi, infrared, etc. The short-range communication protocol is sometimes referred to as the short-range communication protocol below.

[0136] Scene 2

[0137] The difference between scenario 2 and scenario 1 is that scenario 2 is more suitable for a scenario where the first signature module and the second signature module are in different devices (such as mobile phones).

[0138] The second scenario takes the process of a user using a user-specific signature pen to perform signature authentication on an electronic document on an electronic device (such as a bank teller) as an example. The electronic device includes a signature application, a security application in the TEE, a first signature module, and a first connection module. The signature pen includes a second signature module, a collection module, and a second connection module. The first signature module refers to a signature module used to authenticate the identity of the device, and the second signature module refers to a signature module used to authenticate the identity of the user. The key used by the first signature module is called a device key, and the key used by the second signature module is called an identity key.

[0139] For example, Fig. 8A As shown, the user brings his own exclusive signature pen to the bank counter to handle bank transactions. When the bank transaction initiates the authentication of the user's handwritten signature, the user can use the signature pen he carries to enter the handwritten signature on the bank counter. In addition, the bank counter generates device identity signature data, and the signature pen generates user identity signature data, and sends it to the bank counter. Finally, the bank counter sends the handwritten signature data, device identity signature data and user identity signature data to the bank's back-end server. The bank's back-end server verifies the user's handwritten signature data as well as the device identity signature data and the user identity signature data, and determines whether the handwritten signature is credible based on the verification result.

[0140] Figure 8B The following is a flow chart of a signature authentication method in scenario 2. Specifically, the following steps may be included:

[0141] S800, after the device switch of the signature pen is turned on by the user, the electronic device can search for and find the signature pen and establish a secure connection with the signature pen.

[0142] Specifically, the first connection module of the electronic device and the second connection module of the signature pen complete the establishment of a secure connection through negotiation and interaction. The electronic device and the signature pen can be connected via Bluetooth, and of course, can also communicate via other short-range communication protocols other than the Bluetooth communication protocol, including but not limited to WiFi, infrared, etc. In a possible embodiment, if the signature pen successfully establishes a secure connection with the electronic device, the indicator light of the signature pen can be lit to indicate to the user that the signature pen is successfully connected and is in a usable state.

[0143] S801 to S803, the signature application of the electronic device responds to the user's operation, triggering the signature application to open the electronic file that the user needs to sign and authenticate, the signature application transmits the electronic file that needs to be signed and authenticated to the trusted application, and the trusted application displays the file layer of the electronic file to be signed and authenticated in the TUI.

[0144] For example, in combination Fig. 9A For example, Fig. 9AAs shown in (a) of FIG. 1 , when the bank teller detects the user's operation on the signature application control 901, the operation may be a click operation or other voice command, etc. In response to the operation, the bank teller displays the following Fig. 9A The interface 910 of the signature application shown in (b) of FIG. 1 is a trusted user interface (TUI). When the bank teller detects that the user operates the open document control 911 in the signature application, the bank teller displays the following Fig. 9B Interface 920 shown in (c) of FIG. 1 . Exemplarily, the document content of the electronic file "Financial Management Contract" is displayed in interface 920. The display layer where the document content is located is defined as the electronic file layer to be signed in the TUI, and is generally in read-only mode, that is, the user is not allowed to modify the document content.

[0145] In a possible embodiment, if the current interface 920 does not fully display the entire content of the "Financial Management Contract", the user can continue to click the next page control 921 in the operation interface 920. In response to the user's operation, the bank teller can also display the following: Fig. 9B The interface 930 shown in (d) in FIG. The interface 930 displays the remaining document content of the electronic file "Financial Management House Contract". It should be noted that this embodiment only illustrates that the electronic file is divided into two pages. In other possible cases, the electronic file can also be divided into one page or more pages. This embodiment does not limit the number of pages.

[0146] S804 to S805, the trusted application of the bank teller receives the user's operation, such as receiving the user's operation of clicking the start signing control, and the trusted application displays the signature layer of the electronic document to be signed and authenticated.

[0147] Continuing with the above example, when the bank teller detects that the user acts on Fig. 9B When the start signature control 931 in the interface 930 shown in (d) is operated, the bank teller displays the following Fig. 9C The interface 940 shown in (e) in the figure may be a trusted user interface (TUI). The TUI interface displays a signature layer. The user may input a handwritten signature on the signature layer using a signature pen.

[0148] From S806 to S807, the trusted application of the bank teller machine receives the relevant data of the handwritten signature entered by the user using a signature pen (or the user using his finger) on the signature layer, and the trusted application of the bank teller machine merges the two layers, generates and displays a signature-containing file including the relevant data of the electronic file and the handwritten signature, and generates a hash value of the signature-containing file.

[0149] Continuing with the above example, users can use a handwritten pen to Fig. 9C In the interface 940 shown in (e), for example, the user hand-writes the user's name "Wang Wu". When the bank teller detects that the user acts on the confirmation control 941 in the interface 940, the bank teller displays the following Fig. 9C The interface 950 shown in (f) in the figure includes the content of the electronic file "Financial Management Contract" and the user's handwritten signature information. When the bank teller detects that the user acts on the confirmation control 951 in the interface 950, the bank teller generates and displays a signature file including the relevant data of the electronic file and the handwritten signature, and generates a hash value of the signature file.

[0150] Specifically, the signature file is subjected to hash calculation or message-digest algorithm (MD) or secure hash algorithm (SHA) calculation to obtain a first calculation value, such as using MD5 algorithm, MD4 algorithm, MD3 algorithm or other algorithms to obtain a hash value.

[0151] It should be noted that other random algorithms may also be used to generate random numbers for signature files, which is not limited in this embodiment.

[0152] S808 to S809, when the trusted application of the bank teller machine receives the user's confirmation that the handwritten signature operation is completed, the trusted application of the bank teller machine sends the hash value of the signature file to the first signature module of the bank teller machine and the second signature module of the signature pen.

[0153] Continuing with the above example, when the bank teller detects that the user is acting on Fig. 9C When the confirmation control 951 in the interface 950 shown in (f) is pressed, the trusted application of the bank teller transmits the hash value of the signature file to the first signature module of the bank teller and the second signature module of the signature pen.

[0154] S810, the first signature module of the bank teller uses the device key to digitally sign the hash value of the signature file.

[0155] Exemplarily, the first signature module in the TEE or SE of the bank teller uses its own preset device key to digitally sign the hash value of the signature file.

[0156] The device key may be generated by executing a key algorithm on the device identification of the bank teller machine.

[0157] S811, the first signature module of the bank teller machine feeds back the device identity digital signature to the trusted application of the bank teller machine.

[0158] Exemplarily, the first signature module in the TEE or SE of the bank teller machine feeds back the digital signature of the device identity to the trusted application of the bank teller machine.

[0159] S812, the second signature module of the signature pen triggers the collection module to collect the user's biometric features to facilitate user identity authentication.

[0160] From S813 to S814, the collection module of the signature pen collects the user's biometric features and sends the user's biometric features to the second signature module of the signature pen.

[0161] For example, Fig.10 As shown, the collection module of the signature pen can be a fingerprint feature collection sensor, and when the user's fingertip touches the sensor area, the collection module can collect the user's fingerprint features. Thus, the fingerprint feature collection sensor sends the collected fingerprint features to the second signature module.

[0162] S815, the second signature module of the signature pen performs a biometric comparison and generates a verification result. If the verification is successful, S816 is executed, otherwise the signature authentication failure is returned.

[0163] S816, the second signature module of the signature pen uses the user identity key to digitally sign the hash value.

[0164] It should be noted that the above steps S812 to S815 are optional steps. In one possible case, the user identity key can be generated by executing a key algorithm on the user identity identifier. For example, if the user chooses to use biometrics for verification, the user identity identifier can be the user's biometrics collected by the collection module. In another possible case, the user identity identifier can also be the device identifier of a signature pen. Since the device identifiers of signature pens of different users are different, the device identifier of the signature pen can be used to uniquely refer to the user identifier.

[0165] S817, the second signature module of the signature pen returns the user identity digital signature to the trusted application of the bank teller machine.

[0166] S818, the trusted application of the bank teller returns the signature file, the user identity digital signature and the device identity digital signature to the signature application.

[0167] Optionally, this embodiment may further include the following authentication process, namely, including S819 to S822. It should be noted that the authentication process is decoupled from the above-mentioned handwritten signature process, and the two processes may be executed separately or successively.

[0168] S819, the signature application sends the signature file, the user identity digital signature and the device identity digital signature to the bank's backend application server.

[0169] S820, the bank's backend application server uses a pre-stored template to verify the signed document, the user's digital signature, and the device's digital signature.

[0170] Exemplarily, the bank's back-end application server uses the same hash function as the bank counter side to calculate the first hash value for the received signed file, and uses the pre-stored public key related to the user identity to decrypt the user identity digital signature to obtain a second hash value. If the first hash value is the same as the second hash value, the user identity digital signature is deemed to be legal. In addition, the signature application server uses the public key related to the device identifier (such as IMSI) to decrypt the device identity digital signature to obtain a third hash value. If the first hash value is the same as the third hash value, the signed file is deemed to be legal. When it is determined that the user identity digital signature, the device identity digital signature and the signed file are all legal, the bank's back-end application server confirms that the verification is successful; otherwise, it confirms that the verification has failed.

[0171] S821, the bank's backend application server returns the signature authentication result to the signature application.

[0172] S822, the signature application displays the result of signature authentication success or failure to the user.

[0173] It should be noted that the process of the second signature module authenticating the user's biometric features in the above S813 to S815 can occur before the user's handwritten signature, such as before S906; or, it can occur before the device identity digital signature, such as before S910. In addition, the device identity digital signature process can also occur after the user identity digital signature process, that is, S910 to S911 can occur after S917.

[0174] In this embodiment, in this scenario, the user can use a signature pen to sign a handwritten signature on an electronic device. By carrying a dedicated signature pen with him, the user can complete the handwritten signature anytime and anywhere, and the security of the handwritten signature authentication can be guaranteed. Because only when the authentication server (such as a bank backend server) determines that the user identity digital signature, the device identity digital signature and the signature-containing document are all legal, the signature is authenticated successfully, which can ensure that the input device of the handwritten signature handwriting is a safe and reliable device, the input user is a legal user, and the handwritten signature handwriting is also the legal signature information of the legal user, thereby improving the security of the handwritten signature. The purpose of this embodiment combined with digital verification is to verify whether the data transmission process has been tampered with. Since the signature data is obtained by calculating the confidential data (such as the device identification, the user identification) and the handwritten signature handwriting, the signature verification can verify whether the confidential data or the handwritten signature handwriting is tampered with during the process of transmitting to the trusted application server. This method effectively improves the problem of insufficient security of the current handwritten signature technology, improves the credibility of the handwritten signature authentication result, and avoids the problem of attackers illegally obtaining the user's handwritten signature template data to forge the user's handwritten signature and illegally pass the handwritten signature authentication.

[0175] Based on the above scenario 1 and scenario 2, a flowchart of an authentication method provided in an embodiment of the present application is shown in FIG. Fig.11 As shown, the method specifically includes the following steps.

[0176] Step 1101: The business module of the terminal obtains confidential data and handwritten signature related data.

[0177] Among them, the business module can be a trusted application authorized by the trusted execution environment, or it can be other security modules in the trusted execution environment, such as the first signature module or the second signature module. The confidential data can be an electronic file in the signature application, such as the electronic file of the "Rental Contract" in Scenario 1, or the electronic file of the "Financial Management Contract" in Scenario 2. Exemplarily, the specific method of obtaining the confidential data and the relevant data of the handwritten signature can refer to the description of the above Scenario 1 or Scenario 2, which will not be repeated here.

[0178] Step 1102: The business module of the terminal calculates the confidential data and the relevant data of the handwritten signature to obtain the data to be signed.

[0179] Exemplarily, the trusted application of the terminal calculates the signed file including the confidential data and the relevant data of the handwritten signature to obtain a hash value.

[0180] Step 1103: The terminal service module sends the data to be signed to the first signature module and the second signature module.

[0181] Exemplarily, following the above example, the TA of the terminal sends a device signature request to APPLET, the device signature request includes a hash value, and the TA of the terminal sends a user identity signature request to the second signature module of the signature pen, the user identity signature request includes the hash value.

[0182] Step 1104: The first signature module uses the first key to perform signature calculation on the data to be signed to obtain first signature information, and the first signature module sends the first signature information to the service module of the terminal.

[0183] The first key is a key associated with the device identification of the terminal, that is, a key generated according to the device identification of the terminal. The first signature information may be a digital signature associated with the device identification of the terminal, such as the device identity digital signature in the above scenario one or scenario two.

[0184] Step 1105: The second signature module uses the second key to perform signature calculation on the data to be signed to obtain second signature information, and the second signature module sends the second signature information to the service module of the terminal.

[0185] In a possible embodiment, the second signature module uses the user's identity identifier to verify the user's identity; when the verification is successful, the second signature module uses the second key to calculate the signature of the data to be signed to obtain the second signature information. When the verification fails, the second signature module notifies the business module that the signature authentication fails.

[0186] The embodiment of the present application does not limit the order of execution of the above-mentioned step 1104 and step 1105. Step 1104 can be executed first, and then step 1105, or step 1105 can be executed first, and then step 1104, or step 1104 and step 1105 can be executed simultaneously.

[0187] In the above steps 1104 and 1105, the first signature information and the second signature information may be generated by digital signature. For specific examples, please refer to the above scenario 1 or scenario 2. It should be noted that in addition to the digital signature method, the embodiments of the present application may also use other encryption and decryption methods, such as symmetric encryption methods, asymmetric encryption methods, etc., and there is no restriction on the encryption and decryption methods. In the introduction of this article, the use of digital signatures is mainly taken as an example.

[0188] In addition, the first signature module in step 1104 and step 1105 and the second signature module may all be in the same device, as described in scenario one; or, the first signature module in step 1104 and step 1105 and the second signature module may be in different devices, as described in scenario two.

[0189] Step 1106: The business module sends a handwritten signature authentication request message to the authentication server. The authentication request message includes the confidential data and handwritten signature related data, the first signature information, and the second signature information.

[0190] That is, after obtaining the confidential data and the relevant data of the handwritten signature, the first signature information and the second signature information, the business module initiates an authentication request for the handwritten signature, thereby triggering the authentication server to authenticate the handwritten signature.

[0191] Step 1107: The authentication server authenticates the handwritten signature based on the confidential data and the relevant data of the handwritten signature, the first signature information and the second signature information, and sends an authentication response message including the authentication result to the service module of the terminal.

[0192] In a possible implementation, the identity signature module of the authentication server may first authenticate the second signature information (i.e., the identity of the user (such as the user's ID or biometrics)). If the authentication fails, a signature authentication failure notification message and failure reason information are sent to the business module. The failure reason information may include fingerprint verification failure, etc. If the authentication is successful, the device signature module of the authentication server may authenticate the first signature information again. If the authentication fails, a signature authentication failure notification message and failure reason information are sent to the business module. The failure reason information may include illegal device, etc. If the authentication is successful, the device signature module of the authentication server may continue to authenticate the confidential data and the data related to the handwritten signature. If the authentication fails, a signature authentication failure notification message and failure reason information are sent to the business module. The failure reason information may include illegal signature handwriting, etc. If the authentication is successful, the business module is notified that the signature authentication is successful.

[0193] In this embodiment, the user can use a dedicated signature pen to sign handwritten on the electronic device anytime and anywhere, or can sign handwritten through the user's dedicated terminal anytime and anywhere, and the legitimacy of the handwritten signature authentication result can be guaranteed. Because only when the authentication server (such as the bank backend server) determines that the user identity digital signature, the device identity digital signature and the signature-containing document are all legal, the authentication signature is successful, which can ensure that the input device of the handwritten signature handwriting is a safe and reliable device, the input user is a legal user, and the handwritten signature handwriting is also the legal signature information of the legal user, thereby improving the security of the handwritten signature. The purpose of this embodiment combined with digital verification is to verify whether the data transmission process has been tampered with. Since the signature data is obtained by calculating the confidential data (such as the device identification, the user identification) and the handwritten signature handwriting, the signature verification can verify whether the confidential data or the handwritten signature handwriting is tampered with during the process of transmitting to the trusted application server. This method effectively improves the problem of insufficient security of the current handwritten signature technology, improves the credibility of the handwritten signature authentication result, and avoids the problem of attackers illegally obtaining the user's handwritten signature template data to forge the user's handwritten signature and illegally pass the handwritten signature authentication.

[0194] Based on Fig.11 With the same inventive concept as the method embodiment shown, the embodiment of the present invention provides a first device, which is specifically used to implement the method in the above embodiment.

[0195] When the first device includes a first signature module and a second signature module, the structure of the device is as follows: Fig.12 As shown, it includes a business module 1201, a first signature module 1202, and a second signature module 1203.

[0196] The business module 1201 is used to obtain confidential data and handwritten signature related data; calculate the confidential data and handwritten signature related data to obtain data to be signed; and send the data to be signed to the first signature module and the second signature module.

[0197] The first signature module 1202 is used to obtain the device identification of the device used by the user for handwritten signature, generate the first key according to the device identification; use the first key to perform signature calculation on the data to be signed to obtain the first signature information.

[0198] The second signature module 1203 is used to obtain the user's identity identifier, generate the second key according to the user's identity identifier, and use the second key to perform signature calculation on the data to be signed to obtain the second signature information.

[0199] Business module 1201 is also used to send an authentication request message to an authentication server, wherein the authentication request message includes the confidential data and handwritten signature related data, the first signature information and the second signature information; and receive an authentication response message from the authentication server, wherein the authentication response message is used to indicate the authentication server's authentication result of the handwritten signature based on the confidential data and handwritten signature related data, the first signature information and the second signature information.

[0200] In a possible implementation, the second signature module 1203 is further configured to use the user's identity identifier to verify the identity of the user; when the verification is successful, the second key is used to perform a signature calculation on the data to be signed to obtain the second signature information.

[0201] In a possible implementation, the business module 1201 is further used to generate a signature-containing document including the confidential data and relevant data of the handwritten signature, and display the signature-containing document through a display screen.

[0202] In a possible implementation, the first device further includes a first connection module 1204, which is used to establish a communication connection with the signing pen when a device switch of the signing pen for inputting the handwritten signature is turned on.

[0203] Based on Fig.11 With the same inventive concept as the method embodiment shown, the embodiment of the present invention provides a first device and a second device, which are specifically used to implement the method in the above embodiment.

[0204] like Fig.13 As shown, the structure of the first device includes a service module 1301, a first signature module 1302, and a first connection module 1303. The structure of the first device includes a second signature module 1304, and a second connection module 1305.

[0205] The first connection module 1303 is used to establish a secure connection with the second connection module 1305 so that the first device can communicate with the second device. In a possible implementation, when the device switch of the signature pen where the second device is located is turned on, a communication connection is established with the signature pen.

[0206] The business module 1301 is used to obtain confidential data and handwritten signature related data; calculate the confidential data and handwritten signature related data to obtain data to be signed; and send the data to be signed to the first signature module and the second signature module.

[0207] The first signature module 1302 is used to obtain the device identification of the device used by the user for handwritten signature, generate the first key according to the device identification; use the first key to perform signature calculation on the data to be signed to obtain the first signature information.

[0208] The second signature module 1304 is used to obtain the user's identity identifier, generate the second key according to the user's identity identifier, and use the second key to perform signature calculation on the data to be signed to obtain the second signature information.

[0209] The second connection module 1305 is used to send the second signature information to the service module 1301.

[0210] Business module 1301 is also used to send an authentication request message to an authentication server, wherein the authentication request message includes the confidential data and handwritten signature related data, the first signature information and the second signature information; and receive an authentication response message from the authentication server, wherein the authentication response message is used to indicate the authentication server's authentication result of the handwritten signature based on the confidential data and handwritten signature related data, the first signature information and the second signature information.

[0211] In a possible implementation, the second signature module 1304 is further configured to use the user's identity identifier to verify the identity of the user; when the verification is successful, the second key is used to perform a signature calculation on the data to be signed to obtain the second signature information.

[0212] In a possible implementation, the business module 1301 is further used to generate a signature-containing document including the confidential data and relevant data of the handwritten signature, and display the signature-containing document through a display screen.

[0213] This embodiment also provides a signature system, including the above terminal and the above signature pen, to implement the method in the above embodiment.

[0214] This embodiment further provides a computer-readable storage medium, in which computer instructions are stored. When the computer instructions are executed on a terminal, the terminal executes one or more steps executed in the above embodiment to implement the method in the above embodiment.

[0215] This embodiment also provides a program product. When the program product is run on a computer, the computer is enabled to execute one or more steps in the above embodiments to implement the methods in the above embodiments.

[0216] In addition, an embodiment of the present application also provides a device, which can specifically be a chip system, component or module, and the device may include a connected processor and memory; wherein the memory is used to store computer-executable instructions, and when the device is running, the processor can execute the computer-executable instructions stored in the memory to enable the chip to perform one or more steps in the above embodiments to implement the methods in the above embodiments.

[0217] Through the description of the above implementation methods, technicians in the relevant field can clearly understand that for the convenience and simplicity of description, only the division of the above functional modules is used as an example. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above. The specific working process of the system, device and unit described above can refer to the corresponding process in the aforementioned method embodiment, and will not be repeated here.

[0218] Each functional unit in each embodiment of the present application can be integrated into a processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The above integrated unit can be implemented in the form of hardware or in the form of software functional units.

[0219] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the embodiment of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) or a processor to perform all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as flash memory, mobile hard disk, read-only memory, random access memory, disk or optical disk.

[0220] References to "one embodiment" or "some embodiments" etc. described in this specification mean that a particular feature, structure or characteristic described in conjunction with the embodiment is included in one or more embodiments of the present application. Thus, the phrases "in one embodiment", "in some embodiments", "in some other embodiments", "in some other embodiments", etc. that appear at different places in this specification do not necessarily refer to the same embodiment, but mean "one or more but not all embodiments", unless otherwise specifically emphasized in other ways. The terms "including", "comprising", "having" and their variations all mean "including but not limited to", unless otherwise specifically emphasized in other ways.

[0221] In the embodiments provided by the present application, the method provided by the embodiments of the present application is introduced from the perspective of a terminal (e.g., a mobile phone) as an execution subject. In order to implement the functions in the methods provided by the embodiments of the present application, the terminal device may include a hardware structure and / or a software module to implement the functions in the form of a hardware structure, a software module, or a hardware structure plus a software module. Whether a function of the functions described above is executed in the form of a hardware structure, a software module, or a hardware structure plus a software module depends on the specific application and design constraints of the technical solution.

[0222] As used in the above embodiments, the term "when..." or "after..." may be interpreted to mean "if..." or "after..." or "in response to determining..." or "in response to detecting...", depending on the context. Similarly, the phrase "when determining..." or "if (the stated condition or event) is detected" may be interpreted to mean "if determining..." or "in response to determining..." or "when (the stated condition or event) is detected" or "in response to detecting (the stated condition or event)", depending on the context. In addition, in the above embodiments, relational terms such as first and second are used to distinguish one entity from another, without limiting any actual relationship and order between the entities.

[0223] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions may be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium, for example, the computer instructions may be transmitted from a website site, computer, server or data center by wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) mode to another website site, computer, server or data center. The computer-readable storage medium may be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more available media integrated. The available medium may be a magnetic medium, (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state drive Solid State Disk (SSD)), etc.

[0224] Note: A portion of this patent application document contains material which is subject to copyright protection. The copyright owner reserves all rights reserved except for the production of copies of the material in the patent file or patent record in the Patent Office.

Claims

1. An authentication method, applied to a terminal including a service module, characterized in that: The method comprises: The business module obtains confidential data and handwritten signature related data; The business module calculates the confidential data and the relevant data of the handwritten signature to obtain the data to be signed; The business module sends the data to be signed to the first signature module and the second signature module, wherein the first signature module obtains the device identification of the device used by the user for handwritten signature, and generates a first key according to the device identification; the first signature module uses the first key to calculate the signature of the data to be signed to obtain first signature information; the second signature module obtains the user's identity identification, and generates a second key according to the user's identity identification; the second signature module uses the second key to calculate the signature of the data to be signed to obtain second signature information; The business module obtains the first signature information and the second signature information from the first signature module and the second signature module; The business module sends an authentication request message to the authentication server, wherein the authentication request message includes the confidential data and the relevant data of the handwritten signature, the first signature information and the second signature information; The business module receives an authentication response message from the authentication server, where the authentication response message is used to indicate an authentication result of the authentication server authenticating the handwritten signature based on the confidential data and relevant data of the handwritten signature, the first signature information and the second signature information.

2. The method according to claim 1, characterized in that: The first signature module, the second signature module and the service module are all located in the same terminal device.

3. The method according to claim 1, characterized in that The second signature module uses the second key to perform signature calculation on the data to be signed to obtain second signature information, including: The second signature module verifies the identity of the user using the identity identifier of the user; When the verification is passed, the second signature module uses the second key to perform signature calculation on the data to be signed to obtain the second signature information.

4. The method according to claim 1, characterized in that The first signature module and the business module are in the same terminal device, and the second signature module is in a signature pen.

5. The method according to any one of claims 1 to 4, characterized in that: The service module is a trusted application that has been authorized by the trusted execution environment.

6. The method according to any one of claims 1 to 4, characterized in that: The method further comprises: The business module generates a signature-containing document including the confidential data and relevant data of the handwritten signature, and displays the signature-containing document through a display screen.

7. The method according to any one of claims 1 to 4, characterized in that: The signing pen for inputting the handwritten signature includes a device switch; The method further comprises: When the device switch is turned on, the terminal establishes a communication connection with the signature pen.

8. A terminal, characterized in that: The terminal includes a touch panel, a display panel, a sensor, a processor, and a memory; The touch panel is used to receive relevant data of the handwritten signature input by the user; The display panel is used to display confidential data and data related to the handwritten signature; The memory stores program instructions; The processor is configured to run the program instructions stored in the memory, so that the terminal executes: The service module of the terminal obtains the confidential data and the relevant data of the handwritten signature; The business module of the terminal calculates the confidential data and the relevant data of the handwritten signature to obtain the data to be signed; The business module of the terminal sends the data to be signed to the first signature module and the second signature module, wherein the first signature module obtains the device identification of the device used by the user for handwritten signature, and generates a first key according to the device identification; the first signature module uses the first key to calculate the signature of the data to be signed to obtain first signature information; the second signature module obtains the identity identification of the user, and generates a second key according to the identity identification of the user; the second signature module uses the second key to calculate the signature of the data to be signed to obtain second signature information; The service module of the terminal obtains the first signature information and the second signature information from the first signature module and the second signature module; The service module of the terminal sends an authentication request message to the authentication server, wherein the authentication request message includes the confidential data and the relevant data of the handwritten signature, the first signature information and the second signature information; The business module of the terminal receives an authentication response message from the authentication server, wherein the authentication response message is used to indicate an authentication result of the authentication server authenticating the handwritten signature based on the confidential data and relevant data of the handwritten signature, the first signature information and the second signature information.

9. The terminal according to claim 8, characterized in that: The first signature module, the second signature module and the service module are all located in the same terminal device.

10. The terminal according to claim 8, characterized in that: The processor is configured to run the program instructions stored in the memory, so that the terminal further executes: The second signature module of the terminal verifies the identity of the user using the identity identifier of the user; When the verification is passed, the second signature module of the terminal uses the second key to perform signature calculation on the data to be signed to obtain the second signature information.

11. The terminal according to claim 8, characterized in that: The first signature module and the business module are in the same terminal device, and the second signature module is in a signature pen.

12. The terminal according to any one of claims 8 to 11, characterized in that: The service module is a trusted application that has been authorized by the trusted execution environment.

13. The terminal according to any one of claims 8 to 11, characterized in that: The processor is configured to run the program instructions stored in the memory, so that the terminal further executes: The business module of the terminal generates a signature-containing document including the confidential data and data related to the handwritten signature, and displays the signature-containing document through a display screen.

14. The terminal according to any one of claims 8 to 11, characterized in that: The signing pen for inputting the handwritten signature includes a device switch; the terminal also includes a communication unit; The processor is configured to run the program instructions stored in the memory, so that the terminal further executes: When the device switch is turned on, a communication connection is established with the signature pen through the communication unit.

15. A signature pen, characterized in that: Used to input relevant data of a handwritten signature in a terminal as claimed in any one of claims 8 or 11-14, the signature pen comprising: a sensor unit, a processor and a communication unit; The sensor unit is used to detect the motion track information and pressure information of the signature pen when the user signs on the touch panel of the terminal with the signature pen; The processor is configured to use the second key in the second signature module to perform signature calculation on the data to be signed from the terminal to obtain second signature information; The second signature information is sent to the terminal through the communication unit.

16. A signature authentication system, characterized in that: It comprises the terminal as described in any one of claims 8 or 11-14, and the signing pen as described in claim 15.

17. A computer-readable storage medium, characterized in that: The computer-readable storage medium includes program instructions, and when the program instructions are executed on a terminal, the terminal is enabled to execute the method according to any one of claims 1 to 7.