Electronic contract signing method and system based on electronic signature

Through the electronic contract signing method based on electronic signatures, the symmetric key algorithm and quantum cryptographic network are used to solve the problem of insufficient security of the electronic signature system based on PKI in the prior art, and the unconditional security against quantum attacks and the reliability of electronic contracts are achieved.

CN114692219BActive Publication Date: 2025-08-22QUANTUMCTEK CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202011641597.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-12-31
Publication Date
2025-08-22
Estimated Expiration
2040-12-31

AI Technical Summary

Technical Problem

The existing electronic signature system and electronic contract signing system based on PKI technology have security threats, and the computing complexity encryption algorithm cannot guarantee security when facing attacks from quantum computers.

Method used

The electronic contract signing method based on electronic signatures is adopted, and the symmetric key algorithm and quantum cryptographic network are used to distribute shared keys through a trusted center to realize one-cryptographic encryption at a time, embed the signing party's electronic signature information to ensure the reliability and unconditional security of the electronic contract.

Benefits of technology

It eliminates the computational security defects of the traditional electronic signature algorithm and electronic contract signing method based on PKI, provides unconditional security against quantum attacks, and increases the reliability and credibility of electronic contract signing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114692219B_ABST
    Figure CN114692219B_ABST
Patent Text Reader

Abstract

The present invention provides an electronic contract signing method and system based on electronic signatures, which utilizes a symmetric key algorithm for encryption and has anti-quantum attack characteristics. It fundamentally eliminates the defects of traditional electronic signature algorithms and electronic contract signing methods based on PKI, whose security is based on computational security. It is implemented based on a quantum cryptography network and realizes one-time-one-pad encryption by adopting a marking method for the used keys, which has unconditional security. The electronic signature information of the signatory is embedded in the electronic contract signing, which gives the electronic contract dual credibility and increases the reliability of the electronic contract signing.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of encryption communication of quantum cryptography networks, and specifically relates to an electronic contract signing method and system based on electronic signatures. Background Art

[0002] The statements in this section merely provide background information related to the present invention and do not necessarily constitute prior art.

[0003] An electronic signature generally refers to any electronic code that exists and is attached to an electronic document. It can identify the identity of the signatory of the electronic document, ensure the integrity of the document, and indicate that the signatory agrees to the contents of the electronic document.

[0004] Electronic signature systems are a high-tech technology that emerged alongside the development of informatization. They primarily address the issue of signing and stamping electronic documents. They are used to identify the signer, ensure document integrity, and guarantee authenticity, reliability, and non-repudiation. An electronic signature is not a digital representation of a written signature or seal; it exists as an electronic code. Using an electronic signature, recipients can easily verify the sender's identity and signature when transmitting documents over the internet. It can also verify whether the original document has been altered during transmission.

[0005] Electronic contracts, also known as e-commerce contracts, emerged with the development of computer technology and automated office automation. Essentially, they transmit information via electronic pulses, replacing the traditional practice of using paper as the primary credential with a set of electronic information. Generally speaking, an electronic contract can be defined as an agreement between two or more parties, reached electronically via an electronic information network, to establish, modify, or terminate property-related civil rights and obligations. Simply put, an electronic contract is a contract concluded electronically, primarily an agreement reached online by the parties.

[0006] However, according to the inventors' understanding, current electronic signature and electronic contract signing systems are generally implemented based on PKI technology, which authenticates the signer's identity and uses RSA asymmetric keys to implement non-repudiation signatures on data. It is well known that the asymmetric key encryption algorithm used in PKI technology is computationally secure. However, in the face of the foreseeable research and development of quantum computers, cryptographic systems based on computational complexity present security risks. Therefore, current electronic signature and electronic contract signing systems based on PKI technology present security risks. To address the security threats posed by these inherent flaws, the length of PKI keys has been continuously increased, from 512 bits to 1024 bits, and then to 2048 bits. However, this has not been able to address these inherent security flaws. Summary of the Invention

[0007] In order to solve the above problems, the present invention proposes an electronic contract signing method and system based on electronic signature. The present invention can fundamentally eliminate the security defects of traditional electronic signature algorithms based on PKI and electronic contract signatory methods based on computational security.

[0008] According to some embodiments, the present invention adopts the following technical solutions:

[0009] A method for signing an electronic contract based on an electronic signature, comprising the following steps:

[0010] The first signatory sends a request for the first signatory's electronic signature and a request for random number encryption to the trusted center for the electronic contract to be signed;

[0011] The trusted center verifies the identity information of the first signatory, generates relevant electronic signature information, and encrypts the random number using the signature key and sends it to the first signatory;

[0012] The first signatory generates hidden information of the electronic signature belonging to the first signatory based on the received information and sends it to the other signatories, who then verify the correctness of the hidden information of the electronic signature;

[0013] If the verification result is correct, the other signatories send their own electronic signature request and random number encryption request to the trusted center;

[0014] The trusted center verifies the identity information of the corresponding signatory, generates the electronic signature information of the corresponding signatory, and encrypts the random number using the signature key and sends it to the corresponding signatory;

[0015] The corresponding signatory generates his or her own electronic signature hidden information based on the received information and sends it to the first signatory. The first signatory verifies the correctness of the corresponding signatory's electronic signature hidden information. If it is correct, the first signatory sends a random number to the corresponding signatory. Otherwise, it is considered that a dispute exists and the dispute is resolved.

[0016] The other signatories verify the random number they received, and after successful verification, they send their own random number to the first signatory;

[0017] The first signatory verifies whether the random numbers of other signatories are correct. If they are correct, the electronic contract is successfully signed. Otherwise, it is deemed that there is a dispute and the dispute is resolved.

[0018] As an optional implementation method, the trusted center stores the identity registration information and shared key of each signatory in a database. Each signatory securely stores the shared key and divides the shared key according to the length of each use of the shared key together with the shared key in the trusted center database and synchronizes the sequence numbering.

[0019] As an optional implementation, each shared key is marked as used after use.

[0020] As an optional implementation, the specific process of the first signatory sending the first signatory electronic signature request and random number encryption request for the electronic contract to be signed to the trusted center includes:

[0021] The first signatory selects a random number, encrypts the relevant data using an unused shared key with the trusted center, obtains the ciphertext, and uses another unused shared key with the trusted center to calculate the key-related message authentication code. The first signatory sends an electronic signature request for the electronic contract and an encryption request for the random number to the trusted center, and sends its own identity identification code, the identity identification code of the trusted center, the shared key serial number, the ciphertext and the message authentication code to the trusted center.

[0022] As an optional implementation, the electronic signature information includes the electronic contract, the electronic seal information of the signatories involved in the signing of the electronic contract, a random number, an identity identification code of the trusted center, a timestamp at the time of signing, a signature key serial number, and a message authentication code related to the above data.

[0023] As an optional implementation, the electronic signature hidden information includes a random number ciphertext. The corresponding signatory uses the random number to generate a corresponding message authentication code. After receiving the electronic signature hidden information, the random number is used to replace the ciphertext to verify whether the electronic signature hidden information is correct.

[0024] As an optional implementation, the random number of the corresponding signatory is verified to be correct. If the random number is incorrect, or no random number is received within a set time period, it is deemed that a dispute exists and the dispute is resolved.

[0025] As an optional implementation method, the specific process of dispute resolution includes: the dispute initiator sends the hidden information of the electronic signatures of both parties to the trusted center, and the trusted center verifies the correctness of the hidden information of the electronic signatures of both parties, the consistency of the contract, and the consistency of the electronic seal information of the corresponding signatories. If any of them is incorrect, the dispute resolution process is terminated;

[0026] Otherwise, the trusted center decrypts the random number encrypted ciphertext and sends the other party's random number to the corresponding signer;

[0027] After receiving the random number from the other party, the corresponding signatory uses the random number from the other party to replace the relevant ciphertext in the hidden information of the electronic signature, obtains the electronic signature information of other signatories of the electronic contract, and the electronic contract is successfully signed.

[0028] An electronic contract signing system based on electronic signature, comprising:

[0029] The electronic contract signing server is configured to serve as a trusted third-party execution agency in the electronic contract signing process, distribute shared keys to the signatories of each client through the quantum cryptography network, divide the keys of the true random number digital signature key library according to the length used for each digital signature, receive electronic signature requests, random number encryption requests and electronic signature hidden information, verify identity information and electronic signature hidden information, perform symmetric key signing, generate corresponding electronic signature information, and use the signature key to encrypt the random number and send it to the corresponding client;

[0030] Several clients are configured to provide information services to each signatory during the contract signing process, generate their own electronic signature hidden information, and communicate with other clients and the electronic contract signing server.

[0031] As an optional implementation method, before signing an electronic contract, each client submits an identity registration application to the electronic contract signing server. The registration information includes the electronic seal information of the electronic contract signatory. After the electronic contract signing server accepts the identity registration application, it reviews the submitted materials separately.

[0032] As an optional implementation method, the electronic contract signing server distributes shared keys to the signatories of each client who have passed the review, saves the signatory's identity registration information and shared keys, and the client saves the shared keys and divides the shared keys together with the shared keys in the electronic contract signing server database according to the length of the shared keys each time they are used, and synchronizes the sequence numbering.

[0033] As an optional implementation method, each client and the electronic contract signing server obtain a shared key through quantum key distribution. When the shared key between them is about to be used up, each client uses the unused shared key to perform mutual identity authentication with the electronic contract signing server. After the identity authentication is successful, the electronic contract signing server distributes the quantum key to each client through the quantum secure channel of the quantum cryptography network. Each client and the electronic contract signing server use the unused key to encrypt the newly distributed quantum key, use the ciphertext as the new shared key, and divide the new shared key into keys and number them sequentially.

[0034] Compared with the prior art, the present invention has the following beneficial effects:

[0035] The present invention utilizes a symmetric key algorithm for encryption, has the property of resisting quantum attacks, and fundamentally eliminates the defect that the security of traditional PKI-based electronic signature algorithms and electronic contract signing methods is based on computational security.

[0036] The present invention is implemented based on a quantum cryptography network and realizes one-time-one-pad encryption by adopting a marking method for the used keys, which has unconditional security.

[0037] The present invention embeds the electronic signature information of the signatory in the electronic contract signing, so that the electronic contract has dual credibility and increases the reliability of the electronic contract signing.

[0038] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, preferred embodiments are given below and described in detail with reference to the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0039] The accompanying drawings, which constitute a part of the present invention, are used to provide a further understanding of the present invention. The exemplary embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute improper limitations on the present invention.

[0040] Figure 1 This is a schematic diagram of the parties involved in electronic contract signing;

[0041] Figure 2 This is a flowchart of the electronic contract signing process. DETAILED DESCRIPTION

[0042] The present invention will be further described below with reference to the accompanying drawings and embodiments.

[0043] It should be noted that the following detailed descriptions are illustrative and intended to provide further explanation of the present invention. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the art to which the present invention belongs.

[0044] It should be noted that the terms used herein are only for describing specific embodiments and are not intended to limit the exemplary embodiments according to the present invention. As used herein, unless the context clearly indicates otherwise, the singular form is intended to include the plural form. In addition, it should be understood that when the terms "comprise" and / or "include" are used in this specification, they indicate the presence of features, steps, operations, devices, components and / or combinations thereof.

[0045] like Figure 1 As shown, an example is given in which there are two signatories to the electronic contract, but this does not mean that the solution provided by the present invention is only applicable to this scenario.

[0046] A method for signing an electronic contract based on an electronic signature, comprising the following steps:

[0047] Establish a trusted center and a true random number digital signature key library within the trusted center for digitally signing electronic signature data. Divide the keys in the key library into smaller pieces based on the length used for each digital signature, and number the divided keys sequentially.

[0048] Before signing an electronic contract, the signatory of the electronic contract submits an identity registration application to the Trust Center. The registration information includes the electronic seal information of the signatory of the electronic contract. After the Trust Center accepts the signatory's identity registration application, it will review the materials submitted by the signatory, including the review of the electronic seal information. After the review is passed, the Trust Center distributes a shared key to the signatory. The Trust Center stores the signatory's identity registration information (including electronic seal information) and shared key in the database. The signatory safely stores the shared key and divides the shared key according to the length of each shared key use and synchronizes the sequence numbering together with the shared key in the Trust Center database.

[0049] In this embodiment, to facilitate technical personnel to understand the technical solution, it is assumed that the two parties involved in the signing of the electronic contract are A and B (A and B represent the identity identification codes of the contract signatories, respectively, and A and B have completed identity registration in the trusted center in advance), A's electronic seal information is IDA, B's electronic seal information is IDB, and the contract to be signed by A and B is C (of course, the signatories A and B have already agreed on the content of the electronic contract C in advance). Before the contract is signed, A and B already know each other's electronic seal information IDB and IDA, respectively.

[0050] like Figure 2 As shown in the figure, the electronic contract signing process includes:

[0051] (1) Signatory A sends A's electronic signature request and random number encryption request for electronic contract C to the trusted center.

[0052] In this embodiment, A selects a random number RA and uses the shared key K1 with the trusted center to encrypt the data C||IDA||IDB||RA to obtain the ciphertext E K1 (C||IDA||IDB||RA), and uses the shared key K2 with the trusted center to calculate the key-related message authentication code HMAC(A||TP||E K1 (C||IDA||IDB||RA)||N1||N2; K2)(TP is the identity identification code of the trusted center, N1 and N2 represent the serial numbers of the keys K1 and K2 respectively, and || represents the data connection operation). A sends the electronic signature request of the electronic contract and the encryption request of the random number RA to the trusted center, and sends A, TP, N1, N2, E K1 (C||IDA||IDB||RA) and HMAC(A||TP||E K1 (C||IDA||IDB||RA)||N1||N2; K2) is sent to the trusted center;

[0053] (2) The trusted center verifies A's identity, generates A's electronic signature information for the electronic contract C, encrypts the random number using the signature key, and sends it to A:

[0054] The trusted center receives the electronic signature request sent by A, the encryption request of the random number RA, and the data A, TP, N1, N2, E K1 (C||IDA||IDB||RA) and HMAC(A||TP||E K1 (C||IDA||IDB||RA)||N1||N2; K2), read the shared key K2 with A whose serial number is N2 from the database, and verify HMAC(A||TP||E K1 The correctness of (C||IDA||IDB||RA)||N1||N2; K2). If it is correct, A's identity authentication is successful. The trusted center reads the shared key K1 with serial number N1 from the database to decrypt E. K1 (C||IDA||IDB||RA) obtains data C||IDA||IDB||RA;

[0055] The trusted center verifies the correctness of the electronic seal information IDA according to the database records. If it is correct, the trusted center reads the key SK1 with the serial number SN1 from the signature key library to perform a symmetric key signature on the data C||IDA||IDB||RA, and obtains the data as HMAC(C||IDA||IDB||RA||TP||TS||SN1;SK1), where TS is the timestamp of the signature, SN1 is the serial number of the signature key SK1, and DS A =C||IDA||IDB||RA||TP||TS||SN1||HMAC(C||IDA||IDB||RA||TP||TS||SN1;SK1) is the electronic signature information of A in the electronic contract C. RA is encrypted with SK1 to obtain the ciphertext E(RA). The trusted center encrypts DS using the shared key with A. A ||E(RA), and calculate the message authentication code of the ciphertext, and convert DS A ||E(RA) ciphertext and its message authentication code are sent to A;

[0056] (3) Signatory A receives the electronic signature information and random number encryption information of A of electronic contract C sent by the trusted center, generates the hidden information of A of electronic signature of electronic contract C, and sends it to B, who verifies the correctness of the hidden information of A of electronic signature of electronic contract C.

[0057] A receives DS A || After E(RA) ciphertext and its message authentication code, the data DS is verified by the message authentication code A ||E(RA) The legitimacy of the encrypted data. If the verification is successful, the shared key with the trusted center is used to decrypt DS. A ||E(RA) ciphertext, obtain data DS Aand E(RA), save DS A , send ms1 = C||IDA||IDB||E(RA)||TP||TS||SN1||HMAC(C||IDA||IDB||RA||TP||TS||SN1; SK1) to B. After B receives the data, B goes to the trusted center to verify the correctness of ms1 (the trusted center verifies that RA is obtained by decrypting E(RA) using the signature key SK1 with serial number SN1, and verifies whether the message authentication code related to the key SK1 of the data C||IDA||IDB||RA||TP||TS||SN1 is HMAC(C||IDA||IDB||RA||TP||TS||SN1; SK1)). If the verification result is wrong, the electronic contract signing process is terminated, otherwise proceed to step (4).

[0058] (4) If B verifies that the hidden information of A's electronic signature of electronic contract C is correct, B sends a request for B's electronic signature of electronic contract C and a request for random number encryption to the trusted center.

[0059] Signer B selects a random number RB and uses the shared key K3 with the trusted center to encrypt the data C||IDB||IDA||RB to obtain the ciphertext E K3 (C||IDB||IDA||RB), and use the shared key K4 with the trusted center to calculate the key-related message authentication code HMAC(B||TP||E K3 (C||IDB||IDA||RB)||N3||N4; K4)(TP is the identity identification code of the trusted center, N3 and N4 represent the serial numbers of the keys K3 and K4 respectively, || represents the data connection operation), B sends the electronic signature request of the electronic contract and the encryption request of the random number RB to the trusted center, and sends B, TP, N3, N4, E K3 (C||IDB||IDA||RB) and HMAC(B||TP||E K3 (C||IDB||IDA||RB)||N3||N4; K4) is sent to the trusted center.

[0060] Mark keys K3 and K4 as used.

[0061] (5) The trusted center verifies B’s identity, generates B’s electronic signature information for the electronic contract C, encrypts the random number using the signature key, and sends it to B.

[0062] The trusted center receives the electronic signature request sent by B, the encryption request of the random number RB, and the data B, TP, N3, N4, E K3 (C||IDB||IDA||RB) and HMAC(B||TP||E K3(C||IDB||IDA||RB)||N3||N4; K4), read the shared key K4 with B with the serial number N4 from the database, and verify HMAC(B||TP||E K3 The correctness of (C||IDB||IDA||RB)||N3||N4; K4). If it is correct, B's identity authentication is successful. The trusted center reads the shared key K3 with the serial number N3 from the database to decrypt E. K3 (C||IDB||IDA||RB) obtains data C||IDB||IDA||RB;

[0063] The trusted center verifies the correctness of the electronic seal information IDB according to the database records. If it is correct, the trusted center reads the key SK2 with the serial number SN2 from the signature key library to perform a symmetric key signature on the data C||IDB||IDA||RB, and obtains the data as HMAC(C||IDB||IDA||RB||TP||TS||SN2;SK2), where TS is the timestamp of the signature, SN2 is the serial number of the signature key SK2, and DS B =C||IDB||IDA||RB||TP||TS||SN2||HMAC(C||IDB||IDA||RB||TP||TS||SN2;SK2) is the electronic signature information of B in the electronic contract C. RB is encrypted with SK2 to obtain the ciphertext E(RB). The trusted center encrypts DS using the shared key with B. B ||E(RB), and calculate the message authentication code of the ciphertext, and convert DS B ||E(RB) ciphertext and its message authentication code are sent to B.

[0064] (6) Signatory B receives the electronic signature information and random number encryption information of B of electronic contract C sent by the trusted center, generates the hidden electronic signature information of B of electronic contract C, and sends it to A. A verifies the correctness of the hidden electronic signature information of B of electronic contract C.

[0065] Signatory B receives DS B || After E(RB) ciphertext and its message authentication code, the data DS is verified by the message authentication code B ||E(RB) The legitimacy of the ciphertext data. If the verification is successful, the shared key with the trusted center is used to decrypt DS. B ||E(RB) ciphertext, obtain data DS B and E(RB), save DS B, send ms2 = C||IDB||IDA||E(RB)||TP||TS||SN2||HMAC(C||IDB||IDA||RB||TP||TS||SN2; SK2) to A. After receiving the data, A goes to the trusted center to verify the correctness of ms2 (the trusted center verifies whether the message authentication code related to the key SK2 of the data C||IDB||IDA||RB||TP||TS||SN2 is HMAC(C||IDB||IDA||RB||TP||TS||SN2; SK2) after decrypting E(RB) using the signature key SK2 with serial number SN2. If the verification result is wrong, the electronic contract signing process is terminated, otherwise proceed to step (7).

[0066] (7) Signatory A sends the random number to B, who verifies the correctness of the random number. If it is incorrect or the random number is not received, a dispute resolution agreement is initiated.

[0067] Signer A sends the random number RA to B. After receiving RA, B replaces E(RA) in ms1 with RA and verifies with the trusted center whether the message authentication code value of the key SK1 of the data C||IDA||IDB||RA||TP||TS||SN1 is equal to HMAC(C||IDA||IDB||RA||TP||TS||SN1; SK1). If the verification is successful, B sends the random number RB to A. If the verification fails, B can initiate the dispute resolution agreement process.

[0068] (8) A verifies the correctness of the random number sent by B. If it is correct, the electronic contract is successfully signed. If it is incorrect or the random number sent by B is not received, A initiates the dispute resolution agreement processing process.

[0069] After receiving RB, signer A uses RB to replace E(RB) in ms2 and goes to the trusted center to verify whether the message authentication code value of the key SK2 of the data C||IDB||IDA||E(RB)||TP||TS||SN2 is equal to HMAC(C||IDB||IDA||RB||TP||TS||SN2; SK2). If the verification is successful, the signing process of the electronic contract C is completed. Otherwise, A can initiate the dispute resolution agreement processing process.

[0070] If B sends ms2 but does not receive an RA from A or receives an incorrect RA, B can initiate a dispute resolution agreement. If A sends a correct RA but does not receive an RB from B or receives an incorrect RB, A can initiate a dispute resolution agreement process, which includes:

[0071] (a) If A initiates the dispute resolution agreement, A sends ms1 and ms2 to the trusted center. If B initiates the dispute resolution agreement, B sends ms1 and ms2 to the trusted center. The trusted center verifies the correctness of ms1 and ms2, the consistency of contract C in ms1 and ms2, and the consistency of IDA and IDB in ms1 and ms2. If any one of them is incorrect, the dispute resolution agreement is terminated. If all are correct, the next step is carried out.

[0072] (b) The trusted center uses the signature key SK1 with serial number SN1 to decrypt E(RA) in ms1 and obtain RA; it uses the signature key SK2 with serial number SN2 to decrypt E(RB) in ms2 and obtain RB. The trusted center uses the shared key with A to encrypt RB and send it to A, and uses the shared key with B to encrypt RA and send it to B.

[0073] (c) After receiving RB, A uses RB to replace E(RB) in ms2 to obtain B’s electronic signature information DS of electronic contract C. B After receiving RA, B uses RA to replace E(RA) in ms1 to obtain A's electronic signature information DS of electronic contract C. A , the electronic contract was signed successfully.

[0074] To implement the above method steps, an electronic contract signing system based on electronic signatures is constructed, including a trusted center and multiple electronic contract signatories. Of course, in the specific implementation, the trusted center can be executed by the server and the electronic contract signatories can be executed by the client device.

[0075] The Trust Center is a trusted third-party organization. It maintains a true random number signature key library for digitally signing electronic signature data. The keys in the signature key library are divided according to the length used for each digital signature, and the divided keys are sequentially numbered. The Trust Center stores each signature key and its serial number until the key's validity period expires. The Trust Center can increase the number of signature keys in the key library based on signature requirements.

[0076] Before signing an electronic contract, the signatory of the electronic contract submits an identity registration application to the Trust Center. The registration information includes the electronic seal information of the signatory of the electronic contract. After the Trust Center accepts the signatory's identity registration application, it will review the materials submitted by the signatory, including the review of the electronic seal information. After the review is passed, the Trust Center distributes a shared key to the signatory. The Trust Center stores the signatory's identity registration information (including electronic seal information) and shared key in the database. The signatory safely stores the shared key and divides the shared key according to the length of each shared key use and synchronizes the sequence numbering together with the shared key in the Trust Center database.

[0077] The trusted center and the electronic contract signatory obtain a shared key through quantum key distribution. When the shared key between them is about to be used up, the electronic contract signatory uses the unused shared key to perform mutual identity authentication with the trusted center. After the identity authentication is successful, the trusted center distributes the quantum key to the electronic contract signatory through the quantum secure channel of the quantum cryptography network. The trusted center and the electronic contract signatory use the unused key to encrypt the newly distributed quantum key, use the ciphertext as the new shared key, divide the new shared key into keys and number them sequentially.

[0078] It will be understood by those skilled in the art that embodiments of the present invention may be provided as methods, systems, or computer program products. Thus, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0079] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowcharts and / or block diagrams, as well as combinations of processes and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowcharts and / or block diagrams. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0080] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0081] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0082] The foregoing description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. Those skilled in the art will readily appreciate that various modifications and variations of the present invention are possible. Any modifications, equivalent substitutions, or improvements made within the spirit and principles of the present invention are intended to be within the scope of protection of the present invention.

[0083] Although the above describes the specific embodiments of the present invention in conjunction with the accompanying drawings, it is not intended to limit the scope of protection of the present invention. Those skilled in the art should understand that various modifications or variations that can be made by those skilled in the art on the basis of the technical solution of the present invention without any creative work are still within the scope of protection of the present invention.

Claims

1. A method for signing an electronic contract based on an electronic signature, characterized by: The following steps are involved: The trusted center has a true random number signature key library, which is used for digital signature of electronic signature data. The keys in the signature key library are divided according to the length used for each digital signature, and the divided keys are numbered sequentially. Before signing an electronic contract, the signatory submits an identity registration application to the Trust Center. The registration information includes the electronic seal information of the signatory. After the Trust Center accepts the signatory's identity registration application, it reviews the materials submitted by the signatory. If the review is qualified, the Trust Center distributes a shared key to the signatory. The Trust Center stores each signatory's identity registration information and shared key in the database. Each signatory securely stores the shared key and divides the shared key according to the length of each shared key used, along with the shared key in the Trust Center database, and synchronizes the shared key with the shared key in sequence. The trusted center and the electronic contract signatory obtain a shared key through quantum key distribution. When the shared key between them is about to be used up, the electronic contract signatory uses the unused shared key to perform mutual identity authentication with the trusted center. After the identity authentication is successful, the trusted center distributes the quantum key to the electronic contract signatory through the quantum secure channel of the quantum cryptography network. The trusted center and the electronic contract signatory use the unused key to encrypt the newly distributed quantum key, use the ciphertext as the new shared key, divide the new shared key into keys and number them sequentially. The first signatory sends a request for the first signatory's electronic signature and a request for random number encryption to the trusted center for the electronic contract to be signed; The trusted center verifies the identity information of the first signatory, generates relevant electronic signature information, and encrypts the random number using the signature key and sends it to the first signatory; The first signatory generates hidden information of the electronic signature belonging to the first signatory based on the received information and sends it to the other signatories, who then verify the correctness of the hidden information of the electronic signature; If the verification result is correct, the other signatories send their own electronic signature request and random number encryption request to the trusted center; The trusted center verifies the identity information of the corresponding signatory, generates the relevant electronic signature information of the corresponding signatory, and encrypts the random number using the signature key and sends it to the corresponding signatory; The corresponding signatory generates his or her own electronic signature hidden information based on the received information and sends it to the first signatory. The first signatory verifies the correctness of the corresponding signatory's electronic signature hidden information. If it is correct, the first signatory sends a random number to the corresponding signatory. Otherwise, it is considered that a dispute exists and the dispute is resolved. The other signatories verify the random number they received, and after successful verification, they send their own random number to the first signatory; The first signatory verifies whether the random numbers of other signatories are correct. If they are correct, the electronic contract is successfully signed. Otherwise, it is deemed that there is a dispute and the dispute is resolved.

2. The electronic contract signing method based on electronic signature according to claim 1, characterized in that: Furthermore, each shared key is marked as used after use.

3. The electronic contract signing method based on electronic signature according to claim 1, characterized in that: The specific process of the first signatory sending the first signatory's electronic signature request and random number encryption request for the electronic contract to be signed to the trusted center includes: The first signatory selects a random number, encrypts the relevant data using an unused shared key with the trusted center, obtains the ciphertext, and uses another unused shared key with the trusted center to calculate the key-related message authentication code. The first signatory sends an electronic signature request for the electronic contract and an encryption request for the random number to the trusted center, and sends its own identity identification code, the identity identification code of the trusted center, the shared key serial number, the ciphertext and the message authentication code to the trusted center.

4. The electronic contract signing method based on electronic signature according to claim 1, characterized in that: The electronic signature information includes the electronic contract, the electronic seal information of the signatories involved in the signing of the electronic contract, a random number, the identity identification code of the trusted center, the timestamp of the signature, the signature key serial number, and the message authentication code related to the above data.

5. The electronic contract signing method based on electronic signature according to claim 1, characterized in that: The electronic signature hidden information includes a random number ciphertext. The corresponding signatory uses the random number to generate a corresponding message authentication code. After receiving the electronic signature hidden information, the signatory uses the random number to replace the ciphertext to verify whether the electronic signature hidden information is correct.

6. The electronic contract signing method based on electronic signature according to claim 1, characterized in that: Verify that the random number of the corresponding signatory is correct. If the random number is incorrect, or if no random number is received within the set time period, it is considered a dispute and the dispute is resolved; Alternatively, the specific process of resolving a dispute includes: the dispute initiator sends the hidden information of the electronic signatures of both parties to the trusted center, and the trusted center verifies the correctness of the hidden information of the electronic signatures of both parties, the consistency of the contract, and the consistency of the electronic seal information of the corresponding signatories. If any of them is incorrect, the dispute resolution is stopped; Otherwise, the trusted center decrypts the random number encrypted ciphertext and sends the other party's random number to the corresponding signer; After receiving the random number from the other party, the corresponding signatory uses the random number from the other party to replace the relevant ciphertext in the hidden information of the electronic signature, obtains the electronic signature information of other signatories of the electronic contract, and the electronic contract is successfully signed.

7. An electronic contract signing system based on electronic signature, characterized by: include: The electronic contract signing server is configured to serve as a trusted third-party execution agency in the electronic contract signing process, distribute shared keys to the signatories of each client through the quantum cryptography network, divide the keys of the true random number digital signature key library according to the length used for each digital signature, receive electronic signature requests, random number encryption requests and electronic signature hidden information, verify identity information and electronic signature hidden information, perform symmetric key signing, generate corresponding electronic signature information, and use the signature key to encrypt the random number and send it to the corresponding client; Several clients are configured to provide information services to each signatory during the contract signing process, generate their own hidden electronic signature information, and communicate with other clients and the electronic contract signing server; Before signing an electronic contract, each client submits an identity registration application to the electronic contract signing server. The registration information includes the electronic seal information of the electronic contract signatory. After the electronic contract signing server accepts the identity registration application, it will review the submitted materials separately. The electronic contract signing server distributes a shared key to the signatories of each client who has passed the review, saves the signatory's identity registration information and the shared key, and the client saves the shared key and divides the shared key according to the length of each shared key used and synchronizes the sequence numbering together with the shared key in the electronic contract signing server database; Each client and the electronic contract signing server obtain a shared key through quantum key distribution. When the shared key between them is about to be used up, each client uses the unused shared key to perform mutual identity authentication with the electronic contract signing server. After the identity authentication is successful, the electronic contract signing server distributes the quantum key to each client through the quantum secure channel of the quantum cryptography network. Each client and the electronic contract signing server use the unused key to encrypt the newly distributed quantum key, use the ciphertext as the new shared key, divide the new shared key into keys and number them sequentially.

Citation Information

Patent Citations

  • Electronic contract signing method and device and server

    CN107844946A

  • Signing method and signing system resistant to quantum computation based on public key pool

    CN109600228A