A method, system and device for adapting PDF signature syntax to national standards
By generating PDF signature objects and embedding GM0010 and GM0031 signature formats, the problem of PKCS7 being incompatible with GM/T0010 and GM/T0031 is solved, and the country label name specification of PDF files is compatible, improving the user experience of PDF readers.
Patent Information
- Application Number
- CN202211055120.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-08-30
- Publication Date
- 2025-07-29
- Estimated Expiration
- 2042-08-30
AI Technical Summary
In the prior art, the signature specification of PKCS7 is incompatible with the national secret signature standards of GM/T0010 and GM/T0031, resulting in the PDF reader being unable to be compatible with the national label name specification after the standard conversion, affecting the user experience.
Generate PDF signature objects, perform signature preprocessing, and embed pre-built GM0010 and GM0031 signature formats into the signature object. The GM0010 and GM0031 data structures are generated through the hash algorithm and the signature process calculator to form the results of adapting PDF signatures.
It solves the problem of PDF reader identification after standard conversion, and realizes compatibility between GM0010 and GM0031 signature data formats, improving user experience.
Smart Images

Figure CN115396120B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the fields of software development and digital signature technology, and particularly to a method, system, and device for adapting the national standard to the PDF signature syntax. Background Art
[0002] In the related art, the signature specification of PKCS7 is not compatible with the national cryptographic signature standards of GM / T0010 and GM / T0031. After converting from foreign standards to domestic standards, problems occur in the format recognition of pdf readers, which cannot be compatible with the national standard signature specification and cannot provide a better experience for readers. Summary of the Invention
[0003] To at least overcome to some extent the problems in the related art that the format recognition of pdf readers has problems and cannot be compatible with the national standard signature specification, this application provides a method, system, and device for adapting the national standard to the PDF signature syntax.
[0004] The solution of this application is as follows:
[0005] In a first aspect, this application provides a method for adapting the national standard to the PDF signature syntax, and the method includes:
[0006] Generate a PDF signature object and perform signature preprocessing;
[0007] Based on the signature preprocessing, embed the pre-constructed signature formats of GM0010 and GM0031 into the signature object to obtain the results of adapting GM0010 and GM0031 to the PDF signature.
[0008] Further, the signature preprocessing includes: generating a hash algorithm calculator and a signature process calculator.
[0009] Further, the PDF signature object includes: storing the original data to be signed.
[0010] Further, the steps of constructing the signature format of GM0010 include:
[0011] S1. Based on the PDF signature object and the signature preprocessing, establish a signature attribute dictionary and reserve the storage space for the signature format of GM0010;
[0012] S2. Based on the attribute dictionary and the storage space, obtain the signature format of GM0010 through GM0010 data encoding.
[0013] Further, the GM0010 data encoding includes:
[0014] Based on the attribute dictionary and the storage space, through the hash algorithm calculator and the signature process calculator, perform combined processing to obtain a GM0010 data structure generator;
[0015] Based on the GM0010 data structure generator, perform a hash operation on the original data to be signed and generate a signed data encoding to obtain a data encoding in the GM0010 structure.
[0016] Further, the steps of constructing the signature format of GM0031 include:
[0017] S1. Based on the PDF signature object and the signature preprocessing, establish a signature attribute dictionary and reserve a storage space for the signature format of GM0031;
[0018] S2. Based on the attribute dictionary and the storage space, obtain the signature format of GM0031 through GM0031 data encoding.
[0019] Further, the GM0031 data encoding includes:
[0020] Based on the attribute dictionary and the storage space, through the hash algorithm calculator and the signature process calculator, perform combined processing to obtain a GM0031 data structure generator;
[0021] Based on the GM0031 data structure generator, perform a hash operation on the original data to be signed and generate a signed data encoding to obtain a data encoding in the GM0031 structure.
[0022] In a second aspect, the present application provides a system for adapting national standard PDF signature syntax, the system includes:
[0023] A signature preprocessing module, configured to generate a PDF signature object and perform signature preprocessing;
[0024] A signature format adaptation module, configured to embed the pre-constructed signature formats of GM0010 and GM0031 into the signature object based on the signature preprocessing to obtain the results of adapting GM0010 and GM0031 to PDF signatures.
[0025] In a third aspect, the present application provides a device for adapting national standard PDF signature syntax, the device includes:
[0026] A processor and a memory;
[0027] The memory has an executable program stored thereon;
[0028] A processor for executing the executable program in the memory to implement the steps of the method described in any one of the above.
[0029] The technical solution provided by this application may include the following beneficial effects:
[0030] By generating a PDF signature object and performing signature preprocessing; based on the signature preprocessing, embedding the pre-constructed signature formats of GM0010 and GM0031 into the signature object to obtain the results of GM0010 and GM0031 adapted to PDF signatures. This application helps to solve the problem that after converting from foreign standards to domestic standards, the format recognition of the pdf reader has problems and cannot be compatible with the signature specifications of national standards. By embedding GM0010 and GM0031 into the PDF file, the PDF file can use these two signature data formats of GM0010 and GM0031, giving users of the pdf reader a better user experience.
[0031] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit this application. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] The drawings herein are incorporated into the specification and constitute a part of this specification, showing embodiments consistent with this application, and are used together with the specification to explain the principles of this application.
[0033] Figure 1 is a schematic flowchart of a method for adapting national standard to PDF signature syntax provided by an embodiment of this application;
[0034] Figure 2 is a schematic diagram of the system structure composition of a national standard adapted PDF signature syntax provided by another embodiment of this application;
[0035] Figure 3 is a schematic diagram of the device structure of a national standard adapted PDF signature syntax provided by another embodiment of this application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0036] Here, the exemplary embodiments will be described in detail, and the examples are shown in the drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. On the contrary, they are only examples of devices and methods consistent with some aspects of this application as detailed in the appended claims.
[0037] Figure 1 is a schematic flowchart of a method for adapting national standard to PDF signature syntax provided by an embodiment of this application. AsFigure 1 As shown in the figure, this embodiment provides a method for adapting the national standard to the PDF signature syntax, including the following content:
[0038] S1. Generate a PDF signature object and perform signature preprocessing, where the signature preprocessing includes: GM0010 signature preprocessing and GM0031 signature preprocessing;
[0039] S2. Based on the signature preprocessing, embed the pre-constructed signature formats of GM0010 and GM0031 into the signature object to obtain the results of adapting GM0010 and GM0031 to the PDF signature.
[0040] GM0010 can also be expressed as GM / T0010, and GM0031 can also be expressed as GM / T0031;
[0041] The PDF signature object can also be expressed as a signature appearance object or others.
[0042] In the embodiment of the present application, in the signature technology of the PDF file, there is no signature entry. It is a PdfSignature object, which includes the relevant attributes of the signature, mainly including:
[0043] Type and Sig indicate that this is a signature object; Location indicates the signature location;
[0044] ContactInfo indicates the contact information; Filter and Adobe.PPKLite indicate the name of the reader signature validator; SubFilter and adbe.pkcs7.detached indicate the rules of the verification method used by the signature validator; M indicates the signature time of the signature generator; ByteRange indicates the range of the byte stream of the range of the PDF file protected by the signature; Contents indicates the encoded data packet of the signature result.
[0045] In one embodiment, for the PDF file signature using the PKCS7 signature specification, it is necessary to create a PdfSignature with Filter set to Adobe.PPKLite and SubFilter set to adbe.pkcs7.detached to solve the signature encoding formats of GM0010 and GM0031, so that they can be compatibly embedded into the PDF file, and then the different attributes in the PdfSignature object can be used to distinguish from the standard PKCS7 signature standard format.
[0046] In the embodiment of the present application, as described in step S1, the process of performing GM0010 signature preprocessing includes the following steps:
[0047] 1. First, generate an object for the appearance of the PDF signature, specifically by using the stamper.getSignatureAppearance function. This object is a dictionary object in the PDF file used to express the appearance attributes, mainly including the following attributes:
[0048] Use the appearance.setVisibleSignature function to set the appearance of the signature to a visual appearance, set the size and page of the rectangle of the visual image, and the name of this appearance.
[0049] Use the appearance.setSignatureGraphic function to set the image data associated with this signature appearance.
[0050] Then, generate the following attributes of the signature appearance, as shown in Table 1.
[0051] Table 1
[0052]
[0053]
[0054] S1.1GM0010 Process of signature preprocessing:
[0055] S1.1.1 First, generate a PDF signature appearance object. Specifically, use the stamper.getSignatureAppearance function to generate a PDF signature appearance object, name the generated signature appearance object as appearance, and store appearance in the PdfSignatureAppearance class, as shown below: PdfSignatureAppearance appearance = stamper.getSignatureAppearance();
[0056] S1.1.2 Generate a hash algorithm calculator. Specifically, use the BouncyCastleDigest() function to generate the hash algorithm calculator digest, specifically as ExternalDigest digest = new BouncyCastleDigest()
[0057] S1.1.3 Generate a signature process calculator. Specifically, a signature process calculator is generated through the function PdfSM23Signature(prk, "SM3", "BC", chain[0], Parameter). Name the calculator es and store it in the ExternalSignature class, specifically expressed as: ExternalSignature es = new PdfSM23Signature(prk, "SM3", "BC", chain[0], Parameter); This calculator will execute the signature process of GM / T 0010;
[0058] Call the function GMMakeSignature.signDetached(appearance, digest, es, chain, null, null, null, 0, CryptoStandard.CMS), and the process of executing the signature will be entered.
[0059] In this embodiment, the preprocessing of the GM0031 signature includes the following steps:
[0060] 2. The process of generating a signature is actually to generate each attribute of the signature field. The attributes of the signature field are as shown in Table 2.
[0061] Table 2
[0062]
[0063] S1.2 The preprocessing process of the GM0031 signature format:
[0064] S1.2.1 First, generate a PDF signature appearance object. Specifically, the signature appearance object is generated through the function stamper.getSignatureAppearance, specifically: PdfSignatureAppearance appearance = stamper.getSignatureAppearance;
[0065] Generate a hash algorithm calculator ExternalDigest digest = new BouncyCastleDigest();
[0066] S1.2.3 Generate a signature process calculator that complies with GM / T 0031 through the new GM0031PdfSM23Signature(prk, "SM3", "BC", chain[0], sealBytes) function, ExternalSignature es = newGM0031PdfSM23Signature(prk, "SM3", "BC", chain[0], sealBytes); this calculator will execute the signature process of GM / T 0031.
[0067] Call the GM0031MakeSignature.signDetached(appearance, digest, es, chain, null, null, null, sealBytes.length * 2, CryptoStandard.CMS) function, and the signature execution process will start.
[0068] In the embodiment of this application, for step S2, the construction of the signature format of GM0010 includes the following content:
[0069] S2.1 First, create and declare a constant, static final PdfName GM0010 = new PdfName("GM0010");
[0070] This constant will declare the label of GM0010 to represent, which represents the support for the GM0010 signature rule.
[0071] S2.1.1 First, establish a property dictionary for the signer, PdfSignaturedic = new PdfSignature(PdfName.GM0010, PdfName.GM0010);
[0072] Set some properties for the dictionary,
[0073] For example, set the reason for the signature: dic.setReason(sap.getReason());
[0074] For example, set the location of the signature: dic.setLocation(sap.getLocation());
[0075] For example, set the name of the signer:
[0076] dic.setSignatureCreator(sap.getSignatureCreator());
[0077] As set, the contact information of the signer: dic.setContact(sap.getContact());
[0078] Set this dictionary to the signature appearance object sap.setCryptoDictionary(dic);
[0079] S2.1.2 In advance, reserve the storage space to be embedded in the PDF file. The reserved space should be sufficient to ensure that the generated GM / T 0010 data does not exceed the range, as follows:
[0080] HashMap<PdfName, Integer> exc = new HashMap<PdfName, Integer>();
[0081] exc.put(PdfName.CONTENTS, new Integer(estimatedSize * 2 + 2));
[0082] sap.preClose(exc);
[0083] S2.1.3 Generate a generator for encoding GM / T 0010 data. The generator is generated by the externalSignature.get HASH Algorithm() function. The generator will be combined with the signature process to generate a signature in the GM / T 0010 data format, as follows:
[0084] String HASH Algorithm = externalSignature.get HASH Algorithm(); GMPdfPKCS7 sgn = new GMPdfPKCS7(null, chain, HashAlgorithm, null, externalDigest, false);
[0085] S2.1.4 Obtain the original text data to be signed from the signature appearance object, and then calculate the hash value of these original text data. InputStream data = sap.getRangeStream();
[0086] Hash = GMPdfPKCS7.digest(data, GMPdfPKCS7.SM3, "BC");
[0087] S2.1.5 Pass the calculated hash value of the original text to the function getAuthenticatedAttributeBytes(Hash, ocsp, crlBytes, sigtype) to produce the encoding of the data to be signed, specifically: byte[] sh = sgn.getAuthenticatedAttributeBytes(Hash, ocsp, crlBytes, sigtype).
[0088] S2.1.6 Pass the encoding of the data to be signed to the signature function externalSignature to generate the signature result byte[] extSignature = externalSignature.sign(sh).
[0089] S2.2 Set the calculated signature result to the data structure generator of GM / T0010 to form the data encoding of the GM / T0010 structure, and embed the pre - constructed signature format of GM0010 into the signature object to obtain the result of GM0010 - adapted PDF signature;
[0090] sgn.setExternalDigest(extSignature, null, externalSignature.getEncryptionAlgorithm());
[0091] byte[] encodedSig = sgn.getEncodedPKCS7(Hash, tsaClient, ocsp, crlBytes, sigtype).
[0092] In the embodiment of the present application, for step S2, constructing the signature format of GM0031 includes the following content:
[0093] S2.3 First, create a constant and declare it, static final PdfName GM0031 = new PdfName("GM0031");
[0094] This constant will declare the label of GM0031 to represent the support for the GM0031 signature rule.
[0095] S2.3.1 First, establish a property dictionary for the signer, PdfSignaturedic = new PdfSignature(PdfName.GM0031, PdfName.GM0031);
[0096] Set some properties for the dictionary,
[0097] dic.setLocation(sap.getLocation());
[0098] dic.setSignatureCreator(sap.getSignatureCreator());
[0099] dic.setContact(sap.getContact());
[0100] Set this dictionary to the signature appearance object sap.setCryptoDictionary(dic);
[0101] S2.3.2 In advance, reserve the storage space to be embedded in the PDF file.
[0102] HashMap<PdfName, Integer> exc = new HashMap<PdfName, Integer>(); exc.put(PdfName.CONTENTS, new Integer(estimatedSize * 2 + 2)); sap.preClose(exc); The reserved space should be sufficient to ensure that the data generated by GM / T 0031 does not exceed the range.
[0103] S2.3.3 Read the original text of the data to be signed from the signer appearance object.
[0104] InputStream data = sap.getRangeStream();
[0105] byte[] toSigning = readSigningData(data);
[0106] S2.3.4 Pass the original text of the data to be signed to the GM / T 0031 signature generator to generate the signature data encoding that conforms to the GM / T 0031 structure byte[] encodedSig = externalSignature.sign(toSigning);
[0107] S2.4 Embed the encoding of the data structure data generated by GM / T 0031 into the signature appearance object, that is, embed it into the PDF file, so as to complete the combination of the GM / T 0031 signature format and the PDF file signature format.
[0108] byte[] paddedSig = new byte[estimatedSize];
[0109] System.arraycopy(encodedSig, 0, paddedSig, 0, encodedSig.length);
[0110] PdfDictionary dic2 = new PdfDictionary();
[0111] dic2.put(PdfName.CONTENTS, new PdfString(paddedSig).setHexWriting(true));
[0112] sap.close(dic2);
[0113] In one embodiment, a method for improving based on a reader plug-in, after converting from a foreign standard to a domestic standard, solves the problem of format recognition of the pdf reader to overcome the compatibility problem.
[0114] In one embodiment, by generating a PDF signature object, signature preprocessing is performed; based on the signature preprocessing, the signature formats of GM0010 and GM0031 pre-constructed are embedded into the signature object to obtain the results of GM0010 and GM0031 adapted to the PDF signature. This application helps to solve the problem that after converting from a foreign standard to a domestic standard, the format recognition of the pdf reader has problems and cannot be compatible with the national standard signature specification. By embedding GM0010 and GM0031 into the PDF file, the PDF file can use the two signature data formats of GM0010 and GM0031, giving a better user experience to the users of the pdf reader.
[0115] Embodiment 2
[0116] Figure 2 It is a schematic diagram of the system structure composition of a national standard adapted PDF signature syntax provided by another embodiment of the present application. As Figure 2 shown, the embodiment of the present application provides a system for configuring a PDF signature syntax, including the following:
[0117] A signature preprocessing module 101, used to generate a PDF signature object and perform signature preprocessing;
[0118] The signature format adaptation module 102 is used to embed the pre - constructed signature formats of GM0010 and GM0031 into the signature object based on the signature pre - processing, so as to obtain the results of GM0010 and GM0031 adapted to the PDF signature.
[0119] Embodiment III
[0120] Figure 3 It is a schematic structural diagram of a device for adapting the national standard to the PDF signature syntax provided by another embodiment of the present application. As Figure 3 shown, the embodiment of the present application provides a device for adapting the PDF signature syntax, including the following:
[0121] A processor 31 and a memory 32;
[0122] The memory 31 stores an executable program thereon;
[0123] The processor 32 is used to execute the executable program in the memory 31 to implement the steps of the method described in any one of the above.
[0124] It can be understood that the same or similar parts in the above - mentioned embodiments can be referred to each other, and the content not detailed in some embodiments can be seen in the same or similar content of other embodiments.
[0125] It should be noted that in the description of the present application, terms such as "first", "second", etc. are only used for descriptive purposes and cannot be understood as indicating or implying relative importance. In addition, in the description of the present application, unless otherwise specified, the meaning of "a plurality of" refers to at least two.
[0126] Any process or method description in the flowchart or described in other ways herein can be understood as representing a module, segment, or part of code including one or more executable instructions for implementing a specific logical function or process. And the scope of the preferred embodiments of the present application includes additional implementations, where the functions can be executed in a manner that is not in the order shown or discussed, including in a substantially simultaneous manner according to the functions involved or in the reverse order, which should be understood by those skilled in the technical field to which the embodiments of the present application belong.
[0127] It should be understood that various parts of the present application can be implemented by hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented by hardware, as in another embodiment, any one or a combination of the following techniques well known in the art can be used: discrete logic circuits having logic gate circuits for implementing logical functions on data signals, application specific integrated circuits having appropriate combinational logic gate circuits, programmable gate arrays (PGAs), field programmable gate arrays (FPGAs), etc.
[0128] Those of ordinary skill in the art can understand that all or part of the steps carried by the methods in the above embodiments can be completed by instructing relevant hardware through a program, and the program can be stored in a computer-readable device. When the program is executed, it includes one or a combination of the steps of the method embodiments.
[0129] In addition, in each embodiment of the present application, each functional unit can be integrated into a processing module, or each unit can exist physically alone, or two or more units can be integrated into one module. The above integrated module can be implemented in the form of hardware or in the form of a software functional module. When the above integrated module is implemented in the form of a software functional module and sold or used as an independent product, it can also be stored in a computer-readable device.
[0130] The above-mentioned device can be a read-only memory, a magnetic disk, an optical disk, etc.
[0131] In the description of this specification, the description with reference to terms such as "one embodiment", "some embodiments", "example", "specific example", or "some examples" means that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present application. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described can be combined in a suitable manner in any one or more embodiments or examples.
[0132] Although the embodiments of the present application have been shown and described above, it can be understood that the above embodiments are exemplary and should not be construed as limiting the present application. Those of ordinary skill in the art can make changes, modifications, substitutions, and variations to the above embodiments within the scope of the present application.
Claims
1. A method for adapting PDF signature syntax to national standards, characterized in that, include: Generate PDF signature object and perform signature preprocessing; Based on the signature preprocessing, the pre-built GM0010 signature format and GM0031 signature format are embedded into the signature object to obtain the results of GM0010 and GM0031 adapted PDF signature; The signature preprocessing includes: generating a hash algorithm calculator and a signature process calculator; The PDF signature object includes: storing the original data to be signed; The steps of constructing the signature format of GM0010 include: S1. Based on the PDF signature object and the signature preprocessor, establish a signature attribute dictionary and reserve storage space for the GM0010 signature format; S2. Based on the attribute dictionary and storage space, GM0010 data encoding, get the signature format of GM0010; The GM0010 data encoding includes: Based on the attribute dictionary and storage space, the hash algorithm calculator and the signature process calculator are combined to obtain a GM0010 data structure generator; Based on the GM0010 data structure generator, the original data to be signed is hashed and the signature data code is generated to obtain the data code of the GM0010 structure; The steps of constructing the signature format of GM0031 include: S1. Based on the PDF signature object and the signature preprocessor, establish a signature attribute dictionary and reserve storage space for the GM0031 signature format; S2. Based on the attribute dictionary and storage space, GM0031 data encoding is used to obtain the signature format of GM0031; The GM0031 data encoding includes: Based on the attribute dictionary and storage space, the hash algorithm calculator and the signature process calculator are combined to obtain a GM0031 data structure generator; Based on the GM0031 data structure generator, the original data to be signed is hashed and a data code of the signature is generated to obtain a data code of the GM0031 structure.
2. A system for adapting national standard to PDF signature syntax, which is applied to the method for adapting national standard to PDF signature syntax described in claim 1, and is characterized in that, include: Signature preprocessing module, used to generate PDF signature objects and perform signature preprocessing; The signature format adaptation module is used to embed the pre-built GM0010 signature format and GM0031 signature format into the signature object based on the signature preprocessing, and obtain the results of GM0010 and GM0031 adaptation to PDF signature.
3. A device for adapting PDF signature syntax to national standards, characterized in that, include: processor and memory; a memory having an executable program stored therein; A processor, configured to execute the executable program in the memory to implement the steps of the method according to claim 1.
Citation Information
Patent Citations
Batch PDF file digital signature method and system
CN109672536A
Method for rapidly improving OFD signature, signature and verification
CN111611440A