An electronic contract signing method, device, equipment and storage medium
By obtaining user identity and environmental information to generate scenario certificates, and combining them with electronic signatures from banks and guarantee systems, the security risks in electronic contract signing are resolved, achieving higher security and effectiveness.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- AGRICULTURAL BANK OF CHINA
- Filing Date
- 2022-10-19
- Publication Date
- 2026-08-04
AI Technical Summary
Existing electronic contract signing methods have security risks, as facial information is easily stolen, leading to the risk of impersonation in signing contracts.
Obtain necessary user identity and environmental information, generate scenario certificates, combine electronic signatures from banking and guarantee systems, generate and verify electronic contracts, and ensure the security of signing.
By generating scenario certificates and multi-party signatures, the risk of facial information being stolen is avoided, thus improving the security and effectiveness of electronic contract signing.
Smart Images

Figure CN115438325B_ABST
Abstract
Description
Technical Field
[0001] This application belongs to the field of computer technology, and in particular relates to a method, apparatus, device and storage medium for signing electronic contracts. Background Technology
[0002] With the development of electronic technology, electronic contracts have emerged due to their convenient transmission and cost-effectiveness. The entire process of signing an electronic contract is conducted electronically and is easy to preserve, using methods such as email and EDI (Electronic Data Interchange). This contract method significantly reduces transaction costs and improves economic efficiency.
[0003] In banking systems, users often need to sign electronic contracts. Currently, electronic contract signing often involves collecting and archiving users' facial information as evidence, such as through facial recognition or facial video recording, to achieve a personal signature. However, this facial signature is vulnerable to theft and misuse, with the user impersonating another person to sign contracts multiple times. Existing electronic contract signing methods pose significant security risks. Summary of the Invention
[0004] In view of this, the purpose of this application is to provide a method, apparatus, device and storage medium for signing electronic contracts, so as to improve the security of electronic contract signing.
[0005] To achieve the above objectives, the embodiments of this application disclose the following technical solutions:
[0006] Firstly, this application provides a method for signing an electronic contract, including:
[0007] To obtain necessary user identity information and user environment information;
[0008] Based on the user's necessary identity information and the user's environment information, a scenario certificate is generated, which is used to represent the user's electronic signature.
[0009] The scenario certificate and the electronic signature of the banking system are loaded into the first electronic contract to obtain the second electronic contract;
[0010] The second electronic contract is sent to the guarantee system, so that the guarantee system adds its electronic signature to the second electronic contract, thereby generating the third electronic contract.
[0011] Obtain the third-party electronic contract sent by the guarantee system;
[0012] Verify the validity of the third electronic contract. If the verification is successful, confirm that the signing of the electronic contract has been completed.
[0013] Optionally, the user environment information includes one or more of the following: the user's facial video information, the user's device information, the user's geographical location information, and the user's IP address information.
[0014] Optionally, the method further includes uploading the third electronic contract to a storage server.
[0015] Optionally, before generating a scenario certificate based on the user's necessary identity information and the user's environment information, the method further includes:
[0016] Verify the accuracy of the user's necessary identity information. If the verification is successful, proceed to generate a scenario certificate based on the user's necessary identity information and the user's environment information.
[0017] Secondly, this application provides an electronic contract signing device, comprising:
[0018] The first acquisition unit is used to acquire necessary user identity information and user environment information;
[0019] The generation unit is used to generate a scenario certificate based on the user's necessary identity information and the user's environment information, wherein the scenario certificate is used to represent the user's electronic signature;
[0020] The loading unit is used to load the scenario certificate and the electronic signature of the banking system into the first electronic contract to obtain the second electronic contract.
[0021] The sending unit is used to send the second electronic contract to the guarantee system, so that the guarantee system adds the electronic signature of the guarantee system to the second electronic contract and generates a third electronic contract;
[0022] The second acquisition unit is used to acquire the third electronic contract sent by the guarantee system;
[0023] The first verification unit is used to verify the validity of the third electronic contract. If the verification is successful, the signing of the electronic contract is confirmed.
[0024] Optionally, the user environment information includes one or more of the following: the user's facial video information, the user's device information, the user's geographical location information, and the user's IP address information.
[0025] Optionally, the device further includes;
[0026] The uploading unit is used to upload the third electronic contract to the storage server.
[0027] Optionally, the device further includes:
[0028] The second verification unit is used to verify whether the user's necessary identity information is accurate. If the verification is successful, the step of generating a scenario certificate based on the user's necessary identity information and the user's environment information is executed.
[0029] Thirdly, this application provides an electronic contract signing device, comprising:
[0030] Memory, used to store computer programs;
[0031] A processor for executing a computer program stored in the memory to implement the steps of a method for signing an electronic contract as described in any of the first aspects.
[0032] Fourthly, this application provides a computer-readable storage medium storing a computer program that is executed by a processor to implement the steps of the electronic contract signing method as described in any of the first aspects.
[0033] As can be seen, the electronic contract signing method, apparatus, device, and storage medium disclosed in this application obtain necessary user identity information and user environment information; based on the necessary user identity information and user environment information, a scenario certificate is generated, which represents the user's electronic signature; the scenario certificate and the electronic signature of the banking system are loaded into a first electronic contract to obtain a second electronic contract; the second electronic contract is sent to a guarantee system, so that the guarantee system adds its electronic signature to the second electronic contract to generate a third electronic contract; the third electronic contract sent by the guarantee system is obtained; the validity of the third electronic contract is verified, and if the verification is successful, the signing of the electronic contract is confirmed to be complete. By generating a scenario certificate from user environment information, it is ensured that the scenario certificate can only be used for the current contract signing, avoiding the risk of user facial information theft and improving the security of electronic contract signing. Attached Figure Description
[0034] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0035] Figure 1 This is a flowchart illustrating an electronic contract signing method provided in an embodiment of this application;
[0036] Figure 2 This is a schematic diagram of the structure of an electronic contract signing device provided in an embodiment of this application. Detailed Implementation
[0037] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0038] To facilitate understanding of the technical solutions provided in this application, the background technology involved in this application will be explained below.
[0039] In banking systems, users often need to sign electronic contracts. Currently, electronic contract signing often involves collecting and archiving users' facial information as evidence, such as facial recognition or facial video recording, to achieve a personal signature. However, this facial signature is vulnerable to theft and misuse, allowing for repeated contract signings by impersonators. For example, AI face-swapping technology can preprocess user photos and then generate dynamic videos using "photo animation" software. These videos can then be used to impersonate users and sign contracts. Furthermore, due to this vulnerability, users can also deny the signing.
[0040] To address this, this application provides a method, apparatus, device, and storage medium for signing electronic contracts. The method involves: acquiring necessary user identity information and user environment information; generating a scenario certificate based on the necessary user identity information and user environment information, whereby the scenario certificate represents the user's electronic signature; loading the scenario certificate and the electronic signature from the banking system into a first electronic contract to obtain a second electronic contract; sending the second electronic contract to a guarantee system, whereby the guarantee system adds its electronic signature to the second electronic contract to generate a third electronic contract; obtaining the third electronic contract sent by the guarantee system; and verifying the validity of the third electronic contract. If the verification is successful, the signing of the electronic contract is considered complete. By generating a scenario certificate from user environment information, the method ensures that the scenario certificate can only be used for the current contract signing, avoiding the risk of user facial information theft and improving the security of electronic contract signing.
[0041] To facilitate understanding of the technical solution provided in this application, a method for signing an electronic contract will be described below with reference to the accompanying drawings. It should be noted that the electronic contract signing method, apparatus, device, and storage medium provided in this application can be used in the financial field or other fields. For example, it can be used in banking systems within the financial sector. Other fields refer to any field other than the financial sector, such as other fields where electronic contract signing exists. The above are merely examples and do not limit the application areas of the electronic contract signing method provided in this application.
[0042] SeeFigure 1 This figure is a flowchart illustrating an electronic contract signing method provided in an embodiment of this application. Figure 1 As shown, the method includes steps S101-S106. As one possible implementation, this method can be applied to a banking system.
[0043] S101: Obtain necessary user identity information and user environment information.
[0044] In this embodiment, it is necessary to first obtain the user's essential identity information and user environment information. As one possible implementation, the essential user identity information includes one or more of the following: the user's ID card number, the user's bank card number, and the user's mobile phone number. The user environment information includes one or more of the following: the user's facial video information, the user's device information, the user's geographical location information, and the user's IP address information.
[0045] This application does not limit the specific method or timing of obtaining the user's necessary identity information. As one possible implementation, the necessary identity information can be obtained when the user needs to sign an electronic contract or submit an application through a bank's business application. It is understood that the user's necessary identity information can be actively filled in by the user on the application, and after completion, it can be sent to the bank system, allowing the bank system to obtain the user's necessary identity information.
[0046] This application does not limit the specific method of obtaining user environmental information. As one possible implementation, user environmental information can be collected through a terminal device where the user logs into the bank's business application. This terminal device can be, for example, a smartphone, computer, personal digital assistant (PDA), tablet computer, etc.
[0047] S102: Based on the user's necessary identity information and the user's environment information, generate a scenario certificate, which is used to represent the user's electronic signature.
[0048] After obtaining the necessary user identity and environment information, a scenario certificate can be generated based on this information. This scenario certificate can be used to represent the user's electronic signature. It is understood that the scenario certificate generated using this method carries the user's environment information. Loading this environment information into the scenario certificate ensures that it contains the current user's environment information, making it usable only for the signing of this specific contract.
[0049] This application does not limit the specific method for generating a scenario certificate based on the user's necessary identity information and user environment information. As an example, a scenario certificate can be generated by calculating the hash value of the user's necessary identity information and user environment information using a hash algorithm.
[0050] As one possible implementation, before generating the scenario certificate based on the user's necessary identity information and the user's environment information, the method further includes: verifying whether the user's necessary identity information is accurate; if the verification is successful, then performing the step of generating the scenario certificate based on the user's necessary identity information and the user's environment information.
[0051] By verifying the accuracy of users' necessary identity information, the reliability of user information is ensured, thereby improving the security and effectiveness of electronic contract signing using this information.
[0052] S103: Load the scenario certificate and the electronic signature of the bank system into the first electronic contract to obtain the second electronic contract.
[0053] After obtaining the scenario certificate representing the user's electronic signature, the scenario certificate and the bank system's electronic signature can be loaded into the first electronic contract to obtain the second electronic contract. It can be understood that the first electronic contract is the initial contract before any signature is obtained, while the second electronic contract carries both the user's and the bank system's electronic signatures.
[0054] S104: Send the second electronic contract to the guarantee system so that the guarantee system adds its electronic signature to the second electronic contract and generates a third electronic contract.
[0055] In this embodiment, after obtaining the second electronic contract, it is also sent to the guarantee system. The guarantee system adds its electronic signature to the second electronic contract, generating a third electronic contract. It is understood that the third electronic contract will include the user's electronic signature, the bank's electronic signature, and the guarantee system's electronic signature.
[0056] As one possible implementation, the guarantee system will first verify the electronic signature of the second electronic contract user and the electronic signature of the bank system. If the verification is successful, the electronic signature of the guarantee system will be added to the second electronic contract to generate the third electronic contract.
[0057] S105: Obtain the third electronic contract sent by the guarantee system.
[0058] In this embodiment of the application, after the guarantee system generates a third electronic contract, the third electronic contract sent by the guarantee system can be retrieved.
[0059] S106: Verify the validity of the third electronic contract. If the verification is successful, confirm that the signing of the electronic contract has been completed.
[0060] In this embodiment of the application, after obtaining the third electronic contract, it is also necessary to verify the validity of the third electronic contract. Once the verification is successful, the signing of the electronic contract can be confirmed as complete.
[0061] It is understandable that it is necessary to verify the validity of the scenario certificate, the electronic signature of the banking system, and the electronic signature of the guarantee system in the third-party electronic contract. The methods for verifying electronic signatures are well known to those skilled in the art, and this application does not limit the specific methods for verifying the validity of electronic signatures.
[0062] The system obtains necessary user identity and environment information; based on this information, it generates a scenario certificate representing the user's electronic signature; it loads the scenario certificate and the bank system's electronic signature into a first electronic contract, resulting in a second electronic contract; it sends the second electronic contract to the guarantee system, enabling the guarantee system to add its electronic signature to the second electronic contract, generating a third electronic contract; it retrieves the third electronic contract sent by the guarantee system; and it verifies the validity of the third electronic contract. If verification is successful, the electronic contract signing is confirmed as complete. By generating a scenario certificate from user environment information, the system ensures that the scenario certificate can only be used for this specific contract signing, avoiding the risk of user facial information theft and improving the security of electronic contract signing.
[0063] Furthermore, the electronic contract is also signed through a third-party guarantee system, expanding from the traditional two-party electronic contract signing and authentication between the user and the bank system to a three-party online electronic contract signing, further ensuring the security and validity of the electronic contract.
[0064] As one possible implementation, this application provides a method for signing an electronic contract that also includes uploading a third-party electronic contract to a storage server. By uploading the third-party electronic contract to the storage server, the electronic contract can be retrieved as evidence at any time, reducing the possibility of contract disputes.
[0065] The following describes an electronic contract signing device provided in an embodiment of this application. The device described below can be referred to in correspondence with the electronic contract signing method described above.
[0066] This application also provides a schematic diagram of an electronic contract signing device, such as... Figure 2 As shown, the device includes a first acquisition unit 201, a generation unit 202, a loading unit 203, a sending unit 204, a second acquisition unit 205, and a first verification unit 206.
[0067] The first acquisition unit 201 is used to acquire necessary user identity information and user environment information.
[0068] The generation unit 202 is used to generate a scenario certificate based on the user's necessary identity information and the user's environment information, wherein the scenario certificate is used to represent the user's electronic signature.
[0069] The loading unit 203 is used to load the scenario certificate and the electronic signature of the bank system into the first electronic contract to obtain the second electronic contract.
[0070] Sending unit 204 is used to send the second electronic contract to the guarantee system, so that the guarantee system adds the electronic signature of the guarantee system to the second electronic contract and generates a third electronic contract.
[0071] The second acquisition unit 205 is used to acquire the third electronic contract sent by the guarantee system.
[0072] The first verification unit 206 is used to verify the validity of the third electronic contract. If the verification is successful, the signing of the electronic contract is confirmed.
[0073] The system acquires necessary user identity and environment information; based on this information, it generates a scenario certificate representing the user's electronic signature; it loads the scenario certificate and the bank system's electronic signature into a first electronic contract, resulting in a second electronic contract; it sends the second electronic contract to a guarantee system, enabling the guarantee system to add its electronic signature to the second electronic contract, generating a third electronic contract; it retrieves the third electronic contract sent by the guarantee system; and it verifies the validity of the third electronic contract. If verification is successful, the electronic contract signing is confirmed as complete. This device generates a scenario certificate from the user's environment information, ensuring that the scenario certificate can only be used for this specific contract signing, thus avoiding the risk of user facial information theft and improving the security of electronic contract signing.
[0074] As one possible implementation, user environment information includes one or more of the following: user's facial video information, user's device information, user's geographical location information, and user's IP address information.
[0075] As one possible implementation, the device also includes:
[0076] The uploading unit is used to upload the third electronic contract to the storage server.
[0077] As one possible implementation, the device also includes:
[0078] The second verification unit is used to verify whether the user's necessary identity information is accurate. If the verification is successful, the step of generating a scenario certificate based on the user's necessary identity information and the user's environment information is executed.
[0079] This application also provides a device that may include a memory and a processor. The memory stores a computer program, and when the processor calls the computer program in the memory, it can implement the steps provided in the above embodiments. Of course, the device may also include various network interfaces, power supplies, and other components.
[0080] It should be noted that the device provided in this application has the technical effects of any of the above embodiments, and the embodiments of this application will not be described in detail here.
[0081] This application also provides a computer-readable storage medium having a computer program stored thereon, which, when executed, can perform the steps provided in the above embodiments. The storage medium may include various media capable of storing program code, such as a USB flash drive, a portable hard drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.
[0082] It should be noted that the computer-readable storage medium provided in this application has the technical effects of any of the above embodiments, and the embodiments of this application will not be described in detail here.
[0083] It should be understood that in this application, "at least one (item)" means one or more, and "more than" means two or more. "And / or" is used to describe the relationship between related objects, indicating that three relationships can exist. For example, "A and / or B" can represent three cases: only A exists, only B exists, and both A and B exist simultaneously, where A and B can be singular or plural. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. "At least one (item) of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one (item) of a, b, or c can represent: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c can be single or multiple.
[0084] It should also be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0085] This document uses specific examples to illustrate the principles and implementation methods of this application. The descriptions of the embodiments above are only for the purpose of helping to understand the method and core ideas of this application. It should be noted that those skilled in the art can make several improvements and modifications to this application without departing from the principles of this application, and these improvements and modifications also fall within the protection scope of the claims of this application.
Claims
1. A method for signing an electronic contract, characterized in that, include: To obtain necessary user identity information and user environment information; Verify whether the user's necessary identity information is accurate; If the verification is successful, a scenario certificate is generated based on the user's necessary identity information and the user's environment information. The scenario certificate is used to represent the user's electronic signature, and the scenario certificate includes data generated based on the user's environment information to limit the electronic signature to be used only for this signing scenario. The scenario certificate and the electronic signature of the banking system are loaded into the first electronic contract to obtain the second electronic contract; The second electronic contract is sent to the guarantee system, so that after the guarantee system verifies the validity of the user's electronic signature and the bank's electronic signature in the second electronic contract, it adds the guarantee system's electronic signature to the second electronic contract and generates the third electronic contract. Obtain the third electronic contract sent by the guarantee system; Verify the validity of the scenario certificate, the electronic signature of the bank system, and the electronic signature of the guarantee system in the third electronic contract. If all verifications are successful, the signing of the electronic contract is confirmed to be complete.
2. The method according to claim 1, characterized in that, The user environment information includes one or more of the following: the user's facial video information, the user's device information, the user's geographical location information, and the user's IP address information.
3. The method according to claim 1, characterized in that, The method further includes uploading the third electronic contract to a storage server.
4. An electronic contract signing device, characterized in that, The device includes: The first acquisition unit is used to acquire necessary user identity information and user environment information; The second verification unit is used to verify whether the user's necessary identity information is accurate. The generation unit is configured to generate a scenario certificate based on the necessary user identity information and the user environment information if the second verification unit verifies successfully. The scenario certificate is used to represent the user's electronic signature, wherein the scenario certificate includes data generated based on the user environment information to limit the electronic signature to be used only for this signing scenario. The loading unit is used to load the scenario certificate and the electronic signature of the banking system into the first electronic contract to obtain the second electronic contract. The sending unit is used to send the second electronic contract to the guarantee system, so that after the guarantee system verifies the validity of the user's electronic signature and the bank system's electronic signature in the second electronic contract, it adds the guarantee system's electronic signature to the second electronic contract and generates a third electronic contract. The second acquisition unit is used to acquire the third electronic contract sent by the guarantee system; The first verification unit is used to verify the validity of the scenario certificate, the electronic signature of the bank system, and the electronic signature of the guarantee system in the third electronic contract. If all verifications are successful, the signing of the electronic contract is confirmed to be completed.
5. The apparatus according to claim 4, characterized in that, The user environment information includes one or more of the following: the user's facial video information, the user's device information, the user's geographical location information, and the user's IP address information.
6. The apparatus according to claim 4, characterized in that, The device also includes; The uploading unit is used to upload the third electronic contract to the storage server.
7. An electronic contract signing device, characterized in that, include: Memory, used to store computer programs; A processor for executing a computer program stored in the memory to implement the steps of the electronic contract signing method as described in any one of claims 1 to 3.
8. A computer-readable storage medium storing a computer program thereon, characterized in that, The computer program is executed by a processor to implement the steps of the electronic contract signing method as described in any one of claims 1 to 3.