An electronic contract signing method, system, terminal device and readable storage medium

By using personal private keys to sign and record the information of stamped personnel in electronic contracts, the problem of difficult to trace the stamped personnel in the prior art is solved, and the transparency and security of the contract are improved.

CN115482131BActive Publication Date: 2025-06-24SHANDONG ZHIXIN CERTIFICATION SERVICE CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211041883.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-29
Publication Date
2025-06-24
Estimated Expiration
2042-08-29

AI Technical Summary

Technical Problem

The existing electronic contract technology is difficult to trace the person in retrospectively, making it difficult to determine liability when a dispute occurs.

Method used

By receiving the personal private key selected by the user, signing the original text of the contract, generating a digital signature, and recording the information of the stamped person in the electronic contract to ensure that the stamped person can be traced back during the contract circulation process.

Benefits of technology

It realizes the function of recording the information of stamped personnel in an electronic contract, which facilitates subsequent search and traceability, and improves the transparency and security of the contract.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115482131B_ABST
    Figure CN115482131B_ABST
Patent Text Reader

Abstract

The present application provides an electronic contract signing method, system, terminal device and readable storage medium. The method includes: receiving a first target personal private key selected by a first user, where the first user is a member of a first enterprise; signing the original contract according to the first target personal private key to obtain a first stamped contract, where the first stamped contract includes the original contract and the corresponding first digital signature; encrypting the first stamped contract according to a second contract key of a second enterprise to obtain a first encrypted contract; and sending the first encrypted contract and the corresponding first enterprise certificate to the second enterprise system. The present application can enter the information of the person stamping the contract in the contract, providing a basis for subsequent search for the information of the person stamping the contract; it can also achieve that while the enterprise is displayed externally, the counterparty of the contract can also verify the digital signature, enabling the counterparty of the contract to verify the digital signature through the first certificate without being able to obtain the information of the person stamping the contract, improving information confidentiality.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the technical field of electronic contracts, and particularly relates to a method, system, terminal device and readable storage medium for signing electronic contracts. Background Art

[0002] Currently, the flow of electronic contracts is that after the contract initiator drafts and approves the contract, the enterprise electronic seal is used to complete the sealing, and the electronic contract is sent to the counterparty of the contract; the counterparty of the contract receives the electronic contract for approval, uses the enterprise electronic seal to complete the sealing after approval, and then transfers it to the contract initiator to complete the signing of the contract.

[0003] Since the sealers use the enterprise electronic seal and confidentiality requirements are involved, the personal information of the sealers will not be involved in the electronic contract. It is difficult to trace the sealers in case of disputes. Summary of the Invention

[0004] The embodiments of this application provide a method, system, terminal device and readable storage medium for signing electronic contracts, which can solve the problem of difficult tracing of the sealers.

[0005] In a first aspect, the embodiments of this application provide a method for signing an electronic contract, which is applied to a first enterprise system and includes:

[0006] Receiving a first target personal private key selected by a first user, where the first user is a member of a first enterprise;

[0007] Signing the original contract according to the first target personal private key to obtain a first sealed contract, where the first sealed contract includes the original contract and the corresponding first digital signature;

[0008] Encrypting the first sealed contract according to a second contract key of a second enterprise to obtain a first encrypted contract;

[0009] Sending the first encrypted contract and the corresponding first enterprise certificate to the second enterprise system;

[0010] Wherein, the first enterprise system is the system used by the first enterprise to sign electronic contracts, the first target personal private key is generated according to the first enterprise key of the first enterprise, the first enterprise certificate is generated according to the first enterprise key and the information of the first enterprise, and the second enterprise system is the system used by the second enterprise to sign electronic contracts.

[0011] Optionally, after signing the original contract according to the first target personal key to obtain a first sealed contract, it further includes:

[0012] Receive a query instruction input by a second user, and in response to the query instruction, obtain the first digital signature, where the second user is a member of the first enterprise;

[0013] Trace the first digital signature according to the first personal public key in each first personal certificate, and search for a first target personal certificate in the first personal certificate set. The first target personal public key and the first target personal private key in the first target personal certificate are a pair of key pairs;

[0014] Display the first target user information in the first target personal certificate;

[0015] Wherein, the first personal certificate is generated according to the first personal public key and the first user information, the first personal public key is generated according to the first enterprise key, and belongs to a pair of key pairs with the first personal private key.

[0016] Optionally, the second contract key is the identification information of the second enterprise.

[0017] Optionally, after sending the first encrypted contract and the corresponding first enterprise certificate to the second enterprise system, it further includes:

[0018] Receive a second encrypted contract and the corresponding second enterprise certificate from the second enterprise system;

[0019] Decrypt the second encrypted contract according to the first contract key to obtain a second stamped contract. The second stamped contract includes the contract original text and the corresponding first digital signature and second digital signature. The second digital signature is obtained by the second enterprise signing the contract original text;

[0020] Verify the second digital signature according to the second enterprise key in the second enterprise certificate and the contract original text;

[0021] If the verification of the second digital signature passes, save the second stamped contract;

[0022] Wherein, the first contract key is the identification information of the first enterprise.

[0023] Optionally, after receiving the second encrypted contract and the corresponding second enterprise certificate from the second enterprise, it further includes:

[0024] Verify the identity of the second enterprise according to the information of the second enterprise in the second enterprise certificate;

[0025] If the identity verification passes, enter the step: decrypt the second encrypted contract according to the first contract key to obtain a second stamped contract.

[0026] Optionally, before receiving the first target personal private key selected by the first user, it further includes:

[0027] Receiving and storing a first enterprise certificate generated by an authentication center, at least one first personal private key, and corresponding first personal certificates;

[0028] Wherein, the first personal private key is generated according to the first enterprise key, and each of the first personal private keys is different from each other, and each of the first personal certificates is different from each other.

[0029] In a second aspect, an embodiment of the present application provides an electronic contract signing method, which is applied to a second enterprise system and includes:

[0030] Receiving a first encrypted contract and a corresponding first enterprise certificate from a first enterprise system;

[0031] Decrypting the first encrypted contract with a second contract key to obtain a first stamped contract, where the first stamped contract includes the contract original text and a corresponding first digital signature;

[0032] Verifying the first digital signature according to the first enterprise key in the first enterprise certificate and the contract original text;

[0033] If the verification of the first digital signature passes, then receive a second target personal private key selected by a third user, where the third user is a member of the second enterprise;

[0034] Signing the contract original text with the second target personal private key to obtain a second stamped contract, where the second stamped contract includes the contract original text and corresponding first digital signature and second digital signature;

[0035] Encrypting the second stamped contract with the first contract key of the first enterprise to obtain a second encrypted contract;

[0036] Sending the second encrypted contract and a corresponding second enterprise certificate to the first enterprise system;

[0037] Wherein, the second enterprise system is a system used by the second enterprise to sign an electronic contract, the second target personal private key is generated according to the second enterprise key of the second enterprise, the second enterprise certificate is generated according to the second enterprise key and information of the second enterprise, and the first enterprise system is a system used by the first enterprise to sign an electronic contract.

[0038] In a third aspect, an embodiment of the present application provides an electronic contract signing system, including a first enterprise system and a second enterprise system;

[0039] The first enterprise system is used to receive the first target personal private key selected by the first user, where the first user is a member of the first enterprise;

[0040] Sign the original contract according to the first target personal private key to obtain the first sealed contract, where the first sealed contract includes the original contract and the corresponding first digital signature;

[0041] Encrypt the first sealed contract according to the second contract key of the second enterprise to obtain the first encrypted contract;

[0042] Send the first encrypted contract and the corresponding first enterprise certificate to the second enterprise system;

[0043] The second enterprise system is used to receive the first encrypted contract and the corresponding first enterprise certificate from the first enterprise system;

[0044] Decrypt the first encrypted contract through the second contract key to obtain the first sealed contract, where the first sealed contract includes the original contract and the corresponding first digital signature;

[0045] Verify the first digital signature according to the first enterprise key in the first enterprise certificate and the original contract;

[0046] If the verification of the first digital signature passes, receive the second target personal private key selected by the third user, where the third user is a member of the second enterprise;

[0047] Sign the original contract according to the second target personal private key to obtain the second sealed contract, where the second sealed contract includes the original contract and the corresponding first digital signature and second digital signature;

[0048] Encrypt the second sealed contract according to the first contract key of the first enterprise to obtain the second encrypted contract;

[0049] Send the second encrypted contract and the corresponding second enterprise certificate to the first enterprise system;

[0050] Wherein, the first enterprise system is the system used by the first enterprise to sign electronic contracts, the first target personal private key is generated according to the first enterprise key of the first enterprise, the first enterprise certificate is generated according to the first enterprise key and the information of the first enterprise, the second enterprise system is the system used by the second enterprise to sign electronic contracts, the second target personal private key is generated according to the second enterprise key of the second enterprise, and the second enterprise certificate is generated according to the second enterprise key and the information of the second enterprise.

[0051] Fourthly, an embodiment of the present application provides a terminal device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the method described in any one of the first aspect or the second aspect above is implemented.

[0052] Fifthly, an embodiment of the present application provides a computer-readable storage medium storing a computer program, and when the computer program is executed by a processor, the method described in any one of the first aspect or the second aspect above is implemented.

[0053] Sixthly, an embodiment of the present application provides a computer program product. When the computer program product runs on a terminal device, the terminal device is enabled to execute the method described in any one of the first aspect or the second aspect above.

[0054] It can be understood that the beneficial effects of the second aspect to the sixth aspect above can refer to the relevant descriptions in the first aspect, and will not be elaborated here.

[0055] The beneficial effects of the embodiment of the present application compared with the prior art are as follows:

[0056] In this embodiment, by receiving the first target personal private key selected by the first user and signing the original contract text according to the first target personal private key, a first stamped contract is obtained. The first stamped contract includes the original contract text and the corresponding first digital signature, which can record the information of the person stamping the contract and provide a basis for subsequent searching for the information of the person stamping the contract.

[0057] At the same time, based on the fact that the first target personal private key is generated according to the first enterprise key, and the first enterprise certificate is generated according to the first enterprise key and the information of the first enterprise, it is realized that while the enterprise is displayed externally, the counterparty of the contract can also verify the digital signature, so that the counterparty of the contract can verify the digital signature through the first enterprise certificate without being able to obtain the information of the person stamping the contract, improving information confidentiality. Description of the Drawings

[0058] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for use in the embodiments or the description of the prior art. Obviously, the following drawings are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0059] Figure 1 is a schematic diagram of a system provided by an embodiment of the present application;

[0060] Figure 2 is the first flow diagram of the electronic contract signing method provided by an embodiment of the present application;

[0061] Figure 3 It is the second process schematic diagram of the electronic contract signing method provided by an embodiment of the present application;

[0062] Figure 4 It is the structural schematic diagram of the terminal device provided by an embodiment of the present application. Detailed implementation manners

[0063] In the following description, specific details such as specific system architectures and technologies are presented for the purpose of illustration rather than limitation, so as to thoroughly understand the embodiments of the present application. However, those skilled in the art should clearly understand that the present application can also be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to avoid unnecessary details from interfering with the description of the present application.

[0064] It should be understood that when used in the specification of the present application and the appended claims, the term "comprising" indicates the presence of the described features, wholes, steps, operations, elements, and / or components, but does not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components, and / or their combinations.

[0065] It should also be understood that the term "and / or" used in the specification of the present application and the appended claims refers to any combination and all possible combinations of one or more of the related listed items, and includes these combinations.

[0066] As used in the specification of the present application and the appended claims, the term "if" can be interpreted as "when", "once", "in response to determining", or "in response to detecting" according to the context. Similarly, the phrase "if determined" or "if [the described condition or event] is detected" can be interpreted as meaning "once determined", "in response to determining", "once [the described condition or event] is detected", or "in response to detecting [the described condition or event]" according to the context.

[0067] In addition, in the description of the specification of the present application and the appended claims, the terms "first", "second", "third", etc. are only used for distinguishing descriptions and cannot be understood as indicating or implying relative importance.

[0068] References to "one embodiment" or "some embodiments" etc. described in the specification of this application mean that a particular feature, structure, or characteristic described in connection with that embodiment is included in one or more embodiments of this application. Thus, statements such as "in one embodiment", "in some embodiments", "in other some embodiments", "in still other embodiments", etc. that appear in different places in this specification do not necessarily all refer to the same embodiment, but rather mean "one or more but not all embodiments", unless otherwise specifically emphasized. The terms "comprising", "including", "having" and their variants all mean "including but not limited to", unless otherwise specifically emphasized.

[0069] Nowadays, electronic contracts have been widely applied in various fields of social and economic activities. Generally, digital certificates and digital signatures are required to sign an electronic contract. Therefore, an enterprise needs to submit materials to a certification authority to apply for an enterprise key and a contract key. The certification authority generates and stores the enterprise key and the contract key, and then generates at least one personal key pair based on the enterprise key, including a personal private key and a personal public key; then generates an enterprise certificate based on the enterprise key and the information of the enterprise, generates a personal certificate based on the personal public key and the specified user information, and synchronously issues the enterprise certificate, at least one personal private key, and the corresponding personal certificate to the enterprise.

[0070] The first enterprise receives and stores the first enterprise certificate generated by the certification authority, at least one first personal private key, and the corresponding first personal certificate.

[0071] Among them, the first enterprise key and the first contract key are generated by the certification authority according to the information of the first enterprise, the first personal public key and the first personal private key are generated by the certification authority according to the first enterprise key. The first personal certificate is generated by the certification authority according to the first personal public key and the first user information. Each of the first personal key pairs is different from each other, and each of the first personal certificates is different from each other. The first enterprise certificate is generated according to the first enterprise key and the information of the first enterprise.

[0072] The second enterprise receives and stores the second enterprise certificate generated by the certification authority, at least one second personal private key, and the corresponding second personal certificate.

[0073] Among them, the second enterprise key and the second contract key are generated by the certification authority according to the information of the second enterprise, the second personal public key and the second personal private key are generated by the certification authority according to the second enterprise key. The second personal certificate is generated by the certification authority according to the second personal public key and the second user information. Each of the second personal key pairs is different from each other, and each of the second personal certificates is different from each other. The second enterprise certificate is generated by the certification authority according to the second enterprise key and the information of the second enterprise.

[0074] The personal private key can only be used by designated and authorized enterprise members, who use the dedicated personal private key to sign the electronic contract.

[0075] Figure 1 It is a schematic diagram of the system provided by an embodiment of the present application. As Figure 1 shown, the system includes a first enterprise system and a second enterprise system. Among them, the first enterprise system 1 is a system used by the first enterprise to sign electronic contracts, including at least one first terminal. By way of example, it includes the first terminal 10, the first terminal 11, the first terminal 12, and the first terminal 13. The personal key dedicated to the terminal user and the first enterprise certificate are stored in the first terminal.

[0076] The second enterprise system 2 is a system used by the second enterprise to sign electronic contracts, including at least one second terminal. By way of example, it includes the second terminal 20, the second terminal 21, the second terminal 22, and the second terminal 23. The personal key dedicated to the terminal user and the second enterprise certificate are stored in the second terminal.

[0077] When the first enterprise and the second enterprise sign an electronic contract, the first enterprise is the contract initiator and the second enterprise is the counterparty of the contract.

[0078] Figure 2 It is the first process schematic diagram of the electronic contract signing method provided by an embodiment of the present application. As Figure 2 shown, it includes:

[0079] S11: The first enterprise system receives the first target personal private key selected by the first user.

[0080] Among them, the first user is a member of the first enterprise, and the first target personal private key is generated by the certification authority according to the first enterprise key of the first enterprise.

[0081] In application, when the electronic contract process is initiated within the enterprise, after the contract original text passes internal approval, the last approver, the first user, clicks on the dedicated personal private key on the first terminal in use. The first terminal receives the first target personal private key selected by the first user.

[0082] S12: Sign the contract original text according to the first target personal private key to obtain the first stamped contract.

[0083] Among them, the first stamped contract includes the contract original text and the corresponding first digital signature.

[0084] In application, the first terminal uses the first target personal private key to sign the contract original text to affix the digital signature of the first user on the contract original text. Since the first personal private key is generated by the certification authority according to the first enterprise key, this first digital signature is also equivalent to the digital signature of the first enterprise.

[0085] S13: Encrypt the first sealed contract using the second contract key of the second enterprise to obtain the first encrypted contract.

[0086] In an application, the first terminal uses the pre-stored second contract key of the second enterprise to encrypt the first sealed contract so that the first sealed contract can be encrypted for transmission and prevent others from stealing information even if it is stolen.

[0087] S14: Send the first encrypted contract and the corresponding first enterprise certificate to the second enterprise system.

[0088] In an application, after generating the first encrypted contract, the first terminal sends the first encrypted contract and the corresponding first enterprise certificate to the second enterprise system of the second enterprise.

[0089] Among them, it is displayed as an enterprise through the first enterprise certificate. At the same time, since the first personal private key used by the first user is generated based on the first enterprise key, the first enterprise key in the first enterprise certificate can verify the first digital signature.

[0090] It can be understood that by receiving the first target personal private key selected by the first user and signing the original contract according to the first target personal private key, the first sealed contract is obtained. The first sealed contract includes the original contract and the corresponding first digital signature, which can record the information of the person who stamped the contract and provide a basis for subsequent searching for the information of the person who stamped the contract.

[0091] At the same time, based on the fact that the first target personal private key is generated according to the first enterprise key and the first enterprise certificate is generated according to the first enterprise key and the information of the first enterprise, it is realized that while it is displayed as an enterprise externally, the counterparty of the contract can also verify the digital signature, enabling the counterparty of the contract to verify the digital signature through the first enterprise certificate without being able to obtain the information of the person who stamped the contract, improving information confidentiality and reflecting anonymity.

[0092] S21: The second enterprise system receives the first encrypted contract and the corresponding first enterprise certificate from the first enterprise system.

[0093] In an application, a certain second terminal in the second enterprise system receives the first encrypted contract and the corresponding first enterprise certificate.

[0094] S22: Decrypt the first encrypted contract using the second contract key to obtain the first sealed contract.

[0095] Among them, the first sealed contract includes the original contract and the corresponding first digital signature.

[0096] In an application, since the first enterprise uses the second contract key, correspondingly, the second terminal that receives the contract decrypts the first encrypted contract using the second contract key.

[0097] S23: Verify the first digital signature according to the first enterprise key in the first enterprise certificate and the original contract text.

[0098] In the application, the second terminal receiving the contract obtains the first enterprise key from the first enterprise certificate, decrypts the first digital signature, and obtains the contract digest from the first digital signature. Then, perform a hash calculation on the original contract text to obtain the original text digest, and compare the contract digest in the first digital signature with the original text digest obtained by the hash calculation. If they are the same, it indicates that the electronic contract has not been tampered with during the transfer process, and the verification passes. If they are different, it indicates that the electronic contract has been tampered with during the transfer process, and the verification fails.

[0099] By verifying the signature, it can be known whether the original contract text has been tampered with, ensuring the security of the transaction.

[0100] S24: If the verification of the first digital signature passes, then receive the second target personal private key selected by the third user.

[0101] In the application, if the verification passes, then conduct an internal review. Finally, the third user, the approver, clicks on their dedicated personal private key on the second terminal in use. The second terminal receives the second target personal private key selected by the third user.

[0102] Among them, the second target personal private key is generated according to the second enterprise key of the second enterprise.

[0103] S25: Sign the original contract text with the second target personal private key to obtain the second stamped contract.

[0104] Among them, the second stamped contract includes the original contract text and the corresponding first digital signature and second digital signature. The third user is a member of the second enterprise.

[0105] In the application, the signing second terminal uses the first target personal private key to sign the original contract text to stamp the digital signature of the third user on the original contract text. Since the second personal private key is generated by the certification authority according to the second enterprise key, this second digital signature is also equivalent to the digital signature of the second enterprise.

[0106] S26: Encrypt the second stamped contract with the first contract key of the first enterprise to obtain the second encrypted contract.

[0107] In the application, the signing second terminal uses the pre-stored first contract key of the first enterprise to encrypt the second stamped contract so that the second stamped contract can be encrypted for transmission and prevent others from stealing information even if it is stolen.

[0108] S27: Send the second encrypted contract and the corresponding second enterprise certificate to the first enterprise system.

[0109] In an application, after the second terminal with a signature generates a second encrypted contract, it sends the second encrypted contract and the corresponding second enterprise certificate to the first enterprise system of the first enterprise.

[0110] In this embodiment, the second terminal that receives the contract is the same terminal as the second terminal with a signature. In other embodiments, they can be different terminals.

[0111] It can be understood that by receiving the second target personal private key selected by the third user and signing the original contract according to the second target personal private key, a second sealed contract is obtained. The second sealed contract includes the original contract and the corresponding second digital signature, which can record the information of the person who seals the contract and provide a basis for subsequent searching for the information of the person who seals the contract.

[0112] At the same time, based on the fact that the second target personal private key is generated according to the second enterprise key, and the second enterprise certificate is generated according to the second enterprise key and the second enterprise information, it is realized that while the enterprise is externally displayed, the contract initiator can also verify the digital signature, so that the contract initiator can verify the digital signature through the second enterprise certificate without being able to obtain the information of the person who seals the contract, improving information confidentiality.

[0113] S15: The first enterprise system receives the second encrypted contract and the corresponding second enterprise certificate from the second enterprise system.

[0114] In an application, a certain first terminal in the first enterprise system receives the second encrypted contract and the corresponding second enterprise certificate.

[0115] S16: Decrypt the second encrypted contract according to the first contract key to obtain the second sealed contract.

[0116] Among them, the second sealed contract includes the original contract and the corresponding first digital signature and second digital signature, and the second digital signature is obtained by the second enterprise signing the original contract.

[0117] In an application, since the second enterprise uses the first contract key, correspondingly, the first terminal that receives the contract decrypts the second encrypted contract with the first contract key.

[0118] S17: Verify the second digital signature according to the second enterprise key in the second enterprise certificate and the original contract.

[0119] In the application, the first terminal that receives the contract obtains the second enterprise key from the second enterprise certificate, decrypts the second digital signature, and obtains the contract summary from the second digital signature. Then, it calculates the hash of the original contract text to obtain the original text summary, and compares the contract summary in the second digital signature with the original text summary obtained by the hash calculation. If they are the same, it indicates that the electronic contract has not been tampered with during the transfer process, and the verification passes. If they are different, it indicates that the electronic contract has been tampered with during the transfer process, and the verification fails.

[0120] S18: If the verification of the second digital signature passes, save the second stamped contract.

[0121] In the application, if the verification passes, save the second stamped contract for filing. By verifying the signature, it can be known whether the original contract text has been tampered with, ensuring the security of the transaction.

[0122] Figure 3 It is the second process schematic diagram of the electronic contract signing method provided by an embodiment of the present application. As Figure 3 shown, after step S12, it further includes:

[0123] S121: Receive a query instruction input by the second user. In response to the query instruction, obtain the first digital signature. The second user is a member of the first enterprise.

[0124] In the application, after generating the first stamped contract, when the second user in the first enterprise needs to query the information of the person who stamped the first stamped contract, input a query instruction on the first terminal used. The first terminal receives the query instruction. In response to the query instruction, obtain the first digital signature from the first stamped contract according to the query instruction.

[0125] Or, when the second user in the first enterprise needs to query the information of the person who stamped a certain second stamped contract, input a query instruction on the first terminal used. The first terminal receives the query instruction. In response to the query instruction, obtain the first digital signature from the second stamped contract according to the query instruction.

[0126] S122: Trace the first digital signature according to the first person public key in each first person certificate, and find the first target person certificate in the first person certificate set.

[0127] Among them, the first target person public key and the first target person private key in the first target person certificate are a pair of key pairs.

[0128] In the application, after obtaining the first digital signature, in the first person certificate set, decrypt the first digital signature one by one using the first person public key in the first person certificate. If the decryption is successful, obtain the first target person public key and at the same time obtain the first target person certificate. Obtain the information of the user from the first target person certificate, that is, the information of the first user.

[0129] Among them, the first terminal of the second user pre-stores a first set of personal certificates.

[0130] S123: Display the first target user information in the first target personal certificate.

[0131] In the application, the first target user information is displayed on the first terminal used by the second user.

[0132] In this embodiment, by tracking the first digital signature according to the first personal public key in each first personal certificate, searching for the first target personal certificate in the first set of personal certificates, and displaying the first target user information in the first target personal certificate, the information query of the person who stamped the electronic contract is realized, without the need to query through other complicated processes or assist in querying through the business system.

[0133] In one embodiment, the first contract key is the identification information of the first enterprise, and the second contract key is the identification information of the second enterprise. In this case, the two parties to the contract do not need to receive additional digital certificates for decrypting the contract, reducing the difficulty of digital certificate management. At the same time, there is no need to verify these digital certificates, reducing the cumbersome verification process.

[0134] Exemplarily, the identification information is personal identity information or enterprise identity information.

[0135] In one embodiment, after S15, it further includes:

[0136] Verify the identity of the second enterprise according to the information of the second enterprise in the second enterprise certificate.

[0137] In the application, according to the information of the second enterprise, determine whether the second encrypted contract comes from the second enterprise and whether it comes from the counterparty of the contract.

[0138] If the identity verification is passed, enter the step: decrypt the second encrypted contract according to the first contract key to obtain the second stamped contract.

[0139] In the application, if it is determined that it comes from the second enterprise, the verification is passed, and the second encrypted contract is decrypted.

[0140] In this embodiment, by verifying the identity of the second enterprise according to the information of the second enterprise in the second enterprise certificate, to verify whether the electronic contract comes from the counterparty of the contract, timely intercept maliciously forged electronic contracts, and ensure the security of the transaction.

[0141] In one embodiment, before saving the second stamped contract, it further includes:

[0142] Verify the first digital signature according to the first enterprise key in the first enterprise certificate and the original contract text;

[0143] If the verification of the first digital signature passes, proceed to the step of saving the second stamped contract.

[0144] In this embodiment, the first digital signature is verified based on the first enterprise key in the first enterprise certificate and the original contract text, so as to re-verify the first digital signature, promptly detect maliciously forged electronic contracts, and ensure the security of transactions.

[0145] It should be understood that the magnitudes of the sequence numbers of the steps in the above embodiments do not imply the order of execution. The order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application.

[0146] Figure 4 This is a schematic structural diagram of a terminal device provided by an embodiment of the present application. As Figure 4 shown, the terminal device 3 of this embodiment includes: at least one processor 30 ( Figure 4 only one is shown in the figure), a memory 31, and a computer program 32 stored in the memory 31 and executable on the at least one processor 30. When the processor 30 executes the computer program 32, the steps in any of the above method embodiments are implemented.

[0147] The terminal device 3 may be a computing device such as a desktop computer, a notebook, a palm computer, and a cloud server. The terminal device 3 may include, but is not limited to, a processor 30 and a memory 31. Those skilled in the art can understand that Figure 4 this is only an example of the terminal device 3, and does not constitute a limitation to the terminal device 3. It may include more or fewer components than shown in the figure, or combine some components, or different components. For example, it may also include input / output devices, network access devices, etc.

[0148] The so-called processor 30 may be a central processing unit (CPU). The processor 30 may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor, or the processor may also be any conventional processor, etc.

[0149] The memory 31 may be an internal storage unit of the terminal device 3 in some embodiments, such as the hard disk or memory of the terminal device 3. The memory 31 may also be an external storage device of the terminal device 3 in some other embodiments, such as a plug-in hard disk, a Smart Media Card (SMC), a Secure Digital (SD) card, a Flash Card, etc. equipped on the terminal device 3. Further, the memory 31 may also include both the internal storage unit and the external storage device of the terminal device 3. The memory 31 is used to store an operating system, application programs, a BootLoader, data, and other programs, such as the program code of the computer program, etc. The memory 31 may also be used to temporarily store the data that has been output or will be output.

[0150] It should be noted that for the content such as information interaction and execution process between the above-mentioned device / units, since it is based on the same concept as the method embodiment of the present application, for its specific functions and the technical effects brought, reference can be specifically made to the method embodiment part, and details will not be repeated here.

[0151] Those skilled in the art can clearly understand that for the convenience and brevity of description, only the above division of each functional unit and module is used as an example for illustration. In practical applications, the above functions can be allocated to different functional units and modules according to needs, that is, the internal structure of the device is divided into different functional units or modules to complete all or part of the functions described above. Each functional unit and module in the embodiment can be integrated into a processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above integrated unit can be implemented in the form of hardware or in the form of a software functional unit. In addition, the specific names of each functional unit and module are only for the convenience of mutual distinction and do not limit the protection scope of the present application. The specific working process of the units and modules in the above system can refer to the corresponding process in the foregoing method embodiment, and details will not be repeated here.

[0152] The embodiment of the present application also provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the steps in the above-mentioned method embodiments can be implemented.

[0153] The embodiment of the present application provides a computer program product. When the computer program product runs on a terminal device, the terminal device can be made to execute the steps in the above-mentioned method embodiments.

[0154] When the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, to implement all or part of the processes in the above-described embodiment methods of the present application, a computer program can be used to instruct relevant hardware to complete. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, the steps of the above-described various method embodiments can be implemented. Among them, the computer program includes computer program code, and the computer program code can be in the form of source code, object code, executable file, or some intermediate form, etc. The computer-readable medium can at least include: any entity or device that can carry the computer program code to the photographing device / terminal device, recording medium, computer memory, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), electrical carrier signal, telecommunication signal, and software distribution medium. For example, a USB flash drive, a mobile hard disk, a magnetic disk, or an optical disc, etc. In some jurisdictions, according to legislation and patent practice, the computer-readable medium cannot be an electrical carrier signal and a telecommunication signal.

[0155] In the above embodiments, the descriptions of the various embodiments have their own emphases. For the parts not detailed or recorded in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0156] Those of ordinary skill in the art can realize that the units and algorithm steps of the examples described in conjunction with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods for each specific application to implement the described functions, but such implementation should not be considered to exceed the scope of the present application.

[0157] In the embodiments provided in the present application, it should be understood that the disclosed device / network device and method can be implemented in other ways. For example, the device / network device embodiments described above are merely illustrative. For example, the division of the modules or units is only a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of the devices or units can be in electrical, mechanical, or other forms.

[0158] The unit described as a separating component may or may not be physically separated. The component shown as a unit may or may not be a physical unit, that is, it may be located in one place or may be distributed over multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0159] The above-described embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present application, and should all be included in the protection scope of the present application.

Claims

1. An electronic contract signing method, characterized in that, Including: The first enterprise system receives the first target personal private key selected by the first user, where the first user is a member of the first enterprise; Sign the original contract according to the first target personal private key to obtain a first sealed contract, where the first sealed contract includes the original contract and the corresponding first digital signature; Encrypt the first sealed contract according to the second contract key of the second enterprise to obtain a first encrypted contract; Send the first encrypted contract and the corresponding first enterprise certificate to the second enterprise system; Wherein, the first enterprise system is the system used by the first enterprise to sign an electronic contract, the first target personal private key is generated according to the first enterprise key of the first enterprise, the first enterprise certificate is generated according to the first enterprise key and the information of the first enterprise, and the second enterprise system is the system used by the second enterprise to sign an electronic contract; The second enterprise system decrypts the first encrypted contract through the second contract key to obtain a first sealed contract; Verify the first digital signature according to the first enterprise key in the first enterprise certificate and the original contract; After signing the original contract according to the first target personal private key to obtain a first sealed contract, it further includes: after obtaining the first digital signature, in the first personal certificate set, use the first personal public key in the first personal certificate to decrypt the first digital signature one by one. If the decryption is successful, the first target personal public key is obtained, and at the same time, the first target personal certificate is obtained. The information of the user is obtained from the first target personal certificate, which is the information of the first user; the first personal certificate is generated according to the first personal public key and the first user information, the first personal public key is generated according to the first enterprise key, and belongs to a key pair with the first personal private key; the first personal private key is generated according to the first enterprise key, and the first personal private keys are all different from each other.

2. The method according to claim 1, characterized in that: The second contract key is the identification information of the second enterprise.

3. The method according to any one of claims 1-2, characterized in that, After sending the first encrypted contract and the corresponding first enterprise certificate to the second enterprise system, it further includes: Receive a second encrypted contract and the corresponding second enterprise certificate from the second enterprise system; Decrypt the second encrypted contract according to the first contract key to obtain a second sealed contract, where the second sealed contract includes the original contract and the corresponding first digital signature and second digital signature, and the second digital signature is obtained by the second enterprise signing the original contract; Verify the second digital signature according to the second enterprise key in the second enterprise certificate and the original contract; If the verification of the second digital signature passes, save the second sealed contract; Wherein, the first contract key is the identification information of the first enterprise.

4. The method according to claim 3, wherein After receiving the second encrypted contract and the corresponding second enterprise certificate from the second enterprise system, it further includes: Verify the identity of the second enterprise according to the information of the second enterprise in the second enterprise certificate; If the identity verification is passed, proceed to the step of decrypting the second encrypted contract with the first contract key to obtain the second stamped contract.

5. The method according to claim 4, characterized in that, Before receiving the first target personal private key selected by the first user, it further includes: Receiving and storing the first enterprise certificate generated by the certification center, at least one first personal private key, and the corresponding first personal certificate; Among them, each of the first personal certificates is different from each other.

6. An electronic contract signing system, characterized in that, It includes a first enterprise system and a second enterprise system; The first enterprise system is used to receive the first target personal private key selected by the first user, and the first user is a member of the first enterprise; Sign the original contract with the first target personal private key to obtain a first stamped contract, and the first stamped contract includes the original contract and the corresponding first digital signature; Encrypt the first stamped contract with the second contract key of the second enterprise to obtain a first encrypted contract; Send the first encrypted contract and the corresponding first enterprise certificate to the second enterprise system; Among them, the first enterprise system is the system used by the first enterprise to sign electronic contracts, the first target personal private key is generated according to the first enterprise key of the first enterprise, the first enterprise certificate is generated according to the first enterprise key and the information of the first enterprise, and the second enterprise system is the system used by the second enterprise to sign electronic contracts; The second enterprise system decrypts the first encrypted contract with the second contract key to obtain the first stamped contract; Verify the first digital signature according to the first enterprise key in the first enterprise certificate and the original contract; After signing the original contract with the first target personal private key to obtain the first stamped contract, it further includes: after obtaining the first digital signature, in the first personal certificate set, use the first personal public key in the first personal certificate to decrypt the first digital signature one by one. If the decryption is successful, obtain the first target personal public key, and at the same time obtain the first target personal certificate. Obtain the information of the user from the first target personal certificate, which is the information of the first user; The first personal certificate is generated according to the first personal public key and the first user information, the first personal public key is generated according to the first enterprise key, and belongs to a key pair with the first personal private key; the first personal private key is generated according to the first enterprise key, and each of the first personal private keys is different from each other.

7. A terminal device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the method according to any one of claims 1 to 5.

8. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, it implements the method according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • On-line contract signing system based on internet

    CN101419686A