A method, system and electronic device for authorized signature
By managing hosted signature keys and certificates on the business server, the problem of limited computing performance of mobile devices is solved, efficient execution of batch electronic signatures is achieved, and user experience is improved.
Patent Information
- Application Number
- CN202111110122.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-09-23
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2041-09-23
AI Technical Summary
In the process of batch execution of signatures, due to the limited computing performance of mobile devices, the signature process takes a long time and affects the user experience.
By implementing the management and use of managed signature keys and certificates on the business server, the mobile terminal only needs to provide challenge value signatures, while the business server is responsible for executing electronic signatures one by one and sending the results back to the mobile terminal.
It effectively solves the problem of limited computing performance of mobile devices, realizes efficient execution of batch electronic signatures, shortens the time of the signature process, and improves user experience.
Smart Images

Figure CN115866596B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of cryptography, and in particular to a method, system and electronic device for authorized signature. Background Art
[0002] With the rise of the Internet, more and more applications are migrating to mobile devices. The USBKey storage key, execution signature and other cryptographic functions in information security applications are gradually being replaced by new security methods because of their poor convenience, such as white-box symmetric encryption algorithms and collaborative signature technology.
[0003] Collaborative signature is to generate and save the signature private key shards on the mobile terminal and the server respectively. When signing, each party uses its own key shard to participate in the calculation, and finally generates the signature result on the mobile terminal. The complete private key information will not appear in the calculation process of any party, thereby ensuring the security of key shards and cryptographic operations.
[0004] However, the final result of each signature is generated on the mobile terminal. Due to the limited computing performance of the mobile terminal device, the cryptographic operation cannot be performed for a long time. However, in practical applications, batch signatures are often required. In this application scenario, there is a problem of limited computing performance of mobile terminal devices.
[0005] For example, when hospital doctors need to use their mobile phones to sign electronic prescription documents, in order not to affect their work, they generally need to sign dozens or even hundreds of prescriptions accumulated in a day at one time. Signing multiple documents at one time may take dozens of minutes, and no one has the patience to wait for the phone to complete this task without turning off the screen. Summary of the invention
[0006] The present application provides a method, device and electronic device for authorizing signatures, for executing batch electronic signatures.
[0007] In a first aspect, the present application provides a method for authorizing a signature, the method comprising:
[0008] When receiving a batch electronic signature application from a mobile terminal, the business service terminal sends a challenge value to the mobile terminal, wherein the application includes the number of files requested for signature;
[0009] The business service end receives the challenge value signature of the mobile end, and after the challenge value signature is verified, extracts the saved associated escrow signature key identifier and escrow signature certificate;
[0010] The business service end electronically signs the documents one by one according to the escrow signature key identifier and the escrow signature certificate;
[0011] The business service end executes the electronic signature on the document requested for signature in the application, and sends the execution result of the application to the mobile end.
[0012] Through the above method, batch electronic signature execution is realized, solving the problem of limited computing performance of mobile devices in the batch signature execution process in the existing technology application.
[0013] In a possible design, when the business service end receives the batch electronic signature application sent by the mobile end, before sending the challenge value to the mobile end, it also includes:
[0014] The business service end receives the collaborative signature certificate application request sent by the mobile end;
[0015] After receiving the collaborative signature certificate application sent by the mobile terminal, the business service terminal applies for a collaborative signature certificate for the mobile terminal;
[0016] The business service end saves the collaborative signature certificate and sends the collaborative signature certificate to the mobile end, so that the mobile end completes the batch electronic signature application authorization based on the collaborative signature key and the collaborative signature certificate.
[0017] In a possible design, the business service end receives the challenge value signature of the mobile end, and after the challenge value signature is verified, creates a managed signature key identifier and applies for a managed signature certificate, including:
[0018] The business service end receives the challenge value signature of the mobile end, and verifies the challenge value signature using the collaborative signature certificate;
[0019] After the challenge value signature is verified, the business service end creates a managed signature key and saves the managed key identifier, wherein the managed signature key identifier is used to represent the index of the managed signature key;
[0020] After saving the escrow signature key identifier, the business service end applies to create an escrow signature certificate and saves the escrow signature certificate.
[0021] In a possible design, after the business service end executes the electronic signature on the document requested for signature in the application and sends the execution result of the application to the mobile terminal, it also includes:
[0022] The business service end confirms that the authorization record of the application is saved on the evidence service end, wherein the authorization record includes one or more of the event name of the application, the number of files requested for signature, the escrow signature key identifier, the escrow signature public key, the challenge value, the collaborative signature public key, and the collaborative signature value.
[0023] Through the above method, private data intercommunication is achieved under the premise of ensuring privacy security, and the information barriers of multi-party transactions are broken. The blockchain is used to effectively improve the security of data during transmission.
[0024] In a second aspect, the present application provides a method for authorizing a signature, the method comprising:
[0025] The mobile terminal sends the batch electronic signature application to the business service terminal to trigger the business service terminal to generate a challenge value;
[0026] The mobile terminal receives the challenge value, signs the challenge value using the collaborative signature key to obtain a challenge value signature, and sends the challenge value signature to the business service terminal;
[0027] After the challenge value signature is verified by the business service end, the mobile end receives the execution result of the application sent by the business service end.
[0028] In a possible design, the mobile terminal sends a batch electronic signature application to a business service terminal to trigger the business service terminal to generate a challenge value, further comprising:
[0029] After jointly creating a collaborative signature key with the collaborative signature server, the mobile terminal sends a collaborative signature certificate application to the business server, so that the business server applies to create a collaborative signature certificate;
[0030] The mobile terminal receives the collaborative signature certificate sent by the business service terminal.
[0031] In a third aspect, the present application provides a system for authorizing signatures, the system comprising:
[0032] The business service module sends a challenge value to the mobile terminal when receiving a batch electronic signature application sent by the mobile terminal, wherein the application includes the number of files requested for signature;
[0033] The escrow signature module, the business service end receives the challenge value signature of the mobile end, and after the challenge value signature is verified, extracts the saved associated escrow signature key identifier and escrow signature certificate;
[0034] The authorized signature module, the business service end performs electronic signature on each file according to the escrow signature key identifier and the escrow signature certificate;
[0035] The authorization notification module, the business service end executes the electronic signature on the file requested for signature in the application, and sends the execution result of the application to the mobile terminal.
[0036] In a possible design, before the business service module, a business service end is also used to receive a request for a collaborative signature certificate sent by the mobile terminal; after receiving the collaborative signature certificate application sent by the mobile terminal, the business service end applies for a collaborative signature certificate for the mobile terminal; the business service end saves the collaborative signature certificate, and sends the collaborative signature certificate to the mobile terminal, so that the mobile terminal completes the batch electronic signature application authorization based on the collaborative signature key and the collaborative signature certificate.
[0037] In a possible design, the escrow signature module is specifically used for the business server to receive the challenge value signature of the mobile terminal, and use the collaborative signature certificate to verify the challenge value signature; after the challenge value signature is verified, the business server creates a escrow signature key and saves the escrow key identifier, wherein the escrow signature key identifier is used to represent the index of the escrow signature key; after saving the escrow signature key identifier, the business server applies to create a escrow signature certificate and saves the escrow signature certificate.
[0038] In one possible design, after the authorization notification module, it is also used for the business server to confirm that the authorization record of the application is saved on the evidence server, wherein the authorization record includes one or more of the event name of the application, the number of files requested for signature, the managed signature key identifier, the managed signature public key, the challenge value, the collaborative signature public key, and the collaborative signature value.
[0039] In a fourth aspect, the present application provides a system for authorizing signatures, the system comprising:
[0040] Business service module, the mobile terminal sends the batch electronic signature application to the business service terminal to trigger the business service terminal to generate a challenge value;
[0041] The hosting signature module receives the challenge value on the mobile terminal, signs the challenge value using the collaborative signature key, obtains the challenge value signature, and sends the challenge value signature to the business service terminal;
[0042] The authorization notification module receives the execution result of the application sent by the business service end after the challenge value signature is verified by the business service end.
[0043] In one possible design, the business service module is specifically used to send a collaborative signature certificate application to the business service end after the mobile end jointly creates a collaborative signature key with the collaborative signature server, so that the business service end applies to create a collaborative signature certificate; the mobile end receives the collaborative signature certificate sent by the business service end.
[0044] In a fifth aspect, the present application provides an electronic device, the electronic device comprising:
[0045] Memory, used to store computer programs;
[0046] The processor is used to implement the above-mentioned method steps for detecting an object with abnormal motion state when executing the computer program stored in the memory.
[0047] In a sixth aspect, the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the above-mentioned method steps for detecting an object with an abnormal motion state are implemented.
[0048] For each of the above-mentioned aspects from the third to the sixth aspects and the technical effects that may be achieved by each of the aspects, please refer to the above-mentioned description of the technical effects that can be achieved by various possible schemes in the first aspect, the second aspect, or the first aspect and the second aspect, and no further details will be given here. BRIEF DESCRIPTION OF THE DRAWINGS
[0049] Figure 1 A schematic diagram of an application scenario of an authorization signature provided for this application;
[0050] Figure 2 A flowchart of a method for authorizing signature provided for this application;
[0051] Figure 3 A flowchart of a method for authorizing signature provided for this application;
[0052] Figure 4 A schematic diagram of a method for authorizing signature provided for this application;
[0053] Figure 5 A schematic diagram of a system for authorizing signatures provided for this application;
[0054] Figure 6 A schematic diagram of a system for authorizing signatures provided for this application;
[0055] Figure 7 A schematic diagram of the structure of an electronic device provided in this application. DETAILED DESCRIPTION
[0056] See also Figure 1 As shown, the embodiment of the present application provides a possible application scenario.
[0057] like Figure 1As shown, the above application scenario includes a mobile terminal 110 and a server 120. The mobile terminal 110 can be represented as a mobile service APP, and the server 120 can include a business server, etc. Of course, the mobile terminal 110 can be any other mobile device or software on a mobile device, and the server 120 can be any other server. Figure 1 This article takes one possible situation as an example and does not elaborate on other situations.
[0058] exist Figure 1 The mobile terminal 110 is a mobile service APP, which includes a certificate management module, a collaborative signature module, etc., and the mobile service APP can interact with the collaborative signature service module.
[0059] exist Figure 1 The server 120 in the figure is a business service module, which includes an authorization management module, an electronic signature module, a user management module, a certificate management module, etc., and the business service module can interact with the CA module (issuing certificate server), the escrow signature module, and the evidence storage module. It should be explained that the module, server, and server here are equivalent concepts.
[0060] For example, if the mobile terminal 110 is an electronic signature APP used by doctors, the electronic signature APP can provide doctors with functions such as account registration, real-name authentication, collection of handwritten signature images (i.e., electronic signature images), application for collaborative signature certificates, application for escrow signature certificates, and execution of electronic signatures for electronic documents such as electronic prescriptions. These functions need to be completed through the cooperation of the business server, collaborative signature server, CA module, key escrow server, and evidence storage server in the server 120.
[0061] Based on the above possible application scenarios, the embodiments of the present application provide a method, system and electronic device for authorized signature, which solve the problem of limited computing performance of mobile devices in the batch execution of signatures in the prior art applications.
[0062] The method provided in the embodiments of the present application is further described in detail below in conjunction with the accompanying drawings.
[0063] Embodiment 1:
[0064] See also Figure 2 As shown, the embodiment of the present application provides a method for authorizing signature, and the specific process is as follows:
[0065] Before step 201, the business service end first receives the collaborative signature certificate application request sent by the mobile end, and after receiving the collaborative signature certificate application sent by the mobile end, it will apply for a collaborative signature certificate for the mobile end and save the collaborative signature certificate. Then the collaborative signature certificate is sent to the mobile end. After receiving the collaborative signature certificate, the mobile end will complete the authorization of the batch electronic signature application based on the collaborative signature key and the collaborative signature certificate, and the mobile end will send the batch electronic signature application to the business service end.
[0066] Step 201: When receiving a batch electronic signature application sent by a mobile terminal, the business service terminal sends a challenge value to the mobile terminal;
[0067] When the business server receives the batch electronic signature application sent by the mobile terminal, it will generate a randomly generated challenge value and send the challenge value to the mobile terminal. After receiving the challenge value, the mobile terminal will sign the challenge value with the collaborative signature certificate and send the challenge value signature back to the business server.
[0068] Specifically, the above-mentioned batch electronic signature application means applying for one or more electronic signatures. The above-mentioned challenge value is a randomly generated value and has no actual meaning. The challenge value is sent back to the mobile terminal to verify the identity of the mobile terminal and protect information security.
[0069] In addition, the scenario where the mobile terminal applies for batch electronic signatures from the business server is a typical application. On the surface, the application is to apply to the business server to execute batch electronic signatures. In fact, each electronic signature must include an electronic signature, that is, the electronic signature is a visual extension application of the electronic signature.
[0070] Step 202: The business service end receives the challenge value signature of the mobile end, and after the challenge value signature is verified, extracts the saved associated escrow signature key identifier and escrow signature certificate;
[0071] After receiving the challenge value signature sent back by the mobile terminal, the business server will use the same co-signing certificate as the mobile terminal to verify the challenge value signature. If the challenge value signature is verified, a managed signature key will be created and the managed key identifier will be saved. Then, after the business server saves the managed signature key identifier, it will apply to create a managed signature certificate and save the created managed signature certificate.
[0072] Specifically, the above-mentioned process of creating a managed signature key can be implemented in a managed signature module. In the managed signature module, the managed signature module receives an application for creating a managed signature key issued by the business server, generates a managed signature key according to the application, and an index of each managed signature key as a managed signature key identifier, and sends the managed signature key and the managed signature key identifier to the business server.
[0073] The above process of creating a managed signature certificate can be implemented in the CA module. In the CA module, the CA module receives an application for creating a managed signature certificate issued by the business server, generates a managed signature certificate based on the application, and sends the managed signature certificate to the business server.
[0074] Step 203: The business server electronically signs each file according to the escrow signature key identifier and the escrow signature certificate;
[0075] The business server uses the managed signature key identifier and managed signature certificate to perform electronic signature on each document requested for signature.
[0076] Step 204: The business service end executes the electronic signature on the document requested for signature in the application, and sends the execution result of the application to the mobile terminal.
[0077] After the business service end completes the electronic signature on the documents requested for signature included in the batch electronic signature application, it notifies the mobile end that the authorization task has been completed.
[0078] In a possible design, after step 204, the authorization record of this batch electronic signature application can also be saved on the evidence storage server.
[0079] Specifically, the authorization record includes one or more of the event name of the above application, the number of files requested for signature, the escrow signature key identifier, the escrow signature public key, the challenge value, the collaborative signature public key, and the collaborative signature value.
[0080] Embodiment 2:
[0081] See also Figure 3 As shown, the embodiment of the present application provides a method for authorizing signature, and the specific process is as follows:
[0082] Before step 301, the mobile terminal first detects whether there is a valid collaborative signature certificate: if so, continue to step 301; if not, after the mobile terminal and the collaborative signature server jointly create a collaborative signature key, an application for creating a collaborative signature certificate is sent to the business server, and then the business server creates a collaborative signature certificate based on the application and sends the collaborative signature certificate to the mobile terminal. After receiving the collaborative signature certificate sent by the business terminal, the mobile terminal saves the collaborative signature certificate.
[0083] Step 301: The mobile terminal sends a batch electronic signature application to the business service terminal to trigger the business service terminal to generate a challenge value;
[0084] After the mobile terminal determines that it has applied for the collaborative signature certificate, it generates a batch electronic signature application and sends the batch electronic signature application to the business server. After the business server receives the application, it generates a random challenge value and sends the challenge value to the mobile terminal.
[0085] Specifically, the above-mentioned batch electronic signature application means applying for one or more electronic signatures. The above-mentioned challenge value is a randomly generated value and has no actual meaning. The challenge value is sent back to the mobile terminal to verify the identity of the mobile terminal and protect information security.
[0086] In addition, the scenario where the mobile terminal applies for batch electronic signatures from the business server is a typical application. On the surface, the application is to apply to the business server to execute batch electronic signatures. In fact, each electronic signature must include an electronic signature, that is, the electronic signature is a visual extension application of the electronic signature.
[0087] Step 302: The mobile terminal receives the challenge value, and signs the challenge value using the collaborative signature key to obtain a challenge value signature, and sends the challenge value signature to the business service terminal;
[0088] After receiving the challenge value sent by the business server, the mobile terminal will use the collaborative signature key to sign the challenge value, obtain the challenge value signature, and send the challenge value signature to the business server. Then, after receiving the challenge value signature sent back by the mobile terminal, the business server will use the same collaborative signature certificate as the mobile terminal to verify the challenge value signature.
[0089] Step 303: After the challenge value signature is verified by the business service end, the mobile end receives the execution result of the application sent by the business service end.
[0090] If the business server verifies the challenge value signature successfully, it will create a managed signature key and save the managed key identifier. Then, the business server will use the managed signature key identifier and managed signature certificate to perform electronic signatures on the files requested for signature one by one. After the business server completes the electronic signature of the files requested for signature included in the batch electronic signature application, it will notify the mobile terminal that the authorization task has been completed. This notification means that the mobile terminal will receive the execution result of the batch electronic signature application sent by the business server.
[0091] In a possible design, after step 304, the authorization record of this batch electronic signature application can also be saved on the evidence storage server.
[0092] Specifically, the authorization record includes one or more of the event name of the above application, the number of files requested for signature, the escrow signature key identifier, the escrow signature public key, the challenge value, the collaborative signature public key, and the collaborative signature value.
[0093] Embodiment 3:
[0094] See also Figure 4 As shown, this application provides a method for authorizing signature, the specific contents are as follows:
[0095] Embodiment 3 of the present application is a possible specific embodiment applied in the above-mentioned possible application scenario. In addition, the electronic signature APP in Embodiment 3 of the present application is a possible specific application of a mobile terminal.
[0096] Step 1: The electronic signature APP and the collaborative signature server jointly create a collaborative signature key;
[0097] Step 2: The electronic signature APP applies to the business server to create a collaborative signature certificate;
[0098] Step 3: The business server performs business logic processing;
[0099] Step 4: The business server forwards the request to create a co-signed certificate to the CA module;
[0100] Step 5: The CA module creates a co-signed certificate;
[0101] Step 6: The CA module sends the co-signed certificate to the business server;
[0102] Step 7: The business server saves the collaborative signature certificate;
[0103] Step 8: The business server sends the collaborative signature certificate to the electronic signature APP;
[0104] Step 9: The electronic signature APP saves the collaborative signature certificate;
[0105] Step 10: The electronic signature APP applies to the business server to create a managed signature key;
[0106] Step 11: The business server generates a challenge value and sends the challenge value to the electronic signature APP;
[0107] Step 12: The electronic signature APP accepts the challenge value and uses the collaborative signature key to complete the signature of the challenge value;
[0108] Step 13: The electronic signature APP sends the signature of the challenge value to the business server;
[0109] Step 14: The business server accepts the signature of the verification challenge value and verifies the signature of the challenge value using the co-signature certificate;
[0110] Step 15: The business server applies to the escrow signature module to create an escrow signature key;
[0111] Step 16: The managed signature module creates a managed signature key. The key here is a key pair, specifically including a public key and a private key. In addition, multiple managed signature keys may be generated here, and the managed signature key identifier is used as the index of the managed signature key.
[0112] Step 17: The escrow signature module sends the escrow signature key identifier and the escrow signature key identifier public key to the business server;
[0113] Step 18: After saving the escrow key identifier, the business server creates an escrow signature certificate application;
[0114] Step 19: The business server sends a request for creating a managed signature certificate to the CA module;
[0115] Step 20: After the CA module creates the escrow signature certificate, send the escrow signature certificate to the business server;
[0116] Step 21: After receiving the escrow signature certificate, the business server saves the escrow signature certificate;
[0117] Step 22: The business server sends a success notification to the electronic signature APP.
[0118] In a possible design, before step 22, the business server hosts the signature key identifier and the signature certificate, performs electronic signature on each file requested for signature, and after executing the electronic signature, sends the execution result to the electronic signature APP.
[0119] In one possible design, after step 23, the evidence server will save the authorization record of this batch electronic signature application. Specifically, the authorization record includes one or more of the event name of the above application, the number of files requested for signature, the managed signature key identifier, the managed signature public key, the challenge value, the collaborative signature public key, and the collaborative signature value.
[0120] Based on the same inventive concept, the present application also provides a system for authorizing signatures to implement batch electronic signature execution, solving the problem of limited computing performance of mobile devices in the batch signature execution process in the prior art application, see Figure 5 The system comprises:
[0121] Business service module 501, when receiving a batch electronic signature application sent by a mobile terminal, the business service terminal sends a challenge value to the mobile terminal, wherein the application includes the number of files requested for signature;
[0122] The escrow signature module 502, the business service end receives the challenge value signature of the mobile end, and after the challenge value signature is verified, extracts the saved associated escrow signature key identifier and escrow signature certificate;
[0123] Authorized signature module 503, the business server performs electronic signature on each file according to the escrow signature key identifier and the escrow signature certificate;
[0124] Authorization notification module 504, the business service end executes the electronic signature on the file requested for signature in the application, and sends the execution result of the application to the mobile terminal.
[0125] In a possible design, before the business service module 501, a business service end is also used to receive a request for a collaborative signature certificate sent by the mobile terminal; after receiving the collaborative signature certificate application sent by the mobile terminal, the business service end applies for a collaborative signature certificate for the mobile terminal; the business service end saves the collaborative signature certificate, and sends the collaborative signature certificate to the mobile terminal, so that the mobile terminal completes the batch electronic signature application authorization based on the collaborative signature key and the collaborative signature certificate.
[0126] In one possible design, the escrow signature module 502 is specifically used for the business server to receive the challenge value signature of the mobile terminal, and use the collaborative signature certificate to verify the challenge value signature; after the challenge value signature is verified, the business server creates a escrow signature key and saves the escrow key identifier, wherein the escrow signature key identifier is used to represent the index of the escrow signature key; after saving the escrow signature key identifier, the business server applies to create a escrow signature certificate and saves the escrow signature certificate.
[0127] In one possible design, after the authorization notification module 504, the business server is also used to confirm that the authorization record of the application is saved in the evidence storage server, wherein the authorization record includes one or more of the event name of the application, the number of files requested for signature, the managed signature key identifier, the managed signature public key, the challenge value, the collaborative signature public key, and the collaborative signature value.
[0128] Based on the above system, the execution of batch electronic signatures can be realized, solving the problem of limited computing performance of mobile devices in the batch execution signature process of existing technology applications.
[0129] Based on the same inventive concept, the present application also provides a system for authorizing signatures to implement batch electronic signature execution, solving the problem of limited computing performance of mobile devices in the batch signature execution process in the prior art application, see Figure 6 The system comprises:
[0130] Business service module 601, the mobile terminal sends the batch electronic signature application to the business service terminal to trigger the business service terminal to generate a challenge value;
[0131] The managed signature module 602 receives the challenge value on the mobile terminal, signs the challenge value using the collaborative signature key, obtains the challenge value signature, and sends the challenge value signature to the business service terminal;
[0132] Authorization notification module 603, after the challenge value signature is verified by the business service end, the mobile end receives the execution result of the application sent by the business service end.
[0133] In one possible design, the business service module 601 is specifically used for sending a collaborative signature certificate application to the business service end after the mobile end jointly creates a collaborative signature key with the collaborative signature server, so that the business service end applies to create a collaborative signature certificate; the mobile end receives the collaborative signature certificate sent by the business service end.
[0134] Based on the above system, the execution of batch electronic signatures can be realized, solving the problem of limited computing performance of mobile devices in the batch execution signature process of existing technology applications.
[0135] Based on the same inventive concept, an electronic device is also provided in the embodiment of the present application, and the electronic device can realize the functions of any of the aforementioned authorization signature systems, referring to Figure 7 , the electronic device comprises:
[0136] At least one processor 701, and a memory 702 connected to the at least one processor 701. The specific connection medium between the processor 701 and the memory 702 is not limited in the embodiment of the present application. Figure 7 In the example, the processor 701 and the memory 702 are connected via a bus 700. Figure 7 The connections between other components are shown in bold lines, and are not intended to be limiting. The bus 700 can be divided into an address bus, a data bus, a control bus, etc. For ease of illustration, Figure 7 Only one thick line is used in the figure, but it does not mean that there is only one bus or one type of bus. Alternatively, the processor 701 can also be called a controller, and there is no limitation on the name.
[0137] In the embodiment of the present application, the memory 702 stores instructions that can be executed by at least one processor 701. The at least one processor 701 can execute the authorization signature method discussed above by executing the instructions stored in the memory 702. The processor 701 can implement Figure 5 or Figure 6 The functions of each module in the system are shown.
[0138] Among them, processor 701 is the control center of the system, which can use various interfaces and lines to connect various parts of the entire control device, and monitor the system as a whole by running or executing instructions stored in memory 702 and calling data stored in memory 702, various functions of the system and processing data.
[0139] In one possible design, the processor 701 may include one or more processing units, and the processor 701 may integrate an application processor and a modem processor, wherein the application processor mainly processes an operating system, a user interface, and application programs, and the modem processor mainly processes wireless communications. It is understandable that the modem processor may not be integrated into the processor 701. In some embodiments, the processor 701 and the memory 702 may be implemented on the same chip, and in some embodiments, they may also be implemented separately on separate chips.
[0140] Processor 701 may be a general-purpose processor, such as a central processing unit (CPU), a digital signal processor, an application-specific integrated circuit, a field programmable gate array or other programmable logic device, a discrete gate or transistor logic device, or a discrete hardware component, and may implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of the present application. A general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the authorization signature method disclosed in the embodiments of the present application may be directly embodied as being executed by a hardware processor, or may be executed by a combination of hardware and software modules in the processor.
[0141] The memory 702 is a non-volatile computer-readable storage medium that can be used to store non-volatile software programs, non-volatile computer executable programs and modules. The memory 702 may include at least one type of storage medium, such as a flash memory, a hard disk, a multimedia card, a card-type memory, a random access memory (Random Access Memory, RAM), a static random access memory (Static Random Access Memory, SRAM), a programmable read-only memory (Programmable Read Only Memory, PROM), a read-only memory (Read Only Memory, ROM), an electrically erasable programmable read-only memory (Electrically Erasable Programmable Read-Only Memory, EEPROM), a magnetic memory, a disk, an optical disk, etc. The memory 702 is any other medium that can be used to carry or store a desired program code in the form of an instruction or data structure and can be accessed by a computer, but is not limited thereto. The memory 702 in the embodiment of the present application can also be a circuit or any other system that can realize a storage function, for storing program instructions and / or data.
[0142] By programming the processor 701, the code corresponding to the authorization signature method described in the above embodiment can be fixed into the chip, so that the chip can execute the authorization signature method when it is running. Figure 2 The steps of the authorization signature method of the embodiment shown are as follows: How to design and program the processor 701 is a technique known to those skilled in the art and will not be described in detail here.
[0143] Based on the same inventive concept, an embodiment of the present application further provides a storage medium, which stores computer instructions. When the computer instructions are executed on a computer, the computer executes the authorization signature method discussed above.
[0144] In some possible implementations, various aspects of the authorization signature method provided by the present application can also be implemented in the form of a program product, which includes program code. When the program product is run on an apparatus, the program code is used to enable the control device to execute the steps of the authorization signature method according to various exemplary embodiments of the present application described above in this specification.
[0145] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application may adopt the form of a computer program product implemented in one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that include computer-usable program code.
[0146] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0147] These computer program instructions may also be stored in a computer readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture including an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0148] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0149] Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalents, the present application is also intended to include these modifications and variations.
Claims
1. A method for authorizing a signature, characterized in that: The method comprises: The business server receives the collaborative signature certificate request sent by the mobile terminal; After receiving the collaborative signature certificate application sent by the mobile terminal, the business service terminal applies for a collaborative signature certificate for the mobile terminal; The business service end saves the collaborative signature certificate and sends the collaborative signature certificate to the mobile end, so that the mobile end completes the batch electronic signature application authorization based on the collaborative signature key and the collaborative signature certificate; When receiving a batch electronic signature application sent by a mobile terminal, the business service terminal sends a challenge value to the mobile terminal, wherein the batch electronic signature application includes the number of files requested for signature; The business service end receives the challenge value signature of the mobile end, and after the challenge value signature is verified, extracts the saved associated escrow signature key identifier and escrow signature certificate; The business service end electronically signs the documents one by one according to the escrow signature key identifier and the escrow signature certificate; The business service end executes the electronic signature on the document requested for signature in the application, and sends the execution result of the application to the mobile end.
2. The method according to claim 1, characterized in that The business service end receives the challenge value signature of the mobile end, and after the challenge value signature is verified, includes: The business service end receives the challenge value signature of the mobile end, and verifies the challenge value signature using the collaborative signature certificate; After the challenge value signature is verified, the business service end creates a managed signature key and saves the managed key identifier, wherein the managed signature key identifier is used to represent the index of the managed signature key; After saving the escrow signature key identifier, the business service end applies to create an escrow signature certificate and saves the escrow signature certificate.
3. The method according to any one of claims 1-2, characterized in that: After the business service end executes the electronic signature on the document requested for signature in the application and sends the execution result of the application to the mobile end, the process further includes: The business service end confirms that the authorization record of the batch electronic signature application is saved on the evidence storage service end, wherein the authorization record includes one or more of the event name of the application, the number of files requested for signature, the managed signature key identifier, the managed signature public key, the challenge value, the collaborative signature public key, and the collaborative signature value.
4. A method for authorizing a signature, characterized in that: The method comprises: After jointly creating a collaborative signature key with the collaborative signature server, the mobile terminal sends a collaborative signature certificate application to the business server, so that the business server applies to create a collaborative signature certificate; The mobile terminal receives the collaborative signature certificate sent by the business service terminal; The mobile terminal sends the batch electronic signature application to the business service terminal to trigger the business service terminal to generate a challenge value; The mobile terminal receives the challenge value, signs the challenge value using the collaborative signature key to obtain a challenge value signature, and sends the challenge value signature to the business service terminal; After the challenge value signature is verified by the business service end, the mobile end receives the execution result of the application sent by the business service end.
5. A system for authorizing signatures, characterized in that: The system comprises: Business service module, the business service end receives the collaborative signature certificate application request sent by the mobile end; after receiving the collaborative signature certificate application sent by the mobile end, the business service end applies for a collaborative signature certificate for the mobile end; the business service end saves the collaborative signature certificate and sends the collaborative signature certificate to the mobile end, so that the mobile end completes the batch electronic signature application authorization based on the collaborative signature key and the collaborative signature certificate; when receiving the batch electronic signature application sent by the mobile end, the business service end sends a challenge value to the mobile end, wherein the batch electronic signature application includes the number of files requested for signature; The escrow signature module, the business service end receives the challenge value signature of the mobile end, and after the challenge value signature is verified, extracts the saved associated escrow signature key identifier and escrow signature certificate; The authorized signature module, the business service end performs electronic signature on each file according to the escrow signature key identifier and the escrow signature certificate; The authorization notification module, the business service end executes the electronic signature on the file requested for signature in the application, and sends the execution result of the application to the mobile terminal.
6. A system for escrow signature, characterized in that: The system comprises: Business service module: after the mobile terminal jointly creates a collaborative signature key with the collaborative signature server, the mobile terminal sends the collaborative signature certificate application to the business service terminal, so that the business service terminal applies to create a collaborative signature certificate; the mobile terminal receives the collaborative signature certificate sent by the business service terminal; the mobile terminal sends the batch electronic signature application to the business service terminal to trigger the business service terminal to generate a challenge value; The hosting signature module receives the challenge value on the mobile terminal, signs the challenge value using the collaborative signature key, obtains the challenge value signature, and sends the challenge value signature to the business service terminal; The authorization notification module receives the execution result of the application sent by the business service end after the challenge value signature is verified by the business service end.
7. An electronic device, characterized in that: include: Memory, used to store computer programs; A processor, configured to implement the method steps of any one of claims 1 to 4 when executing the computer program stored in the memory.
8. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method steps described in any one of claims 1 to 4 are implemented.
Citation Information
Patent Citations
Method for implementation of electronic seal and server, client and readable storage medium
CN108206831A
Electronic signature, and signature verification system
JP2005260759A