Electronic File Secure Transmission Method, System and Medium Based on Electronic Signature
Through the combination of original handwriting electronic signature technology and the national secret algorithm, the authenticity and integrity problems in the transmission of electronic files are solved, and the secure transmission and authenticity guarantee of electronic files are achieved.
Patent Information
- Application Number
- CN202211735650.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-31
- Publication Date
- 2025-08-05
- Estimated Expiration
- 2042-12-31
AI Technical Summary
The prior art is difficult to effectively guarantee the authenticity and integrity of electronic files during transmission. Especially in paperless office environments, there are difficulties in authenticity detection and secure transmission of electronic files, and the existing electronic signature methods cannot effectively express the willingness of signatures.
The original handwriting electronic signature technology is used to encrypt the electronic file data packets, and digitally signed handwriting pictures are generated using the electronic signature handwriting features. Secure channel transmission is established through asymmetric encryption, and the national secret algorithms SM4, SM2, SM3 are encrypted and verified to generate trusted electronic files.
Ensure that electronic files are not tampered with during transmission, maintain authenticity and integrity, and realize the secure transmission and authenticity of electronic files.
Smart Images

Figure CN116015945B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the fields of computer technology and information security technology, and specifically to a method for securely transmitting electronic archive files based on original handwriting signatures. Background Art
[0002] Paperless office has been widely adopted in many fields, but the management and archiving of the various electronic documents and data generated by paperless office work has become a major challenge. To address the preservation of these electronic documents and data, the application of electronic archive systems has become increasingly widespread. To ensure the complete and effective archiving of electronic documents and data generated by business and office activities, such as those requiring preservation, into electronic archives, four key characteristics must be tested: authenticity, integrity, availability, and security. The authenticity of electronic archives not only reflects the true nature of business and office activities but is also a prerequisite for their value. During the collection, transmission, and storage of electronic archives, their authenticity is often compromised by external factors and network environments. The massive amount of data generated by the network environment complicates archive management. Misleading information collection and organization, or the deliberate collection and upload of false information, can make it difficult to ensure the authenticity of electronic archives.
[0003] Authenticity testing for electronic archives includes: testing whether the metadata of archived electronic files complies with the requirements of DA / T85-2019 and GB / T 33480-2016; testing whether the fixed information in archived electronic files effectively confirms the authenticity of the electronic file's source; and testing whether the electronic attribute information contained in the electronic file's content data is consistent with the information recorded in the electronic file's metadata. To determine the specific content of the "four attributes" test, it is necessary to analyze the three stages of electronic file archiving, electronic archive transfer and acceptance, and long-term preservation of electronic archives, formulate specific authenticity testing indicators, and implement authenticity testing for electronic archives. Authenticity testing includes testing whether the archived information package is consistent with the information package sent by the business department.
[0004] Electronic archives involve many aspects, and the authenticity of electronic archive files must be guaranteed throughout their creation process. They must remain tamper-free throughout their entire lifecycle, from creation to archiving, maintaining their original state. Electronic archives go through multiple stages from creation to archiving, making the secure transmission of electronic archive files crucial. Ensuring the secure transmission of electronic archive files from one stage to the next in the archiving process effectively safeguards the authenticity of electronic archives. Whether electronic archive files can maintain their authenticity during migration and transfer during archiving and transfer remains a pressing issue.
[0005] Only signatures that meet the requirements of the Electronic Signature Law are valid; otherwise, they are considered legally ineffective. Third-party certified electronic signatures, such as CAs, issue certificates based on third-party identification. However, there is insufficient oversight of their use, leading to involuntary electronic contract signing and a high rate of subsequent disputes. Biometric recognition, such as facial recognition, is a static recognition technology that can represent "check-in" but not "confirmation." This fails to effectively convey the intention that the signature is solely controlled by the individual. Summary of the Invention
[0006] In light of this, this application combines the authenticity verification of transferred electronic archive documents with the original handwritten electronic signature, ensuring the authenticity of each step in the electronic archive archiving, transfer, receipt, and long-term preservation of electronic archives. Through the original handwritten electronic signature, the signing behavior at each stage of electronic archive archiving can be restored, ensuring the secure transmission of electronic archive documents and generating and preserving complete evidence of the archiving of electronic archive business data during the archive transfer process. This ensures the secure transmission and authenticity of electronic archive documents.
[0007] According to one aspect of the present application, a method for secure transmission of electronic archive files based on original handwriting signatures is proposed, which encrypts the metadata, files and original handwriting signature data packets in the electronic archive data packet, associates the electronic archive data packet, metadata, electronic signature with the archiving business, generates file summary information, and encrypts the electronic archive data packet to obtain an encrypted electronic archive compressed data packet; reviews the signature records according to the initiation and reception order of the electronic archive transfer business, and uses asymmetric encryption to encrypt the file summary information to generate a trusted electronic file; uses the electronic signature handwriting features and the archived electronic file to generate a digital signature handwriting image, which is synthesized into the electronic archive data packet, establishes a secure channel to transmit the electronic archive data packet and its trusted electronic file, and transfers the electronic archive compressed data packet, metadata, and digital signature handwriting image to the next link, which restores the digital signature handwriting image on the file in the received electronic archive compressed data packet to signature handwriting feature data. If it is the same as the signature handwriting feature in the evidence storage module, the secure transmission of the electronic archive file is completed.
[0008] Further preferably, during the transfer of electronic files, the receiving end reviews and signs the received archive data package file and transfer list, and verifies the identity information of the reviewer. After the verification is passed, the reviewer reviews the electronic file and signs online to confirm the receipt. The electronic signature handwriting feature information, signing time, file hash value, and archiving time are obtained to generate digital summary information, and a timestamp digital signature is formed by encrypting the digital summary information. The digital signature time information is recorded through a trusted timestamp, and the archive data package file received with the summary information as a timestamp signature is recalculated to generate a new digital summary information. The generated digital summary information, timestamp digital signature, and new digital summary information are bound to the archive data package to generate a trusted electronic file.
[0009] Further optimization is to use the national secret algorithm SM4 to encrypt the electronic archive data packet, and use the key exchange algorithm of the national secret algorithm SM2 to calculate the security channel password; use the signature algorithm of the national secret algorithm SM2 to verify the signature of the transmitted electronic archive data packet; use the encryption algorithm SM3 to calculate the HASH value of the encrypted electronic archive compressed data packet, store the encrypted electronic archive compressed data packet in the distributed file storage system, and annotate each file in the data packet in the distributed file storage system with a file tag ID and return it to the business system; associate the file tag ID with the file HASH value and store it in the business system database to complete the association between the business and the data packet.
[0010] Further preferably, the generating of the digital signature handwriting image includes: using the coordinate position and the starting and lifting states of the electronic signature sequence data in the electronic archive data package file to perform binary image echo, segmenting the electronic signature sequence into single words to produce a single word sequence library, searching for single word sequences with consistent content from the single word sequence library according to the echoed electronic signature image, performing signature splicing to obtain a new electronic signature sequence, disturbing the strokes according to the corresponding electronic signature orthographic sequence to generate a new electronic signature sequence, generating electronic signature imitation image data through binary echo of the generated electronic signature sequence, aligning the echoed signature image and the signature imitation image, and splicing them in the channel dimension to construct an electronic signature image pair.
[0011] Further preferably, the generation of the digital signature handwriting image includes: extracting the standardized signature original handwriting data features, calling the national secret algorithm to encrypt and process the unified feature vector to generate the public and private keys of the personal identification password, encrypting the public and private keys to form a vector key, using the vector key to encrypt the electronic signature data to form an encrypted digital signature and generate ciphertext, using the handwritten electronic signature feature vector to generate a private key, using the private key to call the national secret algorithm to decrypt the ciphertext generated by the encrypted digital signature to generate plaintext, calling the national secret algorithm to calculate the plaintext hash based on the plaintext, calling the private key to encrypt the plaintext hash, and generating a digital signature; decrypting and reconstructing based on the user name and its original signature handwriting features, the signature mapper obtains the weight bias, verifies the collected electronic signature data to extract the signature features, sets the key library weight bias, and the signature mapper reconstructs the style features based on the weight bias and the extracted features to obtain the electronic signature image pair.
[0012] Further optimization is to obtain an electronic archive data package, decompress the electronic files and archive transfer list in the data package, extract the original handwriting electronic signature handwriting feature information in the file; obtain the public key used for national secret algorithm SM2 encryption from the encryption server through an encrypted channel; generate a signature handwriting image based on the electronic signature handwriting feature information, and synthesize the signature handwriting image onto the business flow document certificate; add the electronic signature handwriting feature information, the original electronic files in the electronic archive data package, and the business flow document certificate with the synthesized signature handwriting image to a temporary electronic archive compressed data package; use the public key to encrypt the temporary electronic archive compressed data package to obtain an encrypted electronic archive compressed data package; decrypt the encrypted electronic archive compressed data package, query the file ID and HASH value in the encrypted electronic archive compressed data package corresponding to each business in the circulation link through the business server, and obtain the corresponding encrypted electronic archive compressed data package in the distributed file storage system according to the file ID; and verify the correctness of each file in the compressed package through the file HASH value.
[0013] Further preferably, the sending server generates a 128-bit hash value from the electronic archive data package using a digest algorithm, encrypts the hash value using the RSA algorithm and the sender's private key, and generates a digest ciphertext as the sender's digital signature; the digital signature is sent to the receiving server together with the electronic archive compressed data package; the receiving end uses the same digest algorithm as the sending end to calculate and generate a 128-bit hash value for the received file, decrypts the attached digital signature using the RSA algorithm and the sender's public key, and confirms whether the electronic file in the received electronic archive compressed data package is the original archive file confirmed by the sender's signature based on the hash value and the decryption result; the digest algorithm uses the MD5 algorithm, and uses a one-way hash function to transform a byte string of any length in the electronic file in the electronic archive compressed data package into a 128-bit hash value; the receiving end uses the same digest algorithm to calculate a message digest for the received file; if the message digests are the same, the file in the received electronic archive data package has not been tampered with; if the message digests are different, the file in the received electronic archive data package has been tampered with.
[0014] According to another aspect of the present invention, a secure transmission system for electronic archive files based on original handwriting signatures is proposed, comprising: an encryption module encrypting metadata, files and original handwriting signature data packets in electronic archive data packets, associating electronic archive data packets, metadata, electronic signatures with archiving services, generating file summary information, and encrypting electronic archive data packets to obtain encrypted electronic archive compressed data packets; reviewing signature records according to the initiation and reception sequence of electronic archive transfer services, and adopting asymmetric encryption to encrypt file summary information to generate trusted electronic files; a signature verification module using electronic signature handwriting features and archived electronic files to generate digital signature handwriting images, and synthesizing the digital signature handwriting images into electronic archive data packets; a transmission module establishing a secure channel to transmit electronic archive data packets and trusted electronic files, and transferring electronic archive compressed data packets, metadata, and digital signature handwriting images to the receiving end of the next link; the receiving end restores the digital signature handwriting images on the files in the received electronic archive compressed data packets to signature handwriting feature data; if they are the same as the signature handwriting feature data in the evidence storage module, the secure transmission of electronic archive files is completed.
[0015] Further preferably, the receiving end reviews and signs the received archive data package file and transfer list, and verifies the identity information of the reviewer. After the verification is passed, the reviewer reviews the electronic file and signs online to confirm the receipt is completed; obtains the electronic signature handwriting feature information, signing time, file hash value, and archiving time to generate digital summary information, encrypts the digital summary information to form a timestamp digital signature, records the digital signature time information through a trusted timestamp, and recalculates the new digital summary information for the archive data package file received with the summary information as the timestamp signature; binds the generated digital summary information, the timestamp digital signature, and the new digital summary information to the archive data package to generate a trusted electronic file.
[0016] Further optimization is to use the national secret algorithm SM4 to encrypt the electronic archive data packet, and use the key exchange algorithm of the national secret algorithm SM2 to calculate the security channel password; use the signature algorithm of the national secret algorithm SM2 to verify the signature of the transmitted electronic archive data packet; use the encryption algorithm SM3 to calculate the HASH value of the encrypted electronic archive compressed data packet, store the encrypted electronic archive compressed data packet in the distributed file storage system, and annotate each file in the data packet in the distributed file storage system with a file tag ID and return it to the business system; associate the file tag ID with the file HASH value and store it in the business system database to complete the association between the business and the data packet.
[0017] Further preferably, the signature verification module generates a digital signature handwriting image including: using the coordinate position and pen start and pen lift status in the electronic signature sequence data in the electronic archive data package file to perform binary image echo, performing single-word segmentation on the electronic signature sequence to produce a single-word sequence library, searching for single-word sequences with consistent content from the single-word sequence library according to the echoed electronic signature image, performing signature splicing to obtain a new electronic signature sequence, perturbing the strokes in the corresponding electronic signature orthographic sequence to generate a new electronic signature sequence, generating electronic signature imitation image data through binary echo of the generated electronic signature sequence, aligning the echoed signature image and the signature imitation image, and splicing them in the channel dimension to construct an electronic signature image pair.
[0018] Further preferably, the signature verification module decompresses the electronic files and archive transfer list in the data package, extracts the original handwriting electronic signature handwriting feature information in the file; obtains the public key used for encryption of the national secret algorithm SM2 from the encryption server through an encrypted channel; generates a signature handwriting image based on the electronic signature handwriting feature information, and synthesizes the signature handwriting image onto the business flow document certificate; adds the electronic signature handwriting feature information, the original electronic files in the electronic archive data package, and the business flow document certificate with the synthesized signature handwriting image to a temporary electronic archive compressed data package; uses the public key to encrypt the temporary electronic archive compressed data package to obtain an encrypted electronic archive compressed data package; decrypts the encrypted electronic archive compressed data package, queries the file ID and HASH value in the encrypted electronic archive compressed data package corresponding to each business in the circulation link through the business server, and obtains the corresponding encrypted electronic archive compressed data package in the distributed file storage system according to the file ID; verifies the correctness of each file in the compressed package through the file HASH value.
[0019] According to another aspect of the present application, a non-transitory computer-readable storage medium storing computer instructions is proposed, wherein the computer instructions are used to enable the computer to execute the above-mentioned method for secure transmission of electronic archive files based on original handwriting signatures.
[0020] Original handwriting electronic signature technology can effectively ensure the authenticity, integrity and confidentiality of electronic file information, ensure that electronic files are not maliciously deleted or tampered with during transmission, and ensure the original value and significance of electronic files. Digital signatures represent the characteristics of electronic files and confirm that electronic files are indeed signed and issued by the sender.
[0021] The secure transmission method of this application can ensure the secure transmission of electronic archive files between the previous link and the next link in the archiving process, and ensure that the electronic archive files maintain their authenticity when migrating and transferring during the archiving and transfer process, so that the authenticity of the electronic archives is effectively guaranteed. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] like Figure 1 The figure shows a schematic diagram of using the original handwriting electronic signature to realize the authenticity of the electronic file in the exemplary embodiment of the present application;
[0023] Figure 2 The figure shows a schematic diagram of the asymmetric encryption process of a digital summary proposed in an exemplary embodiment of the present application;
[0024] Figure 3 The figure shows a flow chart of verifying the authenticity of an electronic document using a digital signature in an exemplary embodiment of the present application;
[0025] like Figure 4 Schematic diagram of electronic document verification using electronic signature in an embodiment of the present application;
[0026] like Figure 5 Shown is a structural block diagram of an exemplary electronic device that can be used to implement the embodiments of the present application. DETAILED DESCRIPTION
[0027] The following describes embodiments of the present application in more detail with reference to the accompanying drawings. Although certain embodiments of the present application are shown in the accompanying drawings, it should be understood that the present application can be implemented in various forms and should not be construed as limited to the embodiments described herein. Instead, these embodiments are provided to provide a more thorough and complete understanding of the present application. It should be understood that the drawings and embodiments of the present application are for illustrative purposes only and are not intended to limit the scope of protection of the present application.
[0028] It should be understood that the various steps described in the method embodiments of the present application can be performed in different orders and / or in parallel. In addition, the method embodiments may include additional steps and / or omit the steps shown. The scope of the present application is not limited in this respect.
[0029] The term "including" and its variations used in this document are open inclusions, that is, "including but not limited to". The term "based on" means "based at least in part on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one other embodiment"; the term "some embodiments" means "at least some embodiments". The relevant definitions of other terms will be given in the description below. It should be noted that the concepts of "first", "second", etc. mentioned in this application are only used to distinguish different devices, modules or units, and are not used to limit the order or interdependence of the functions performed by these devices, modules or units.
[0030] It should be noted that the modifications of "one" and "multiple" mentioned in this application are illustrative rather than restrictive. Those skilled in the art should understand that unless otherwise clearly indicated in the context, they should be understood as "one or more".
[0031] The names of the messages or information exchanged between multiple devices in the embodiments of the present application are only used for illustrative purposes and are not used to limit the scope of these messages or information.
[0032] Original handwriting electronic signature technology changes the current market model of CA digital certificates, moving from a model where all electronic signatures are certified by a CA to a biometric-based approach that requires no third-party authentication. Original handwriting signatures eliminate the need for CA certificates, effectively avoiding the risk of unreliable electronic documents due to unreliable CA certificates. This maximizes the assurance of genuine intent during electronic document verification and enhances the authenticity of electronic documents when verifying the four characteristics of electronic documents. The signature captures multi-dimensional behavioral characteristics of the signer's handwriting, including strokes, stroke order, pen pressure, pen speed, and signing time, into a data package. After this data is collected, the signature font is equipped with handwriting recognition capabilities. An algorithm extracts the signature's biometric information, using graphological principles to trace the handwriting's origin, analyze handwriting trends and writing habits, and perform intelligent comparisons to effectively verify the signature's authenticity. During the electronic document transmission process, offline and prior electronic signatures on documents, transfer approval forms, and other electronic signatures are recognized before and after transmission, and encrypted using handwriting. This ensures the authentic transmission of electronic documents during transfer, preventing tampering and attacks.
[0033] The present application proposes a method for secure transmission of electronic archive files based on original handwriting signatures, which encrypts metadata, files and original handwriting signature data packets in electronic archive data packets, associates electronic archive data packets, metadata, electronic signatures with archiving services, generates file summary information, and encrypts the electronic archive data packets to obtain encrypted electronic archive compressed data packets; reviews signature records according to the initiation and reception order of electronic archive transfer services, and uses asymmetric encryption to encrypt file summary information to generate a trusted electronic file; uses electronic signature handwriting features and archived electronic files to generate digital signature handwriting images, synthesizes the digital signature handwriting images into electronic archive data packets, establishes a secure channel to transmit electronic archive data packets and their trusted electronic files, and transfers the electronic archive compressed data packets, metadata, and digital signature handwriting images to the next link, which restores the digital signature handwriting images on the files in the received electronic archive compressed data packets to signature handwriting feature data. If they are the same as the signature handwriting features in the evidence storage module, the secure transmission of electronic archive files is completed.
[0034] like Figure 1The figure shows a schematic diagram of achieving electronic archive authenticity using an original handwriting electronic signature in an exemplary embodiment of the present application. Electronic files, metadata, and other related electronic archive business data are formatted as a layout file. The layout file is subjected to security processing including the original handwriting electronic signature, encryption using the national secret encryption algorithm, and a trusted timestamp, and then input into the electronic archive management system. The original handwriting electronic signature is used to achieve electronic archive authenticity. The electronic file data and its metadata-related information are formatted to generate an archive information data package. The original handwriting electronic signature is applied to the electronic archive transfer registration and approval form. The entire process of transferring electronic archive files is recorded. At the same time, the generated archive data package is trusted. The transfer and acceptance of electronic archives is achieved through the national secret SM2 algorithm, the original handwriting electronic signature, the trusted timestamp, and other methods. At the same time, the authenticity of the electronic file is verified by signing and storing the signed original handwriting electronic signature, comparing the signatory's identity information, digital summary information, handwriting restoration, etc.
[0035] By determining whether there is business evidence in the previous link, the consistency of the evidence data in each link of the same business flow is compared: if it is consistent, it is passed; if it is inconsistent, it is rejected. At the same time, it is necessary to verify the consistency of the signed document of the business evidence and the signed document of the signed evidence to check whether the HASH list of the business evidence documents in each link is missing.
[0036] Combine the original handwritten electronic signature to sign the electronic document and complete the secure transmission of the electronic archive file.
[0037] The business system obtains the original electronic archive files with electronic signatures and seals, generates metadata related to the archive files, generates electronic archive transfer registration forms, transfer archive details, review forms and other documents that need to be signed and confirmed, and packages the above files to generate archive data packages.
[0038] The business system and archive management system call the original handwriting electronic signature module. When the electronic archive is transferred, the files and transfer lists in the archive data package are reviewed and signed, and the identity information of the sender and receiver reviewers are verified. After the verification is passed, the reviewer reviews the electronic archive and signs online to confirm the receipt is completed. The electronic signature handwriting feature information, signing time, file hash value, archiving time, current receiving and review signing time, signed electronic signature handwriting feature information, and file hash value signed in the previous link are obtained. Summary information is generated based on the above-mentioned archived document package file and signature information. The digital summary information is encrypted to form a digital signature. The digital signature time information is recorded through a trusted timestamp. The summary information is used as the original text of the timestamp signature data to recalculate the new digital summary information; the digital summary information is encrypted through asymmetric encryption technology to form a timestamp digital signature. The generated digital summary information, timestamp digital signature, summary digital signature information, etc. are bound to the archive data package to generate a trusted electronic file. After the electronic archive data package is transferred from the previous link to the next link, the authenticity of the electronic signature in the archived data package is verified to ensure that the electronic signature on the electronic archive file is a genuine and valid electronic signature signed by the legal signatory. The electronic archive signature verification stage of the transfer link verifies the authenticity of the electronic file by comparing and verifying the generated digital summary information.
[0039] Signed electronic documents are stored using blockchain encryption technology to provide evidence of both the business and the signing process, linking the signed document with the business voucher. The stored evidence includes the handwritten signature information before and after the transfer, the signing time, the file hash value, and the filing time.
[0040] This embodiment of the application records encrypted summary information based on the business initiation and signing sequence of the transferred electronic archive data package file, using asymmetric encryption to encrypt the file summary information. The file summary information includes signature information, signatory information, signature event information, file information, signing event, and other signing information. A hash digest is calculated based on the signature information and compared with the generated encrypted hash digest to ensure the originality and authenticity of the transferred electronic archive data package file.
[0041] Signatory information includes: signatory's name, valid ID number, and role; signature information includes: signing initiation time, signing end time, start time and end time of each signing, and signing ID; file information includes: archive data package file hash value, file archiving time, and other information; signing events include: review signature, submission signature, transfer signature, archiving signature, and other events.
[0042] like Figure 2The figure shows a schematic diagram of the asymmetric encryption process of the digital summary proposed in an embodiment of the present application, sampling asymmetric encryption, such as the sending end uses key A to encrypt the signature information, signatory information, signature events, file information, signing events, metadata, archive files, etc. in the process of transferring electronic files, and at the same time performs encryption operation on the transferred archive data packet, (*&, the encrypted ciphertext received by the receiving end) (*&,, B) uses a key B different from that of the encryption end to decrypt the received transferred electronic file ciphertext data, and obtains the original information of the transferred electronic file through decryption operation.
[0043] The electronic archive management system accepts timestamp services, connects to various business systems, provides business data, formats and solidifies layout files, uses trusted timestamps to record digital signature time information for electronic files, and uses the summary information as the original text of the timestamp signature data to recalculate new digital summary information.
[0044] like Figure 3 Shown is a schematic diagram of the process of verifying the authenticity of an electronic file using a digital signature in an exemplary embodiment of the present application.
[0045] The signature information, signed documents, and metadata of the transferred electronic archive are encrypted using MD5 (Message Digest Algorithm Version 5) to generate a digital summary. This includes signature information, signatory information, signature event information, document information, and signature event information. This digital summary is then encrypted using asymmetric encryption to form a timestamp digital signature. The generated digital summary information, timestamp digital signature, and summary digital signature information are then bound to the archived data package of the transferred electronic archive to create a trusted electronic file. Using a sample asymmetric encryption algorithm, the sender encrypts the ciphertext with the public key, and the receiver decrypts the received ciphertext with the private key. Specifically, the equations are: plaintext + encryption algorithm + public key = ciphertext, and ciphertext + decryption algorithm + private key = plaintext.
[0046] The sending end encrypts the original handwriting data of the electronic signature in the electronic document to obtain digital summary 1, and the receiving end decrypts the encrypted digital summary using the public key to obtain digital summary 2. The digital summary 1 and digital summary 2 are compared, and if they are equal, the verification is passed.
[0047] In the embodiment of the present application, the encryption end and the decryption end generate a digital digest using the original handwriting data of the electronic signature in the electronic document, specifically including:
[0048] The sending end uses archived electronic files, signature information, and electronic signature handwriting feature information to generate a public key, and uses the MD5 encryption algorithm to encrypt the signature information, signing time, and original handwriting signature data in the electronic files in the archived data package, transfer registration form and other files to generate summary information, and uses the private key to encrypt the summary information to obtain the signature data.
[0049] The receiving end extracts the signature data from the received file, encrypts the signature data using the MD5 (Message Digest Algorithm Version 5) encryption algorithm to obtain summary information, and decrypts the obtained summary using the public key obtained from the sending end for comparison and judgment. Based on whether the summary information is equal, it is determined whether the received electronic file has been tampered with.
[0050] Signed documents serve as a record of electronic signatures, including signature traceability, signature evidence, evidence download, and evidence summary. The evidence report includes essential signature data information such as the signature summary, signatory information, signature event, signing completion time, and evidence event.
[0051] In the process of transferring electronic archives, this implementation compares and verifies the electronic signature handwriting feature information on the electronic archive files sent before and after the transfer with the stored electronic signature feature information to ensure the authenticity of the handwriting features signed before and after the transfer. Using the verified electronic signature handwriting features, the archived electronic file generates a digital signature handwriting image, which is synthesized in the archived electronic file and transferred to the next link.
[0052] In the embodiment of the present application, the authenticity verification of the signature handwriting features and the generation of the digital signature handwriting image include: extracting the electronic signature sequence data of the handwritten signature in the electronic archive data package file, converting the handwritten signature material in the electronic archive file into an image, detecting and extracting the handwritten signature image, the converted signature material image not only contains a single signature image, but may also contain a certain degree of other background, and the target detection algorithm can be used to first detect the handwritten signature position area of the file; therefore, based on the existing signature area, further signature clipping is performed, and the complete handwritten signature image is extracted from the original detection area for binarization and storage, and finally the pre-processed binarized signature image is obtained.
[0053] When signing documents and registration forms, electronic signature sequence data is verified, including quality screening, sequence repair, and resampling. The signature trajectory coordinates, pressure, pen-up and pen-up states, and time distribution within the current electronic signature sequence data are determined. The electronic signature sequence data is then converted to electronic signature image data. The coordinates and pen-up and pen-up states within the electronic signature sequence data are used to generate a binary image for echo. The image width*height*channels can be 224*112*1, generating the electronic signature image data.
[0054] Align and pre-process the handwritten binary signature image and electronic signature image data in the archive file, aligning them in terms of thickness, scale, and spatial position. This mainly includes:
[0055] 1) Scale alignment: The size of the extracted binary signature image also changes dynamically, and there may be a problem of smaller signature size due to noise and wild points. Therefore, dilation, erosion and wild point removal operations are used to perform background denoising and background edge removal on the binary signature image. 2) Spatial position alignment: Due to the signature angle, character spacing and signature non-centering issues in the binary signature image, the signature angle is improved through affine transformation operations. The character spacing of the electronic signature dynamically adjusts the maximum and minimum character spacing in the paper signature, and the signature is centered according to the pixel bounding box so that the signature is in the center of the image. At the same time, the entire image is scaled to a fixed size. 3) Thickness alignment: The binary signature image is overall thicker in visual appearance and shows dynamic changes, that is, the thickness range of different signatures jumps relatively large. Since the electronic signature image is a binary echo, the stroke thickness is consistent. The skeleton refinement algorithm is used to process it so that the two reach the same thickness level. Image pairs are constructed. All electronic signature images are matched with their corresponding ID binary signature images in a 1V1 manner and then spliced on the channel to obtain electronic-binarized signature image pairs. The dataset of the electronic-binarized signature image pairs is divided into labeled datasets and unlabeled datasets. The unlabeled dataset generates multiple unlabeled subsets through adversarial samples. The labeled dataset and unlabeled subsets are input into the classification training handwriting recognition model, and the identity of the signatory is verified through transmembrane state comparison.
[0056] Electronic signatures are collected and captured, handwriting feature vectors are standardized, and encryption and decryption verification is performed based on the combination of handwritten electronic signatures and national secret algorithms. Handwritten original handwriting electronic signature data is collected using electronic devices such as tablets and electronic screens. The original handwritten electronic signature data is standardized and features are extracted from the standardized original handwriting data to form a unified feature vector. The unified feature vector is converted into a personal identification password public and private key using the national secret identification password algorithm. This is encrypted using the national secret algorithm to form a vector key. The electronic signature data is encrypted using the vector key to form an encrypted digital signature and store it. Feature extraction is performed on the electronic signature, signature style clustering is performed, sample style features are calculated, standardized style features are predefined, and the signature mapper obtains weight biases and constructs a signature key library. The key library weight bias is set, signature features are extracted, and the signature mapper reconstructs style features based on the weight bias and extracted features. Identity verification is performed using identity features. Extract the features of the original handwriting data of the standardized signature, call the national secret algorithm to encrypt and process the unified feature vector to generate the public and private keys of the personal identification password, encrypt the public and private keys to form a vector key, use the vector key to encrypt the electronic signature data to form an encrypted digital signature and generate ciphertext, use the handwritten electronic signature feature vector to generate a private key, use the private key to call the national secret algorithm to decrypt the ciphertext generated by the encrypted digital signature to generate plaintext, call the national secret algorithm to calculate the plaintext hash based on the plaintext, call the private key to encrypt the plaintext hash and generate a digital signature; decrypt and reconstruct based on the user name and its original signature handwriting features, the signature mapper obtains the weight bias, verifies the collected electronic signature data to extract the signature features, sets the key library weight bias, and the signature mapper reconstructs the style features based on the weight bias and the extracted features to obtain the electronic signature image pair.
[0057] During the transfer of electronic documents, if a third-party signature server needs to be called for signing and verification, the signed document that has been stored will be verified through blockchain evidence verification to verify whether the document has been tampered with.
[0058] like Figure 4 The figure shows a schematic diagram of verifying a transmitted electronic document using an electronic signature in an embodiment of the present application. A user submits information and applies for a certificate. Upon approval, a certificate text is generated based on the user information. A private key and public key pair are generated based on the certificate text. The electronic certificate is verified and a digital certificate is generated using the user information, public key, and the user's own private key signature. The private key and digital certificate are then returned to the user terminal, which decrypts the digital certificate using the returned private key.
[0059] The specific implementation methods of electronic signature and business document evidence data package encryption / decryption management include: using the national secret encryption algorithm to encrypt the metadata business file data package and signature data package in the electronic archive data package, and associating the electronic archive data package, metadata, electronic signature and electronic archive archiving business; establishing a secure channel, and encrypting the data transmitted in the electronic archive data package that needs to be transferred through the national secret algorithm: using the national secret algorithm SM4 (a packet data algorithm for wireless LAN standards. Symmetric encryption, key length and packet length are both 128 bits) to encrypt the transmitted electronic archive data package; using the national secret algorithm SM2's key exchange algorithm to calculate the secure channel password; using the SM2 signature algorithm to verify the signature of the data in the transmitted electronic archive data package.
[0060] Use the national secret encryption algorithm to encrypt the electronic signature data package and business file data package and associate them with the business.
[0061] 1. Establishment of a secure channel
[0062] (1) SM4 (GM / T 0002-2012) is used to encrypt the signature information data of the transmitted signed document.
[0063] (2) The SM2 (GB / T 32918) key exchange algorithm is used to calculate the password used in the secure channel.
[0064] (3) Use the SM2 (GB / T 32918) signature algorithm to verify the signature of the transmitted data.
[0065] 2. Electronic signature and business document data package encryption
[0066] (1) Obtain the public key used for SM2 encryption from the server through an encrypted channel.
[0067] (2) Generate a signature handwriting image from the original data of the electronic signature.
[0068] (3) Composite the signature handwriting image onto the document transferred to the electronic file.
[0069] (4) Add the original electronic signature data, the original signed document transferred to the electronic archive, and the archive file of the synthesized signature handwriting image to a temporary compressed package (zip data package).
[0070] (5) Using the SM2 algorithm, the public key obtained from the server is used to encrypt the temporary zip data packet, obtain the encrypted zip data packet, and delete the temporary zip data packet.
[0071] 3. Secure data transmission
[0072] (1) The encrypted zip data package is transmitted to the server using a secure channel.
[0073] (2) The server verifies the data signature to ensure the authenticity and integrity of the transmitted data.
[0074] 4. Data service association
[0075] (1) Calculate the HASH value of the encrypted zip data packet using SM3 (GM / T 0004-2012).
[0076] (2) The encrypted zip data package is stored in the distributed file storage system and the file ID is returned.
[0077] (3) Store the file ID and file HASH value in the business system database to complete the association between the business and the data packet.
[0078] Encrypt the electronic files in the electronic archive data package, the electronic signatures in the transfer list, and the business document and certificate data package. Obtain the electronic archive data package, decompress it to obtain the electronic files and archive transfer list in the package, and extract the electronic signature biometric data information from the archive file data package; obtain the public key used for encryption using the national secret algorithm SM2 from the encryption server through an encrypted channel; generate a signature handwriting image based on the handwriting biometric data of the electronic signature, and synthesize the signature handwriting image onto the document and certificate; add the electronic signature handwriting feature data, the original electronic file in the electronic archive data package, and the document and certificate file with the synthesized signature handwriting image to a temporary electronic archive compressed data package (zip compressed data package); encrypt the temporary electronic archive compressed data package using the national secret algorithm SM2 (asymmetric encryption, based on ECC) using the public key obtained from the encryption server (the public key used for encryption using the national secret algorithm SM2 is obtained from the encryption server through an encrypted channel) to obtain an encrypted electronic archive compressed data package, and delete the temporary compressed data package.
[0079] Secure transmission: During the transfer of electronic archive data, secure transmission of electronic archive data is required. The process of transferring data from the business system to the collection system, from the collection system to the transfer system, and finally from the transfer system to the collection system involves the transmission and storage of large amounts of data files. During this transfer process, the authenticity and validity of electronic archive data must be guaranteed, and the entire transfer cycle of electronic archives must be recorded. The electronic archive data packages are encrypted and transmitted using a secure channel throughout the entire transfer process.
[0080] The system server of the previous circulation link transmits the encrypted electronic archive compressed data package to the server of the next circulation link using a secure channel. The server of the next circulation link verifies the electronic signature data of the electronic archive data package to ensure the authenticity and integrity of the data in the archive compressed data package transmitted through the secure channel.
[0081] Data service association: During the transfer and transmission of electronic archive file data packets, data services need to be associated.
[0082] The encryption algorithm SM3 (message digest algorithm) is used to calculate the HASH value of the encrypted electronic archive compressed data package (zip package); the encrypted electronic archive compressed data package is stored in the distributed file storage system, and the file ID of each file in the data package is marked and returned; the file mark ID is associated with the file HASH value and stored in the business system database to complete the association between the business and the data package.
[0083] Obtain encrypted data packages and decrypt and manage electronic archive data packages, electronic signatures, and business flow document evidence packages. Query the file ID and hash value in the encrypted electronic archive compressed data package corresponding to each business in the flow link through the business server; obtain the corresponding encrypted electronic archive compressed package file from the distributed file storage system based on the file ID; and verify the hash value of each file in the compressed package to ensure the correctness of the file.
[0084] Decrypt the encrypted data packet, decrypt the electronic archive compressed data packet through the cipher machine to obtain the unencrypted electronic archive compressed data packet file; decompress the electronic archive compressed data packet, extract the electronic signature handwriting feature data, the original business document certificate file, and the certificate file with the synthesized signature handwriting image in the electronic archive file, and complete the decryption of the electronic archive data packet.
[0085] The exemplary embodiment of this application uses RSA signature to complete digital signature, specifically including:
[0086] When electronic files are transferred from the previous link to the next link in the circulation, a secure channel is used for transmission and the transferred files are digitally signed.
[0087] The sender generates a 128-bit hash value as the message digest from the electronic archive archive electronic file message in the decrypted electronic archive compressed data package using a digest algorithm, and encrypts the hash value using the RSA algorithm and the sender's own private key to generate a digest ciphertext as the sender's digital signature;
[0088] Send the digital signature as an attachment to the message (the archived electronic file of the electronic archive) and to the recipient together with the message:
[0089] The receiver uses the same digest algorithm as the sender to calculate a 128-bit hash value from the electronic archive file in the received decrypted electronic archive compressed data package, and uses the RSA algorithm and the sender's public key to decrypt the digital signature attached to the message. If the two hash values are the same, the receiver can confirm that the message has been signed and confirmed by the sender and no error or tampering has occurred.
[0090] Digital signature methods based on public key cryptography technology can also use DSA signatures and elliptic curve digital signature algorithm (ECDSA), etc.
[0091] The Message Digest 5 (MD5) algorithm can be used as a digest algorithm. The MD5 algorithm uses a one-way hash function to transform a byte string of any length in an electronic file into a 128-bit hash value. This irreversible string transformation algorithm means that an MD5 hash value cannot be converted back to the original string. This 128-bit hash value is also called a digital fingerprint. Much like a human fingerprint, it serves as the "fingerprint" for verifying the identity of the message.
[0092] The authenticity of the electronic archive data package is guaranteed by digital signatures. The recipient uses the same digest algorithm to calculate the message digest of the received electronic archive message. If the message digests are the same, the archive file has not been tampered with. If the digests are different, it can be determined that the received electronic archive message is inconsistent with the originally sent electronic archive message, and the file in the received electronic archive data package has been tampered with.
[0093] If a file in an electronic archive data package is modified during network transmission, the message digest calculated by the receiver using the same digest algorithm as the sender will be different after receiving the message. This ensures that the receiver can determine whether the message has been modified from the time it was signed until it was received. If the sender wants the receiver to mistakenly believe that the message was signed and sent by the sender, since the receiver does not know the sender's private key, when the receiver uses the sender's public key to decrypt the message digest encrypted by the sender, the result will also be a different message digest. This ensures that the receiver can determine whether the message was sent by the designated signer.
[0094] The exemplary embodiments of the present application further provide an electronic device, comprising: at least one processor; and a memory communicatively connected to the at least one processor. The memory stores a computer program executable by the at least one processor, wherein the computer program, when executed by the at least one processor, causes the electronic device to perform a method according to an embodiment of the present application.
[0095] An exemplary embodiment of the present application further provides a non-transitory computer-readable storage medium storing a computer program, wherein the computer program, when executed by a processor of a computer, is used to cause the computer to perform a method according to an embodiment of the present application.
[0096] An exemplary embodiment of the present application further provides a computer program product, including a computer program, wherein when the computer program is executed by a processor of a computer, it is used to cause the computer to perform the method according to the embodiment of the present application.
[0097] refer to Figure 5 , a block diagram of an electronic device 300 that can serve as a server or client of the present application will now be described, which is an example of a hardware device that can be applied to various aspects of the present application. The electronic device is intended to represent various forms of digital electronic computer equipment, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processing, cellular phones, smart phones, wearable devices and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present application described and / or required herein.
[0098] like Figure 5 As shown, electronic device 300 includes a computing unit 301, which can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 302 or a computer program loaded from a storage unit 308 into a random access memory (RAM) 303. RAM 303 may also store various programs and data required for the operation of device 300. Computing unit 301, ROM 302, and RAM 303 are interconnected via a bus 304. An input / output (I / O) interface 305 is also connected to bus 304.
[0099] Multiple components within electronic device 300 are connected to I / O interface 305, including an input unit 306, an output unit 307, a storage unit 308, and a communication unit 309. Input unit 306 can be any type of device capable of inputting information into electronic device 300. Input unit 306 can receive input numeric or character information and generate key signal inputs related to user settings and / or function control of the electronic device. Output unit 307 can be any type of device capable of presenting information and may include, but is not limited to, a display, a speaker, a video / audio output terminal, a vibrator, and / or a printer. Storage unit 308 may include, but is not limited to, a magnetic disk or an optical disk. Communication unit 309 allows electronic device 300 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks and may include, but is not limited to, a modem, a network card, an infrared communication device, a wireless communication transceiver and / or a chipset, such as a Bluetooth device, a WiFi device, a WiMax device, a cellular communication device, and / or the like.
[0100] The computing unit 301 can be any general-purpose and / or specialized processing component with processing and computing capabilities. Some examples of the computing unit 301 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The computing unit 301 performs the various methods and processes described above. For example, in some embodiments, the reconstruction and decomposition of muscle movement trajectories based on the original trajectory of a signature stroke, as well as the decomposition of its logarithmic velocity curve, can be implemented as a computer software program tangibly embodied in a machine-readable medium, such as the storage unit 308. In some embodiments, part or all of the computer program can be loaded and / or installed on the electronic device 300 via the ROM 302 and / or the communication unit 309. In some embodiments, the computing unit 301 can be configured to perform the signature handwriting dynamic acquisition implementation method through any other suitable means (e.g., via firmware).
[0101] The program code for implementing the methods of the present application can be written in any combination of one or more programming languages. Such program code can be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device, so that when the program code is executed by the processor or controller, the functions / operations specified in the flow charts and / or block diagrams are implemented. The program code can be executed entirely on the machine, partially on the machine, as a stand-alone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.
[0102] In the context of this application, a machine-readable medium may be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, device, or apparatus. A machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium may include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of machine-readable storage media may include an electrical connection based on one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), optical fibers, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0103] As used herein, the terms "machine-readable medium" and "computer-readable medium" refer to any computer program product, apparatus, and / or device (e.g., a magnetic disk, an optical disk, a memory, a programmable logic device (PLD)) for providing machine instructions and / or data to a programmable processor, including a machine-readable medium that receives machine instructions as a machine-readable signal. The term "machine-readable signal" refers to any signal for providing machine instructions and / or data to a programmable processor.
[0104] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the computer. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).
[0105] The systems and techniques described herein can be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer with a graphical user interface or a web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network (LAN), a wide area network (WAN), and the Internet.
[0106] Computer systems may include clients and servers. A client and server are generally remote from each other and typically interact through a communication network. The client and server relationship arises through computer programs running on the respective computers and having a client-server relationship to each other.
Claims
1. A method for secure transmission of electronic archive files based on electronic signatures, characterized in that: Encrypting metadata, electronic files, and original handwriting signature data packages in the electronic archive data package, associating the electronic archive data package, metadata, electronic signature, and archiving business, generating file summary information, and obtaining an encrypted electronic archive compressed data package; The signature record is reviewed based on the order in which the electronic archive transfer business is initiated and received, and the file summary information is encrypted using asymmetric encryption to generate a trusted electronic file. A digital signature handwriting image is generated using the electronic signature handwriting characteristics and the archived electronic file. The digital signature handwriting image is synthesized into the electronic archive data package, and a secure channel is established to transmit the electronic archive data package and the trusted electronic file. The electronic archive compressed data package, metadata, and digital signature handwriting image are transferred to the next link. The next link restores the digital signature handwriting image on the file in the received electronic archive compressed data package to signature handwriting feature data. If it is the same as the signature handwriting feature in the evidence storage module, the secure transmission of the electronic archive file is completed. The method for generating a digital signature handwriting image comprises: using the coordinate position and the starting and lifting states of the electronic signature sequence data in the electronic archive data package file to perform binary image echoing, segmenting the electronic signature sequence into single words to produce a single word sequence word library, searching for a single word sequence with the same content from the single word sequence word library according to the echoed electronic signature image, performing signature splicing to obtain a new electronic signature sequence, disturbing the strokes in the corresponding electronic signature orthographic sequence to generate a new electronic signature sequence, generating electronic signature imitation image data by binarizing the generated electronic signature sequence, aligning the echoed signature image and the signature imitation image, and then performing the following steps: The method further comprises: extracting the features of the original handwriting data of the signature after standardization to form a unified feature vector, encrypting the unified feature vector with a national secret algorithm to generate a public and private key of the personal identification password, encrypting the public and private keys to form a vector key, encrypting the electronic signature data with the vector key to form an encrypted digital signature and generate ciphertext, generating a private key with the handwritten electronic signature feature vector, decrypting the ciphertext generated by the encrypted digital signature with the private key and generating plaintext by calling the national secret algorithm, calculating a plaintext hash based on the plaintext with the national secret algorithm, encrypting the plaintext hash with the private key, and generating a digital signature; Based on the decryption and reconstruction of the user name and the original handwriting features of the signature, the signature mapper obtains the weight bias, verifies the collected electronic signature data to extract the signature features, sets the key library weight bias, and the signature mapper reconstructs the style features according to the weight bias and the extracted features to obtain the electronic signature image pair.
2. The method according to claim 1, characterized in that During the transfer of electronic files, the receiving end reviews and signs the received archive data package file and transfer list, and verifies the identity information of the reviewer. After the verification is passed, the reviewer reviews the electronic file and signs online to confirm the receipt. The electronic signature handwriting feature information, signing time, file hash value, and archiving time are obtained to generate digital summary information, and the digital summary information is encrypted to form a timestamp digital signature. The digital signature time information is recorded through a trusted timestamp, and the archive data package file received with the summary information as the timestamp signature is recalculated to generate a new digital summary information. The generated digital summary information, timestamp digital signature, and new digital summary information are bound to the archive data package to generate a trusted electronic file.
3. The method according to claim 1 or 2, characterized in that The electronic archive data packet is encrypted using the national secret algorithm SM4, and the security channel password is calculated using the key exchange algorithm of the national secret algorithm SM2; the signature algorithm of the national secret algorithm SM2 is used to verify the signature of the transmitted electronic archive data packet; the encryption algorithm SM3 is used to calculate the HASH value of the encrypted electronic archive compressed data packet, and the encrypted electronic archive compressed data packet is stored in the distributed file storage system, and the file tag ID is marked for each file in the data packet in the distributed file storage system and returned to the business system; the file tag ID is associated with the file HASH value and stored in the business system database to complete the association between the business and the data packet.
4. The method according to claim 1 or 2, characterized in that Obtain the electronic archive data package, decompress it to obtain the electronic files and archive transfer list in the data package, and extract the original handwriting electronic signature handwriting feature information in the file; obtain the public key used for encryption using the national encryption algorithm SM2 from the encryption server through an encrypted channel; generate a signature handwriting image based on the electronic signature handwriting feature information, and synthesize the signature handwriting image onto the business flow document certificate; add the electronic signature handwriting feature information, the original electronic file in the electronic archive data package, and the business flow document certificate with the synthesized signature handwriting image to the temporary electronic archive compressed data package; The public key is used to encrypt the temporary electronic archive compressed data package to obtain an encrypted electronic archive compressed data package; the encrypted electronic archive compressed data package is decrypted, and the file ID and HASH value in the encrypted electronic archive compressed data package corresponding to each business in the circulation link are queried through the business server, and the corresponding encrypted electronic archive compressed data package is obtained in the distributed file storage system according to the file ID; Verify the correctness of each file in the compressed package through the file HASH value.
5. The method according to claim 1 or 2, characterized in that The sending server generates a 128-bit hash value from the electronic archive data packet using a digest algorithm, encrypts the hash value using the RSA algorithm and the sender's private key, and generates a digest ciphertext as the sender's digital signature; the digital signature is sent to the receiving server as an attachment to the electronic archive compressed data packet; the receiving end uses the same digest algorithm as the sending end to calculate and generate a 128-bit hash value for the received file, decrypts the attached digital signature using the RSA algorithm and the sender's public key, and confirms whether the electronic file in the received electronic archive compressed data packet is the original archive file confirmed by the sender's signature based on the hash value and decryption result; the digest algorithm uses the MD5 algorithm, and uses a one-way hash function to transform a byte string of any length in the electronic file in the electronic archive compressed data packet into a 128-bit hash value. The receiving end uses the same digest algorithm to calculate the message digest of the received file. If the message digests are the same, the file in the received electronic archive data packet has not been tampered with. If the message digests are different, the file in the received electronic archive data packet has been tampered with.
6. The electronic file security transmission system based on original handwriting signature is characterized by: The encryption module encrypts metadata, files, and original handwriting signature data packets in the electronic archive data packet, associates the electronic archive data packet, metadata, electronic signature, and archiving business, generates file summary information, encrypts the electronic archive data packet to obtain an encrypted electronic archive compressed data packet, reviews the signature record according to the initiation and reception order of the electronic archive transfer business, and uses asymmetric encryption to encrypt the file summary information to generate a trusted electronic file; The signature verification module uses the electronic signature handwriting characteristics and archived electronic files to generate a digital signature handwriting image, and the digital signature handwriting image is synthesized into the electronic archive data package; The transmission module establishes a secure channel to transmit electronic archive data packets and trusted electronic files, and transfers the electronic archive compressed data packets, metadata, and digital signature handwriting images to the next link receiving end. The receiving end restores the digital signature handwriting images on the files in the received electronic archive compressed data packets to signature handwriting feature data. If they are the same as the signature handwriting feature data in the evidence storage module, the secure transmission of the electronic archive files is completed; The method for generating a digital signature handwriting image comprises: using the coordinate position and the starting and lifting states of the electronic signature sequence data in the electronic archive data package file to perform binary image echoing, segmenting the electronic signature sequence into single words to produce a single word sequence word library, searching for a single word sequence with the same content from the single word sequence word library according to the echoed electronic signature image, performing signature splicing to obtain a new electronic signature sequence, disturbing the strokes in the corresponding electronic signature orthographic sequence to generate a new electronic signature sequence, generating electronic signature imitation image data by binarizing the generated electronic signature sequence, aligning the echoed signature image and the signature imitation image, and then performing the following steps: The method further comprises: extracting the features of the original handwriting data of the signature after standardization to form a unified feature vector, encrypting the unified feature vector with a national secret algorithm to generate a public and private key of the personal identification password, encrypting the public and private keys to form a vector key, encrypting the electronic signature data with the vector key to form an encrypted digital signature and generate ciphertext, generating a private key with the handwritten electronic signature feature vector, decrypting the ciphertext generated by the encrypted digital signature with the private key and generating plaintext by calling the national secret algorithm, calculating a plaintext hash based on the plaintext with the national secret algorithm, encrypting the plaintext hash with the private key, and generating a digital signature; Based on the decryption and reconstruction of the user name and the original handwriting features of the signature, the signature mapper obtains the weight bias, verifies the collected electronic signature data to extract the signature features, sets the key library weight bias, and the signature mapper reconstructs the style features according to the weight bias and the extracted features to obtain the electronic signature image pair.
7. The system according to claim 6, characterized in that The receiving end reviews and signs the received archive data package file and transfer list, and verifies the identity information of the reviewer. After the verification is passed, the reviewer reviews the electronic file and signs online to confirm the receipt. The electronic signature handwriting feature information, signing time, file hash value, and archiving time are obtained to generate digital summary information, and the digital summary information is encrypted to form a timestamp digital signature. The digital signature time information is recorded through a trusted timestamp, and the archive data package file received with the summary information as the timestamp signature is recalculated to generate a new digital summary information. The generated digital summary information, timestamp digital signature, and new digital summary information are bound to the archive data package to generate a trusted electronic file.
8. The system according to claim 6, characterized in that The electronic archive data packet is encrypted using the national secret algorithm SM4, and the security channel password is calculated using the key exchange algorithm of the national secret algorithm SM2; the signature algorithm of the national secret algorithm SM2 is used to verify the signature of the transmitted electronic archive data packet; the encryption algorithm SM3 is used to calculate the HASH value of the encrypted electronic archive compressed data packet, and the encrypted electronic archive compressed data packet is stored in the distributed file storage system, and the file tag ID is marked for each file in the data packet in the distributed file storage system and returned to the business system; the file tag ID is associated with the file HASH value and stored in the business system database to complete the association between the business and the data packet.
9. The system according to any one of claims 6 to 8, characterized in that: The signature verification module decompresses the electronic files and archive transfer list in the data package, extracts the handwriting characteristics of the original electronic signature in the file, obtains the public key used for encryption using the national encryption algorithm SM2 from the encryption server through an encrypted channel, generates a signature handwriting image based on the electronic signature handwriting characteristics, and synthesizes the signature handwriting image onto the business flow document. The electronic signature handwriting characteristics, the original electronic file in the electronic archive data package, and the business flow document with the synthesized signature handwriting image are added to the temporary electronic archive compressed data package. The public key is used to encrypt the temporary electronic archive compressed data package to obtain an encrypted electronic archive compressed data package; the encrypted electronic archive compressed data package is decrypted, and the file ID and HASH value in the encrypted electronic archive compressed data package corresponding to each business in the circulation link are queried through the business server, and the corresponding encrypted electronic archive compressed data package is obtained in the distributed file storage system according to the file ID; Verify the correctness of each file in the compressed package through the file HASH value.
10. A non-transitory computer-readable storage medium storing computer instructions, characterized in that: in, The computer instructions are used to enable the computer to execute the method for securely transmitting electronic archive files with electronic signatures according to any one of claims 1 to 5.
Citation Information
Patent Citations
Method, system and equipment for signing multiple electronic files at one time and storage medium
CN114491462A
Evidence preservation apparatus, method of preserving evidence, and program
JP2010114725A