A multi-level cross-network electronic signature method and device based on a one-way network gatekeeper
Through the multi-level cross-network electronic signature method based on a one-way network gateway, the problem of mutual recognition and interoperability of electronic signatures between networks with different levels of security is solved, and the signature file verification of the high-level network to the low-level network is realized, ensuring the security and reliability of data transmission and improving the security execution efficiency of cross-network services.
Patent Information
- Application Number
- CN202311366698.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-10-20
- Publication Date
- 2025-09-05
- Estimated Expiration
- 2043-10-20
AI Technical Summary
It is difficult to mutually recognize and communicate electronic signatures between networks of different confidentiality levels. Staff on high-confidentiality networks are unable to verify the signature documents of low-confidentiality networks, posing a security risk.
A multi-level cross-network electronic signature method based on a one-way network gatekeeper is adopted. Document data is signed and encrypted through a low-level electronic signature system, and a one-way network gatekeeper is used for data transmission and verification to ensure that sensitive data is encrypted and transmitted to a high-level electronic signature system. Public key certificates are issued through the LDAP module to achieve mutual recognition of electronic signatures between high-level networks and low-level networks.
It realizes the mutual recognition and interoperability of electronic signatures between networks with different confidentiality levels, ensures the security and reliability of data transmission, and improves the security execution efficiency of cross-network business.
Smart Images

Figure CN117424706B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of multi-level cross-network electronic signature, and more specifically, to a multi-level cross-network electronic signature method and device based on a one-way network gateway. Background Art
[0002] With the widespread adoption of electronic processes throughout the enterprise, large enterprise groups have a strong demand for electronic signature applications. Various applications within networks of varying security levels require the use of electronic signature systems. However, because each network is isolated, only some applications utilize gateways to enable the flow of a portion of application data. For the use of electronic seals, each network essentially establishes its own electronic signature service. This model only addresses the electronic signature and seal requirements within a single network. In scenarios where three or more networks utilize the same set of applications, mutual recognition and interoperability of electronic signatures across multiple security levels cannot be achieved. Consequently, staff on high-security networks are unable to verify signature documents from lower-security networks within their applications, impacting the secure execution of cross-network services. Furthermore, data transmission between networks with multiple security levels is often not protected by security measures, posing significant security risks. Summary of the Invention
[0003] In view of the deficiencies of the prior art, the present invention provides a multi-level cross-network electronic signature method and device based on a one-way gateway.
[0004] According to one aspect of the present invention, a multi-level cross-network electronic signature method based on a one-way gateway is provided, comprising:
[0005] The low-level electronic signature system uses the network user's private key to sign the document data in the business system and affix an electronic signature to generate signature electronic seal data. The low-level electronic signature system also uses its private key to electronically sign all data to be transmitted and generate signature data.
[0006] The low-level electronic signature system transmits the document data, the electronic seal data, the signature data, the network user's public key KeyD1, and the low-level electronic signature system's public key KeyD2 to the high-level electronic signature system via a one-way gateway;
[0007] The one-way gatekeeper determines whether the document data is flowing from a low-level electronic signature system to a high-level electronic signature system. If not, the transmission is terminated. If so, the one-way gatekeeper verifies whether the signature data is valid based on the public key of the low-level electronic signature system. If not, the transmission is terminated.
[0008] If it is valid, the one-way gateway will identify the sensitive data in the document data and encrypt the data to generate encrypted document data, and transmit it together with the signature electronic seal data to the high-level electronic signature system;
[0009] The LDAP module of the one-way network gatekeeper publishes and transmits the network user public key and the low-level electronic signature system public key to the high-level electronic signature system;
[0010] The high-level electronic signature system decrypts the encrypted document data to obtain the document data, and verifies whether the document data is credible based on the low-level electronic signature public key and the signature electronic seal data.
[0011] Optionally, the one-way gatekeeper identifies sensitive data in the document data, including:
[0012] The one-way firewall automatically identifies sensitive data in document data based on natural language processing and regular expressions.
[0013] Optionally, performing data encryption to generate encrypted document data includes:
[0014] The national secret SM4 algorithm is used to encrypt document data to generate encrypted document data. The encryption method uses two negotiations and two encryptions with the low-level electronic signature system, and is securely transmitted in the form of a digital envelope.
[0015] Optionally, after the one-way network gatekeeper identifies sensitive data in the document data and encrypts the data to generate encrypted document data, the method further includes:
[0016] The one-way gateway negotiates keys with the high-security electronic signature system to generate new encryption symmetric keys for data transmission.
[0017] Optionally, the high-level electronic signature system verifies whether the document data is authentic based on the low-level electronic signature public key and the signed electronic seal data, including:
[0018] The high-level electronic signature system uses the public key of the low-level electronic signature system to verify the signature electronic seal data;
[0019] If the verification is successful, the signature electronic seal data is compared with the decrypted document data to determine whether the signature electronic seal data is valid. If it is valid, the document data is determined to be credible.
[0020] According to another aspect of the present invention, a multi-level cross-network electronic signature device based on a one-way gateway is provided, comprising:
[0021] The stamping and signing module is used by the low-level electronic signature system to sign and stamp the document data in the business system with the network user's private key to generate the signature electronic seal data. The low-level electronic signature system uses its private key to electronically sign all data to be transmitted and generate signature data.
[0022] The transmission module is used for the low-level electronic signature system to transmit document data, signature electronic seal data, signature data, network user public key KeyD1 and low-level electronic signature system public key KeyD2 to the high-level electronic signature system via a one-way network gateway;
[0023] The judgment module is used by the one-way network gate to judge whether the document data is flowing from the low-level electronic signature system to the high-level electronic signature system. If not, the transmission is terminated. If so, the one-way network gate verifies whether the signature data is valid based on the public key of the low-level electronic signature system. If not, the transmission is terminated.
[0024] The identification and encryption module is used to, if valid, enable the one-way gateway to identify sensitive data in the document data and encrypt the data to generate encrypted document data, and transmit it together with the signature electronic seal data to the high-security electronic signature system;
[0025] Publishing and transmission module, used for publishing LDAP module of one-way network gatekeeper, and transmitting network user public key and low-level electronic signature system public key to high-level electronic signature system;
[0026] The verification module is used by the high-level electronic signature system to decrypt encrypted document data, obtain document data, and verify whether the document data is credible based on the low-level electronic signature public key and signature electronic seal data.
[0027] According to another aspect of the present invention, a computer-readable storage medium is provided, wherein the storage medium stores a computer program, and the computer program is used to execute the method according to any one of the above aspects of the present invention.
[0028] According to another aspect of the present invention, an electronic device is provided, comprising: a processor; a memory for storing instructions executable by the processor; and the processor for reading the executable instructions from the memory and executing the instructions to implement the method described in any one of the above aspects of the present invention.
[0029] Therefore, this application adopts the strategy of deploying electronic signature systems on multiple networks separately, and then uses a special one-way network gate tool to realize the automatic flow of non-sensitive data such as signature sensitive data and public key certificates to the high-security network, thereby achieving the main purpose of high-security network application verification of low-security electronic seals. This application uses a one-way network gate to realize the one-way transmission of signature data and key data, and realizes the mutual recognition and interoperability of electronic signatures on networks of different security levels while ensuring the confidentiality requirements of each network. The one-way network gate encrypted transmission is implemented using a symmetric encryption algorithm and uses an adaptive encryption strategy, which has a faster transmission speed. BRIEF DESCRIPTION OF THE DRAWINGS
[0030] A more complete understanding of exemplary embodiments of the present invention may be obtained by referring to the following drawings:
[0031] Figure 1 1 is a flowchart of a multi-level cross-network electronic signature method based on a one-way gateway provided by an exemplary embodiment of the present invention;
[0032] Figure 2 1 is a schematic diagram of the structure of a multi-level cross-network electronic signature system based on a one-way gateway provided by an exemplary embodiment of the present invention;
[0033] Figure 3 This is a schematic diagram of a business process flow for transmitting data from a low-security level to a high-security level environment, provided by an exemplary embodiment of the present invention;
[0034] Figure 4 This is a schematic diagram of the structure of a multi-level cross-network electronic signature device based on a one-way gateway provided by an exemplary embodiment of the present invention;
[0035] Figure 5 This is a structure of an electronic device provided by an exemplary embodiment of the present invention. DETAILED DESCRIPTION
[0036] Below, the exemplary embodiments according to the present invention will be described in detail with reference to the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, rather than all the embodiments of the present invention, and it should be understood that the present invention is not limited to the exemplary embodiments described herein.
[0037] It should be noted that the relative arrangement of components and steps, the numerical expressions and numerical values set forth in these embodiments do not limit the scope of the present invention unless specifically stated otherwise.
[0038] Those skilled in the art will understand that the terms "first" and "second" in the embodiments of the present invention are only used to distinguish different steps, devices or modules, and neither represent any specific technical meaning nor indicate the necessary logical order between them.
[0039] It should also be understood that, in the embodiments of the present invention, “a plurality of” may refer to two or more than two, and “at least one” may refer to one, two or more than two.
[0040] It should also be understood that any component, data or structure mentioned in the embodiments of the present invention can generally be understood as one or more, unless explicitly limited or otherwise indicated in the context.
[0041] In addition, the term "and / or" in this invention merely describes an association relationship between related objects, indicating that three possible relationships exist. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. Furthermore, the character " / " in this invention generally indicates that the related objects are in an "or" relationship.
[0042] It should also be understood that the description of the various embodiments of the present invention focuses on the differences between the various embodiments, and the same or similar aspects thereof can be referenced with each other. For the sake of brevity, they will not be described one by one.
[0043] At the same time, it should be understood that for the convenience of description, the sizes of the various parts shown in the drawings are not drawn according to the actual proportional relationship.
[0044] The following description of at least one exemplary embodiment is merely illustrative in nature and is in no way intended to limit the invention, its application, or uses.
[0045] Technologies, methods, and equipment known to ordinary technicians in the relevant art may not be discussed in detail, but where appropriate, the technologies, methods, and equipment should be considered part of the specification.
[0046] It should be noted that like reference numerals and letters refer to like items in the following figures, and therefore, once an item is defined in one figure, it need not be further discussed in subsequent figures.
[0047] Embodiments of the present invention may be applied to electronic devices such as terminal devices, computer systems, and servers, and may operate in conjunction with numerous other general-purpose or specialized computing system environments or configurations. Examples of well-known terminal devices, computing systems, environments, and / or configurations suitable for use with terminal devices, computer systems, servers, and other electronic devices include, but are not limited to, personal computer systems, server computer systems, thin clients, thick clients, handheld or laptop devices, microprocessor-based systems, set-top boxes, programmable consumer electronics, network personal computers, minicomputer systems, mainframe computer systems, and distributed cloud computing technology environments including any of the above.
[0048] Electronic devices such as terminal devices, computer systems, and servers can be described in the general context of computer system-executable instructions (such as program modules) executed by a computer system. Generally, program modules can include routines, programs, object programs, components, logic, data structures, etc., which perform specific tasks or implement specific abstract data types. Computer systems / servers can be implemented in a distributed cloud computing environment, where tasks are performed by remote processing devices linked via a communication network. In a distributed cloud computing environment, program modules can be located on local or remote computing system storage media, including storage devices.
[0049] Exemplary Methods
[0050] Figure 1This is a flow chart of a multi-level cross-network electronic signature method based on a one-way gateway provided by an exemplary embodiment of the present invention. This embodiment can be applied to electronic devices, such as Figure 1 As shown, the multi-level cross-network electronic signature method 100 based on a one-way gateway includes the following steps:
[0051] Step 101: The low-level electronic signature system signs and stamps the document data in the business system with the network user's private key to generate signed electronic seal data. The low-level electronic signature system also uses its private key to electronically sign all data to be transmitted to generate signature data.
[0052] Step 102: The low-level electronic signature system transmits the document data, the electronic seal data, the signature data, the network user public key KeyD1, and the low-level electronic signature system public key KeyD2 to the high-level electronic signature system via a one-way gateway.
[0053] Step 103: The one-way gateway determines whether the document data is flowing from a low-level electronic signature system to a high-level electronic signature system. If not, the transmission is terminated. If so, the one-way gateway verifies whether the signature data is valid based on the public key of the low-level electronic signature system. If not, the transmission is terminated.
[0054] Step 104: If the data is valid, the one-way gateway identifies the sensitive data in the document data and encrypts the data to generate encrypted document data, and transmits the encrypted document data together with the signature electronic seal data to the high-security electronic signature system;
[0055] Step 105: The LDAP module of the one-way gateway publishes and transmits the network user public key and the low-level electronic signature system public key to the high-level electronic signature system;
[0056] In step 106, the high-level electronic signature system decrypts the encrypted document data to obtain the document data, and verifies whether the document data is credible based on the low-level electronic signature public key and the signature electronic seal data.
[0057] Specifically, this application uses a new one-way gateway tool and adds a data intelligent processing module to achieve secure transmission of signature data across multiple security levels. To address potential issues with electronic document source verification, document integrity verification, prevention of unauthorized document tampering, and non-repudiation of document signing, this application proposes a strategy for jointly deploying an electronic signature system across three networks. Furthermore, through a special one-way gateway, a solution is proposed to enable the adaptive flow of sensitive and non-sensitive data from low-security networks to high-security networks, thereby resolving the mutual recognition and trust issues of signed electronic documents and data in cross-network circulation.
[0058] Further, refer to Figure 2As shown, this application adopts the strategy of deploying electronic signature systems in multiple networks separately, and then uses a special one-way network gateway tool to enable signature-sensitive data, public key certificates and other non-sensitive data to automatically flow to the high-density network (wherein the low-density network is the low-density electronic signature system, and the high-density network is the high-density electronic signature system), thereby achieving the main purpose of high-density network application to verify low-density electronic seals.
[0059] Further, refer to Figure 2 As shown, in addition to the general data transmission functions of a one-way gateway, the one-way gateway also features modules for class-level determination, sensitive data identification, data encryption and decryption, and signature verification. It automatically identifies data types and adaptively implements encrypted or unencrypted transmission, thus supporting adaptability in complex security environments and ensuring the "free flow" of data. Furthermore, the signature verification module verifies electronically signed data transmitted over low-security networks, ensuring non-repudiation of the transmission source. The one-way gateway has a built-in LDAP directory module that publishes the public key certificates of all users and systems transmitted, which are used by the one-way gateway's signature verification module. The one-way gateway uses a sensitive data automatic identification module based on natural language processing and regular expressions to automatically identify sensitive data. Sensitive data such as signatures are securely encrypted, while public data such as public keys are directly transmitted, achieving adaptive encrypted transmission. The one-way gateway's electronic signature verification function ensures non-repudiation of data transmission and prevents other applications from impersonating the user. The electronic signature system for low-security networks includes a sending module. Before data is sent, it is electronically signed using the electronic signature system's key. When the data reaches the gatekeeper, it retrieves the public key from a built-in LDAP list and verifies the electronic signature. If verification succeeds, the data is transferred to the next higher security level. If not, the transmission fails and is returned.
[0060] Further, refer to Figure 2 and Figure 3 As shown, the one-way gatekeeper uses a two-way negotiation and two-way encryption method. The low-level electronic signature system negotiates a key with the one-way gatekeeper to generate a symmetric encryption key using the SM4 algorithm. This encrypts data between the two parties and ensures that low-level signature data can pass securely through the gatekeeper. After receiving the encrypted data, the one-way gatekeeper decrypts it and then negotiates a new key with the high-level electronic signature system to generate a new symmetric encryption key. This allows encrypted data transmission between the one-way gatekeeper and the high-level electronic signature system. After receiving the ciphertext, the high-level electronic signature system decrypts it for use.
[0061] Furthermore, this application solves the problem of free and secure transmission of data from low-level to high-level. Taking this scenario as an example, the business process of transferring signed documents, public keys and other data from low-level to high-level environments is introduced. Figure 3 .
[0062] 1. In a low-security environment, the user uses a business application to sign the business document data S with the user's private key and affix an electronic seal, which is recorded as signature electronic seal data S1. The electronic signature system uses the electronic signature system private key to electronically sign all data to be transmitted, which is recorded as signature data S2;
[0063] 2. The document data S, S1, S2, the low-level network user public key KeyD1, and the low-level electronic signature system public key KeyD2 are transmitted to the high-level area via a one-way gateway;
[0064] 3. The document passes through the "Secret Level Judgment" module of the one-way gateway to determine the transmission direction. If the document is not flowing from a low-security network to a high-security network, the transmission is terminated. Otherwise, it is deemed to have passed the judgment and the signature verification operation in step 4 is carried out to verify whether S2 is valid using the public key KeyD2 of the low-security electronic signature system.
[0065] 4. If the signature verification fails, the transmission is terminated; otherwise, the signature verification passes and the process goes to step 5;
[0066] 5. After S2 passes the signature verification, the one-way network gatekeeper will identify the sensitive data in document S and encrypt the data to generate the encrypted document data Enc(S). The encryption is performed using the national secret SM4 algorithm, with two negotiations and two encryptions, and is securely transmitted in the form of a digital envelope. After KeyD1 and KeyD2 are released by the network gatekeeper LDAP module, they are transmitted to the high-security network.
[0067] 6. After Enc(S) and S1 are transmitted to the high-security network, the electronic signature system decrypts Enc(S) to obtain the document data S. The public key KeyD2 representing the low-security network electronic signature system is used to verify S1 and compare it with the S data to determine whether the seal data is valid. If it is valid, it means that the S data is credible.
[0068] Therefore, this application uses a one-way network gate to achieve one-way transmission of signature data and key data, enabling mutual recognition and interoperability of electronic signatures across networks with different security levels while ensuring the confidentiality requirements of each network. One-way network gate encrypted transmission is implemented using a symmetric encryption algorithm and an adaptive encryption strategy, resulting in faster transmission speeds. Furthermore, the solution adopts a non-invasive design concept, with the core focus on modifying the network gate. This approach has minimal impact on existing electronic signature systems with different security levels, making it easy to implement.
[0069] Exemplary devices
[0070] Figure 4 This is a schematic diagram of the structure of a multi-level cross-network electronic signature device based on a one-way network gateway provided by an exemplary embodiment of the present invention. Figure 4 As shown, the apparatus 400 includes:
[0071] The stamping and signing module 410 is used for the low-level electronic signature system to sign and stamp the document data in the business system with the network user's private key to generate signed electronic seal data. The low-level electronic signature system also uses its private key to electronically sign all data to be transmitted to generate signature data.
[0072] Transmission module 420, used for the low-level electronic signature system to transmit document data, signature electronic seal data, signature data, network user public key KeyD1 and low-level electronic signature system public key KeyD2 to the high-level electronic signature system via a one-way gateway;
[0073] The determination module 430 is configured to determine whether the document data is flowing from a low-level electronic signature system to a high-level electronic signature system. If not, the transmission is terminated. If so, the one-way gatekeeper verifies whether the signature data is valid based on the public key of the low-level electronic signature system. If not, the transmission is terminated.
[0074] Identification and encryption module 440, for, if valid, enabling the one-way gateway to identify sensitive data in the document data and encrypt the data to generate encrypted document data, and transmit the encrypted document data together with the signature electronic seal data to the high-security electronic signature system;
[0075] Publishing and transmission module 450, used for publishing the LDAP module of the one-way network gatekeeper and transmitting the network user public key and the low-level electronic signature system public key to the high-level electronic signature system;
[0076] The verification module 460 is used for the high-level electronic signature system to decrypt the encrypted document data to obtain the document data, and to verify whether the document data is credible based on the low-level electronic signature public key and the signature electronic seal data.
[0077] Optionally, the identification encryption module 440 includes:
[0078] The identification submodule is used for the one-way gateway to automatically identify sensitive data in document data based on natural language processing and regular expressions.
[0079] Optionally, the identification encryption module 440 includes:
[0080] The encryption submodule is used to encrypt document data using the national secret SM4 algorithm to generate encrypted document data. The encryption method uses two negotiations and two encryptions with the low-level electronic signature system, and is securely transmitted in the form of a digital envelope.
[0081] Optionally, after the one-way network gate identifies sensitive data in the document data and encrypts the data to generate encrypted document data, the apparatus 400 further includes:
[0082] The negotiation module is used to negotiate keys between the one-way gateway and the high-security electronic signature system to generate new encryption symmetric keys for data transmission.
[0083] Optionally, the verification module 460 includes:
[0084] The verification submodule is used for the high-level electronic signature system to verify the signature electronic seal data using the public key of the low-level electronic signature system;
[0085] The judgment submodule is used to compare the signature electronic seal data with the decrypted document data when the verification is passed, to determine whether the signature electronic seal data is valid, and if it is valid, the document data is determined to be credible.
[0086] Exemplary electronic devices
[0087] Figure 5 This is the structure of an electronic device provided by an exemplary embodiment of the present invention. Figure 5 As shown, the electronic device 50 includes one or more processors 51 and a memory 52 .
[0088] The processor 51 may be a central processing unit (CPU) or other forms of processing units having data processing capabilities and / or instruction execution capabilities, and may control other components in the electronic device to perform desired functions.
[0089] The memory 52 may include one or more computer program products, which may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. The volatile memory may, for example, include random access memory (RAM) and / or cache memory (cache), etc. The non-volatile memory may, for example, include read-only memory (ROM), a hard disk, a flash memory, etc. One or more computer program instructions may be stored on the computer-readable storage medium, and the processor 51 may execute the program instructions to implement the methods of the software programs of the various embodiments of the present invention described above and / or other desired functions. In one example, the electronic device may further include: an input device 53 and an output device 54, which are interconnected via a bus system and / or other forms of connection mechanisms (not shown).
[0090] In addition, the input device 53 may also include, for example, a keyboard, a mouse, and the like.
[0091] The output device 54 can output various information to the outside. The output device 54 can include, for example, a display, a speaker, a printer, a communication network and a remote output device connected thereto.
[0092] Of course, to simplify, Figure 5Only some of the components related to the present invention in the electronic device are shown, and components such as a bus, an input / output interface, etc. are omitted. In addition, the electronic device may further include any other appropriate components according to specific application conditions.
[0093] Exemplary computer program products and computer-readable storage media
[0094] In addition to the above-mentioned methods and devices, an embodiment of the present invention may also be a computer program product, which includes computer program instructions, which, when executed by a processor, enable the processor to perform the steps of the method according to various embodiments of the present invention described in the above "Exemplary Method" section of this specification.
[0095] The computer program product may be written in any combination of one or more programming languages to implement the operations of embodiments of the present invention, including object-oriented programming languages such as Java, C++, and conventional procedural programming languages such as C or similar programming languages. The program code may be executed entirely on the user's computing device, partially on the user's computing device, as a stand-alone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server.
[0096] In addition, an embodiment of the present invention may also be a computer-readable storage medium having computer program instructions stored thereon, which, when executed by a processor, enable the processor to execute the steps of the method according to various embodiments of the present invention described in the above "Exemplary Method" section of this specification.
[0097] The computer-readable storage medium can adopt any combination of one or more readable media. The readable medium can be a readable signal medium or a readable storage medium. The readable storage medium can, for example, include but is not limited to a system, system or device of electricity, magnetism, light, electromagnetic, infrared, or semiconductor, or any combination thereof. More specific examples (non-exhaustive list) of readable storage media include: an electrical connection with one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof.
[0098] The basic principles of the present invention have been described above in conjunction with specific embodiments. However, it should be noted that the advantages, strengths, and effects mentioned in the present invention are merely illustrative and non-limiting, and should not be construed as necessarily possessed by each embodiment of the present invention. Furthermore, the specific details disclosed above are provided for illustrative purposes and to facilitate understanding, and are not intended to be limiting. These details do not necessarily limit the present invention to being implemented using these specific details.
[0099] Each embodiment in this specification is described in a progressive manner, with each embodiment focusing on its differences from the other embodiments. References to the same or similar parts between the various embodiments are sufficient. For system embodiments, since they largely correspond to method embodiments, their description is relatively simple. For relevant parts, references to the description of the method embodiments are sufficient.
[0100] The block diagrams of the devices, systems, equipment, and systems involved in the present invention are merely illustrative examples and are not intended to require or imply that they must be connected, arranged, or configured in the manner shown in the block diagrams. As will be appreciated by those skilled in the art, these devices, systems, equipment, and systems can be connected, arranged, or configured in any manner. Words such as "including," "comprising," "having," and the like are open-ended words, meaning "including but not limited to," and can be used interchangeably therewith. The words "or" and "and" used herein refer to the words "and / or" and can be used interchangeably therewith, unless the context clearly indicates otherwise. The word "such as" used herein refers to the phrase "such as but not limited to," and can be used interchangeably therewith.
[0101] The method and system of the present invention may be implemented in many ways. For example, the method and system of the present invention may be implemented by software, hardware, firmware, or any combination of software, hardware, and firmware. The above sequence of steps for the method is for illustration only, and the steps of the method of the present invention are not limited to the sequence specifically described above, unless otherwise specified. In addition, in some embodiments, the present invention may also be implemented as a program recorded in a recording medium, which includes machine-readable instructions for implementing the method according to the present invention. Thus, the present invention also covers recording media that store programs for executing the method according to the present invention.
[0102] It should also be noted that, in the system, device and method of the present invention, each component or each step can be decomposed and / or recombined. These decompositions and / or recombinations should be regarded as equivalent schemes of the present invention. The above description of the disclosed aspects is provided to enable any technician in this field to make or use the present invention. Various modifications to these aspects will be very obvious to those skilled in the art, and the general principles defined here can be applied to other aspects without departing from the scope of the present invention. Therefore, the present invention is not intended to be limited to the aspects shown here, but according to the widest scope consistent with the principles disclosed here and novel features.
[0103] The above description has been provided for the purpose of illustration and description. Furthermore, this description is not intended to limit the embodiments of the present invention to the forms disclosed herein. Although a number of example aspects and embodiments have been discussed above, those skilled in the art will recognize certain variations, modifications, alterations, additions, and sub-combinations thereof.
Claims
1. A multi-level cross-network electronic signature method based on a one-way gateway, characterized in that: include: The low-level electronic signature system uses the network user's private key to sign the document data in the business system and affix an electronic signature to generate signed electronic seal data. The low-level electronic signature system also uses its private key to electronically sign all data to be transmitted to generate signature data. The low-level electronic signature system transmits the document data, the signature electronic seal data, the signature data, the network user public key KeyD1 and the low-level electronic signature system public key KeyD2 to the high-level electronic signature system via a one-way network gateway; The one-way network gate determines whether the document data is flowing from a low-level electronic signature system to a high-level electronic signature system. If not, the transmission is terminated. If so, the one-way network gate verifies whether the signature data is valid based on the public key of the low-level electronic signature system. If not, the transmission is terminated. If valid, the one-way network gatekeeper identifies the sensitive data in the document data and encrypts the data to generate encrypted document data, and transmits the encrypted document data together with the signature electronic seal data to the high-security electronic signature system; The LDAP module of the one-way network gate publishes and transmits the network user public key and the low-level electronic signature system public key to the high-level electronic signature system; The high-level electronic signature system decrypts the encrypted document data to obtain the document data, and verifies whether the document data is credible based on the public key of the low-level electronic signature system and the signature electronic seal data.
2. The method according to claim 1, characterized in that The one-way network gatekeeper identifies sensitive data in the document data, including: The one-way network gatekeeper automatically identifies sensitive data in the document data based on natural language processing and regular expressions.
3. The method according to claim 1, characterized in that Perform data encryption to generate encrypted document data, including: The document data is encrypted using the national secret SM4 algorithm to generate the encrypted document data, wherein the encryption method adopts two negotiations and two encryptions with the low-level electronic signature system, and is securely transmitted in the form of a digital envelope.
4. The method according to claim 1, wherein After the one-way network gate identifies the sensitive data in the document data and encrypts the data to generate encrypted document data, the method further includes: The one-way gateway performs key negotiation with the high-security electronic signature system to generate a new encryption symmetric key for data transmission.
5. The method according to claim 1, wherein The high-level electronic signature system verifies whether the document data is credible based on the public key of the low-level electronic signature system and the signed electronic seal data, including: The high-level electronic signature system verifies the signed electronic seal data using the public key of the low-level electronic signature system; If the verification is successful, the signature electronic seal data is compared with the decrypted document data to determine whether the signature electronic seal data is valid. If it is valid, the document data is determined to be credible.
6. A multi-level cross-network electronic signature device based on a one-way network gate, characterized in that: include: The stamping and signing module is used for the low-level electronic signature system to sign and stamp the document data in the business system with the network user's private key to generate signed electronic seal data, and the low-level electronic signature system uses its private key to electronically sign all data to be transmitted to generate signature data; A transmission module is used for the low-level electronic signature system to transmit the document data, the signed electronic seal data, the signature data, the network user public key KeyD1 and the low-level electronic signature system public key KeyD2 to the high-level electronic signature system via a one-way network gateway; a judgment module, configured for the one-way gateway to judge whether the document data is flowing from a low-level electronic signature system to a high-level electronic signature system; if not, the transmission is terminated; and if so, the one-way gateway to verify whether the signature data is valid based on the public key of the low-level electronic signature system; if not, the transmission is terminated; an identification and encryption module, configured to, if valid, enable the one-way gateway to identify sensitive data in the document data and encrypt the data to generate encrypted document data, and transmit the encrypted document data together with the signature electronic seal data to the high-security electronic signature system; A publishing and transmission module, used for publishing the LDAP module of the one-way network gatekeeper and transmitting the network user public key and the low-level electronic signature system public key to the high-level electronic signature system; The verification module is used for the high-level electronic signature system to decrypt the encrypted document data to obtain the document data, and to verify whether the document data is credible based on the public key of the low-level electronic signature system and the signature electronic seal data.
7. The device according to claim 6, characterized in that Identify encryption modules, including: The identification submodule is used for the one-way network firewall to automatically identify sensitive data in the document data based on natural language processing and regular expressions.
8. The device according to claim 6, characterized in that Identify encryption modules, including: The encryption submodule is used to encrypt the document data using the national secret SM4 algorithm to generate the encrypted document data, wherein the encryption method adopts two negotiations and two encryptions with the low-level electronic signature system, and is securely transmitted in the form of a digital envelope.
9. A computer-readable storage medium, characterized in that The storage medium stores a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 5 is implemented.
10. An electronic device, characterized in that: The electronic device comprises: processor; a memory for storing instructions executable by the processor; The processor is configured to read the executable instructions from the memory and execute the instructions to implement the method according to any one of claims 1 to 5.
Citation Information
Patent Citations
File transmission method, device and equipment based on gatekeeper
CN111355752A
Security domain communication method and device, electronic equipment and storage medium
CN115277149A