Large file signing technology method and equipment based on edge computing electronic signature system

Through the collaboration model between the edge computing electronic signature system and the cloud electronic signature system, the large file signing task is transferred to the edge computing node, solving various problems in the traditional cloud system in the process of signing large files, and achieving efficient and low-cost electronic signature of large files.

CN118944898BActive Publication Date: 2025-05-13GUANGDONG ELECTRONIC CERTIFICATION AUTHORITY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411343559.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-09-25
Publication Date
2025-05-13
Estimated Expiration
2044-09-25

AI Technical Summary

Technical Problem

Traditional single-center cloud systems face problems in network transmission bottlenecks, storage and processing pressures, poor user experience, and cost and efficiency during the signing of large documents.

Method used

Adopting an edge computing-based strategy, through the edge computing electronic signature system and the cloud electronic signature system, the large file signing task is transferred to the edge computing node on the user side to perform, thereby reducing the burden on the cloud system.

Benefits of technology

It realizes efficient electronic signature of large files, reduces data transmission time, saves network bandwidth, improves user experience, and reduces operating costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118944898B_ABST
    Figure CN118944898B_ABST
Patent Text Reader

Abstract

The present invention discloses a large file signing technical method based on an edge computing electronic signature system, including the following steps: applying to create a two-way collaborative electronic signature protocol channel; an application requiring an electronic signature initiates the signing of an electronic file; the application determines whether the provided electronic file needs to be signed using edge computing; the edge computing electronic signature system receives the electronic file; an application is applied to create an edge computing signing service in a cloud electronic signature system; the cloud electronic signature system completes the creation of the edge computing service according to the requirements of the edge computing electronic signature system, and performs related processing for the signing of the electronic file; completes the signature preprocessing of the file and provides a signature summary; digitally signs the signature summary to generate a digital signature result; and performs signature synthesis on the electronic file. The present invention transfers the large file signing task in the cloud to the edge computing node on the user side for execution, thereby reducing the burden on the cloud system in terms of bandwidth, memory, storage, and computing.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of electronic signatures, and in particular to a large file signing technical method and device based on an edge computing electronic signature system. Background Art

[0002] With the in-depth development of digital transformation in various industries, the application of large electronic files is becoming more and more widespread. These files are usually huge in data volume, up to hundreds of megabytes or even gigabytes, and are commonly seen in business scenarios such as high-definition scans, high-definition engineering drawings, and multi-file collections. In order to ensure the integrity and legal validity of these documents, electronic signatures have become an indispensable part.

[0003] However, signing large documents directly in a traditional single-center cloud system faces many challenges:

[0004] (1) Network transmission bottleneck: The transmission of large files is limited by network bandwidth and latency. Especially in cross-border or cross-region situations, the transmission time is too long, affecting business efficiency.

[0005] (2) Storage and processing pressure: Large files increase storage costs, and processing these files (such as previewing, editing, and signing) requires higher-performance computing resources, otherwise the system response will be slow;

[0006] (3) Poor user experience: Long file loading time leads to poor user experience, especially on mobile devices or in low-bandwidth environments. The complex signing process may also cause users to give up halfway;

[0007] (4) Cost and efficiency issues: High network fees, storage costs, and inefficient file processing processes increase the operating costs of enterprises;

[0008] In order to solve these problems, the present invention proposes a large file signing technical method and equipment based on an edge computing electronic signature system, and designs a collaborative mode combining edge computing and cloud electronic signature systems. This mode transfers the large file signing task on the cloud to the edge computing node on the user side for execution, thereby reducing the burden on the cloud system in terms of bandwidth, memory, storage, and computing, and realizing efficient large file electronic signatures. Summary of the invention

[0009] The main purpose of the present invention is to provide a technical method and device for signing large files based on an edge computing electronic signature system. It adopts an edge computing-based strategy and proposes a way of collaborating between an edge computing electronic signature system and a cloud electronic signature system to solve the following problems in the large file signing process: network delay problem, limited bandwidth resource problem, business collaboration problem, data security problem, and improve the scalability of the cloud signing system, thereby solving the technical problems raised in the background technology.

[0010] The present invention adopts the following technical solutions to solve the above technical problems:

[0011] The large file signing technical method based on the edge computing electronic signature system is implemented based on the cloud electronic signature system and the edge computing electronic signature system, including the following specific operation steps:

[0012] S1. Register with the cloud electronic signature system based on the edge computing electronic signature system and apply to create a two-way collaborative electronic signature agreement channel;

[0013] S2. Applications that require electronic signatures initiate electronic document signing through the SDK;

[0014] S3. The SDK detection application determines whether the provided electronic document needs to be signed using edge computing;

[0015] S4. The edge computing electronic signature system receives the electronic file from the SDK;

[0016] S5. The edge computing electronic signature system sends a request to the cloud electronic signature system to apply for creating an edge computing signing service in the cloud electronic signature system;

[0017] S6. The cloud electronic signature system completes the creation of the edge computing business according to the requirements of the edge computing electronic signature system. At this time, the electronic file is saved in the edge computing electronic signature system and will not be sent to the cloud electronic signature system. If the signing process requires user participation, jump to the subsequent S7 step. If the signing process does not require user participation, jump to the subsequent S10 step.

[0018] S7. For the signing process that requires user participation, the cloud electronic signature system provides the user with an interactive signing interface;

[0019] S8. During the operation, when the user needs to view the content of the file, the cloud electronic signature system sends instructions to the edge computing electronic signature system, and the edge computing service generates a rendering result for the user to view;

[0020] S9. During the operation, the cloud electronic signature system records the user's electronic document operation behavior and forms an electronic document signing instruction. Through the two-way collaborative electronic signature protocol, the electronic document signing related processing is performed, and then jumps to the subsequent S11 step;

[0021] S10. For the signing process that does not require user participation, the edge computing electronic signature system and the cloud electronic signature system perform electronic document signing related processing through a two-way collaborative electronic signature protocol, and then execute the subsequent S11 step;

[0022] S11. The cloud electronic signature system sends an electronic signature preprocessing instruction, and the edge computing electronic signature system completes the signature preprocessing of the file and provides the cloud electronic signature system with a signature summary;

[0023] S12. The cloud electronic signature system provides the user with a signature summary of the electronic document, and the user or other application system digitally signs the signature summary to generate a digital signature result;

[0024] S13. The cloud-based electronic signature system sends the digital signature result to the edge computing electronic signature system, which then performs the final signature synthesis processing on the electronic file and finally completes the electronic file signature.

[0025] Preferably, the specific method for determining whether the electronic file needs to be signed by edge computing in step S3 includes:

[0026] S31. Determine whether the file size is greater than 50MB. If so, sign it using edge computing;

[0027] S32. Determine whether the application specifies the mandatory use of edge computing when calling the interface. If edge computing signature is used, forward the file to the edge computing electronic signature system deployed locally in the application or in the same local area network.

[0028] Preferably, the transmission in the two-way collaborative electronic signature protocol channel in step S1 adopts a two-way collaborative electronic signature protocol data packet structure, and the data message of the data packet structure includes, in byte sequence, the following:

[0029] Protocol header, length 10 bytes;

[0030] Version number and type, length 1 byte;

[0031] Random number, length 8 bytes;

[0032] Message identifier, length 8 bytes;

[0033] Timestamp, length 8 bytes;

[0034] The length of the compressed encrypted data message is 8 bytes.

[0035] Preferably, the portion of the data message starting from the 35th byte to the data length is set as the data packet actually transmitted.

[0036] Preferably, the data message needs to be compressed and restored during the sending and receiving process in the transmission process, specifically including:

[0037] Before sending the data message, the MessagePack algorithm is used to compress the message instruction first, and then the SM4 symmetric encryption algorithm is used to encrypt it. The Deflate algorithm is used to compress the ciphertext twice, and the compressed data is sent when sending.

[0038] The party receiving the data message uses the reverse process of the sender to perform the following steps on the secondary compressed data: Deflate decompression, SM4 decryption, and MessagePack decompression to restore the original data.

[0039] Preferably, the two-way collaborative electronic signature protocol in step S9 and step S10 is provided with a layered model consisting of a business layer, an instruction layer, a compression layer, an encryption layer, and a network layer, and the layered model includes, from bottom to top:

[0040] The business layer is used to initiate business processing requests and complete business processing. It generates electronic signature collaborative processing requests based on the electronic signature application scenario.

[0041] The instruction layer is used for the compilation and parsing of electronic signature collaborative processing requests, and compiles the requests into instructions according to the business requirements between the cloud electronic signature system and the edge computing electronic signature system;

[0042] The compression layer is used for message compression to reduce the bandwidth occupied during instruction transmission and increase the speed of information transmission;

[0043] The encryption layer is used to convert compression instructions into encryption and decryption information to form an abstract encrypted transmission channel to ensure the confidentiality of information transmission;

[0044] The network layer is set as the model framework basis of the layered model, and is used to send the encrypted message to the receiver or to receive the encrypted message sent by the sender as the receiver.

[0045] Preferably, the processing flow of sending a message to a recipient in the hierarchical model includes:

[0046] a1. At the business layer, generate an electronic signature business processing request;

[0047] a2. At the instruction layer, convert the electronic signature business processing request into a transmittable electronic signature instruction data message;

[0048] a3. In the compression layer, data messages are compressed to improve information transmission efficiency;

[0049] a4. At the encryption layer, the compressed data is encrypted to ensure data confidentiality;

[0050] a5. Use the network layer to send information requests.

[0051] Preferably, the processing flow of receiving an encrypted message sent by a sender in the hierarchical model includes:

[0052] b1. Use the network layer to receive the request sent;

[0053] b2. In the encryption layer, the requested data message is decrypted to obtain compressed data;

[0054] b3. In the compression layer, the compressed data is decompressed and restored to the command data message;

[0055] b4. At the instruction layer, complete the parsing of the instruction data message and generate a business request;

[0056] b5. At the business layer, complete business processing according to business requests.

[0057] On the other hand, the present invention also discloses a large file signing technology device based on an edge computing electronic signature system, which is used to execute any of the large file signing technology methods based on an edge computing electronic signature system described above, including a cloud electronic signature system and an edge computing electronic signature system, wherein the cloud electronic signature system or data center can collaborate with multiple distributed edge computing electronic signature system nodes to process services, and is used to provide private edge electronic signature service access to multiple different customers;

[0058] The cloud-based electronic signature system and the edge computing electronic signature system serve as the center and node of the system framework respectively. Data flows bidirectionally between the center and the nodes. The edge node is used to send key information back to the center, and the center is used to push updates or instructions to the edge.

[0059] Preferably, during use of the device:

[0060] The cloud electronic signature system is triggered by the application or user. During the electronic signature process, the cloud electronic signature system is used to communicate in both directions in the form of signature business instructions through a two-way collaborative electronic signature protocol:

[0061] When edge computing is needed, the cloud-based electronic signature system sends instructions to the edge computing electronic signature system to complete the corresponding business processing;

[0062] When cloud business processing is required, the edge computing electronic signature system sends instructions to the cloud electronic signature system to complete the corresponding business processing;

[0063] In the process of information exchange, attribute information related to the file signing business is merged into the signature instruction in the form of attributes or parameters, and then the instruction is compressed and encrypted as a whole for package transmission through the two-way collaborative electronic signature protocol;

[0064] When the user needs to view the content of the electronically signed file, the cloud-based electronic signature system sends a rendering instruction for the file page content to the edge computing electronic signature system through a two-way collaborative electronic signature protocol, renders the file content page using edge computing, provides the cloud-based electronic signature system with the rendering content result, and the cloud-based electronic signature system displays the content to the user.

[0065] On the other hand, the present invention further discloses a computer-readable storage medium storing a computer program, wherein when the computer program is executed by a processor, the processor executes the steps of the above method.

[0066] On the other hand, the present invention further discloses a computer device, including a memory and a processor, wherein the memory stores a computer program, and when the computer program is executed by the processor, the processor executes the steps of the above method.

[0067] It can be seen from the above technical solution that the present invention provides a large file signing technical method and device based on edge computing electronic signature system. Compared with the prior art, the present invention has the following advantages:

[0068] 1. By setting up an edge computing electronic signature system, the present invention can reduce the time required for data transmission to a remote data center and complete the signing of large electronic files without affecting the operation of the cloud electronic signature service. The file data does not need to be sent to the cloud service, thus solving the sensitive data security problem in the prior art.

[0069] 2. The electronic document signing of the present invention is completed by the edge computing electronic signature system. Not all data needs to be sent to the cloud for processing. Only necessary data will be transmitted. This can save network bandwidth and solve the problem of bandwidth occupation for large electronic document signing in the cloud.

[0070] 3. The method of the present invention supports the user, cloud center, and edge computing node, and the three parties work together to complete the signing of electronic documents. The private key is always kept by the user, ensuring that the digital signature is reliable, effective and cannot be forged, thereby ensuring the security of operations and data.

[0071] 4. The device of the present invention integrates the dual processing capabilities of cloud and edge computing, and realizes unified processing and secure transmission of signature instructions by adopting the flexible architecture of "one center and multiple nodes" and single center and single node, combined with an efficient two-way intercommunication protocol. Compared with the traditional secure electronic signature system, the present invention optimizes the data processing process and can disperse the load of cloud electronic signature services, avoiding overload of a single data center, thereby supporting larger-scale service deployment.

[0072] 5. The device of the present invention integrates edge computing devices and cloud platforms in system design, which can realize local encryption processing of data to be signed, effectively reduce the computing burden of the cloud, and improve the response speed. At the same time, because the edge computing device first encrypts the data and then transmits it to the cloud platform through a secure channel for further decryption and signing operations, this process ensures the confidentiality of the data during transmission and processing.

[0073] It should be understood that the content described in this section is not intended to identify the key or important features of the embodiments of the present invention, nor is it intended to limit the scope of the present invention. Other features of the present invention will become easy to understand through the following description. Of course, it is not necessary to achieve all of the advantages described above simultaneously for any product implementing the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0074] The drawings constituting a part of the present application are used to provide a further understanding of the present invention. The exemplary embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation of the present invention. In the drawings:

[0075] Figure 1 This is a flow chart of large file signing based on the edge computing electronic signature system of the present invention;

[0076] Figure 2 A schematic diagram of the structure of a two-way collaborative electronic signature protocol data packet of the present invention;

[0077] Figure 3 It is a schematic diagram of the hierarchical framework of the two-way collaborative electronic signature protocol of the present invention;

[0078] Figure 4 It is a flow chart of the data transmission process of the two-way collaborative electronic signature protocol of the present invention;

[0079] Figure 5 This is a flow chart of the collaborative electronic signature protocol data receiving process of the present invention. DETAILED DESCRIPTION

[0080] The technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, rather than all of the embodiments. In the absence of conflict, the embodiments in this application and the features in the embodiments can be combined with each other. Based on the embodiments in the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention.

[0081] In the embodiment, see Figures 1 to 5 .

[0082] like Figure 1As shown, the large file signing technical method based on the edge computing electronic signature system proposed in the embodiment of the present invention is implemented based on the cloud electronic signature system and the edge computing electronic signature system. It mainly adopts the edge computing-based strategy and proposes the use of the edge computing electronic signature system and the cloud electronic signature system to collaborate to solve the problems of network delay, limited bandwidth resources, business collaboration, data security and improve the scalability of the cloud signing system in the process of signing large files. The large files here include: PDF, OFD, WORD, EXCEL, PPT, WPS, JPG, PNG and other types of electronic files that can provide file content display.

[0083] The method specifically includes the following steps:

[0084] S1. Register with the cloud electronic signature system based on the edge computing electronic signature system and apply to create a two-way collaborative electronic signature agreement channel;

[0085] S2. Applications that require electronic signatures initiate electronic document signing through the SDK;

[0086] S3. The SDK detection application determines whether the provided electronic file needs to be signed using edge computing. The specific determination method for determining whether the electronic file needs to be signed using edge computing includes:

[0087] S31. Determine whether the file size is greater than 50MB. If so, sign it using edge computing;

[0088] S32. Determine whether the application specifies the mandatory edge computing method when calling the interface. If edge computing is used for signing, forward the file to the edge computing electronic signature system deployed locally or in the same local area network of the application;

[0089] S4. The edge computing electronic signature system receives the electronic file from the SDK;

[0090] It should be noted here that, in addition to using SDK to initiate electronic document signing to the cloud electronic signature system, applications that require electronic signatures can also directly call the API provided by the cloud electronic signature system to initiate electronic document signing;

[0091] S5. The edge computing electronic signature system sends a request to the cloud electronic signature system to apply for creating an edge computing signing service in the cloud electronic signature system;

[0092] S6. The cloud electronic signature system completes the creation of the edge computing business according to the requirements of the edge computing electronic signature system. At this time, the electronic file is saved in the edge computing electronic signature system and will not be sent to the cloud electronic signature system. If the signing process requires user participation, jump to the subsequent S7 step. If the signing process does not require user participation, jump to the subsequent S10 step.

[0093] At this time, the edge computing electronic signature system can reduce the time required for data transmission to the remote data center and complete the signing of large electronic documents without affecting the operation of the cloud electronic signature service. The file data does not need to be sent to the cloud service, solving the sensitive data security problem in the existing technology. In addition, the electronic document signing is completed by the edge computing electronic signature system. Not all data needs to be sent to the cloud for processing. Only necessary data will be transmitted, which can save network bandwidth and solve the problem of bandwidth occupation for large electronic document signing in the cloud.

[0094] S7. For the signing process that requires user participation, the cloud electronic signature system provides the user with an interactive signing interface;

[0095] S8. During the operation, when the user needs to view the content of the file, the cloud electronic signature system sends instructions to the edge computing electronic signature system, and the edge computing service generates a rendering result for the user to view;

[0096] S9. During the operation, the cloud electronic signature system records the user's electronic document operation behavior and forms an electronic document signing instruction. Through the two-way collaborative electronic signature protocol, the electronic document signing related processing is performed, and then jumps to the subsequent S11 step;

[0097] S10. For the signing process that does not require user participation, the edge computing electronic signature system and the cloud electronic signature system perform electronic document signing related processing through a two-way collaborative electronic signature protocol, and then execute the subsequent S11 step;

[0098] S11. The cloud electronic signature system sends an electronic signature preprocessing instruction, and the edge computing electronic signature system completes the signature preprocessing of the file and provides the cloud electronic signature system with a signature summary;

[0099] S12. The cloud electronic signature system provides the user with a signature summary of the electronic document, and the user or other application system digitally signs the signature summary to generate a digital signature result;

[0100] S13. The cloud-based electronic signature system sends the digital signature result to the edge computing electronic signature system, which then performs the final signature synthesis processing on the electronic file and finally completes the electronic file signature.

[0101] It should be noted that in addition to being applicable to cloud-based signing of large files, the business process of this method is also applicable to scenarios where there are high requirements for the confidentiality of electronic files and the original electronic files cannot be sent to the cloud-based electronic signature system, but it is necessary to allow users to use the cloud-based electronic signature system for interface interaction, content viewing, and file signing.

[0102] This method is based on the interaction between the cloud-based electronic signature system and the electronic signature service system based on edge computing. It mainly exchanges information through a two-way collaborative electronic signature protocol. The method supports users, cloud centers, and edge computing nodes to complete the signing of electronic documents through three-party linkage. The private key is always kept by the user to ensure that the digital signature is reliable, valid and cannot be forged.

[0103] At the same time, for application scenarios that need to process a large number of concurrent requests, the edge computing electronic signature system can disperse the load of the cloud electronic signature service, avoid overloading a single data center, and thus support larger-scale service deployment.

[0104] At this point, it can be further explained that the transmission within the two-way collaborative electronic signature protocol channel adopts the two-way collaborative electronic signature protocol data packet structure, such as Figure 2 As shown, the data message of the data packet structure includes, in byte sequence, the following:

[0105] Protocol header, length 10 bytes;

[0106] Version number and type, length 1 byte;

[0107] Random number, length 8 bytes;

[0108] Message identifier, length 8 bytes;

[0109] Timestamp, length 8 bytes;

[0110] The length of the compressed encrypted data message is 8 bytes.

[0111] The portion of the data message starting from the 35th byte to the data length is set as the data packet actually transmitted.

[0112] In addition, data packets need to be compressed and restored during the transmission process, including:

[0113] Before sending the data message, the MessagePack algorithm is used to compress the message instruction first, and then the SM4 symmetric encryption algorithm is used to encrypt it. The Deflate algorithm is used to compress the ciphertext twice, and the compressed data is sent when sending.

[0114] The party receiving the data message uses the reverse process of the sender to perform the following steps on the secondary compressed data: Deflate decompression, SM4 decryption, and MessagePack decompression to restore the original data.

[0115] In summary, the protocol has the characteristics of full-duplex, full encryption, and high efficiency. It is designed specifically for electronic signature collaborative processing. The following advantages exist when using this protocol to send messages: (1) Privacy and security. All information is encrypted and transmitted using the national secret standard algorithm; (2) Stability and reliability. The protocol is based on the repackaging of the TCP protocol to ensure reliable delivery of information; (3) Fast information transmission speed. All data is losslessly compressed using the MessagePack and Deflate algorithms before sending; (4) Modularity. The protocol adopts a layered processing strategy for sending and receiving. Each processing step is independently isolated according to the layer; (5) Two-way intercommunication enables closer collaboration between the cloud-based electronic signature system and the edge computing electronic signature system.

[0116] In addition, in a specific embodiment, it is also necessary to explain that the two-way collaborative electronic signature protocol in step S9 and step S10 is provided with a layered model consisting of a business layer, an instruction layer, a compression layer, an encryption layer, and a network layer. Figure 3 As shown, the hierarchical model includes from bottom to top:

[0117] The business layer is used to initiate business processing requests and complete business processing. It generates electronic signature collaborative processing requests based on the electronic signature application scenario.

[0118] The instruction layer is used for the compilation and parsing of electronic signature collaborative processing requests, and compiles the requests into instructions according to the business requirements between the cloud electronic signature system and the edge computing electronic signature system;

[0119] The compression layer is used for message compression to reduce the bandwidth occupied during instruction transmission and increase the speed of information transmission;

[0120] The encryption layer is used to convert compression instructions into encryption and decryption information to form an abstract encrypted transmission channel to ensure the confidentiality of information transmission;

[0121] The network layer is set as the model framework basis of the layered model, which is used to send the encrypted message to the receiver or as the receiver to receive the encrypted message sent by the sender;

[0122] For further reference, Figure 4 In the specific hierarchical model, the process of sending a message to the receiver includes:

[0123] a1. At the business layer, generate an electronic signature business processing request;

[0124] a2. At the instruction layer, convert the electronic signature business processing request into a transmittable electronic signature instruction data message;

[0125] a3. In the compression layer, data messages are compressed to improve information transmission efficiency;

[0126] a4. At the encryption layer, the compressed data is encrypted to ensure data confidentiality;

[0127] a5. Use the network layer to send information requests;

[0128] For further reference, Figure 5 , in the specific hierarchical model, the processing flow of receiving the encrypted message sent by the sender includes:

[0129] b1. Use the network layer to receive the request sent;

[0130] b2. In the encryption layer, the requested data message is decrypted to obtain compressed data;

[0131] b3. In the compression layer, the compressed data is decompressed and restored to the command data message;

[0132] b4. At the instruction layer, complete the parsing of the instruction data message and generate a business request;

[0133] b5. At the business layer, complete business processing according to business requests

[0134] In addition, it should be noted that in addition to electronic signatures, the collaborative processing of this method can also be used for various types of electronic signature business processing based on cryptographic technology. At this time, since it is also compatible with electronic signature instructions in addition to electronic signature instructions, electronic signature operation information such as signature data structure, signature appearance, signature positioning and other information are sent through instructions, which can support the completion of electronic document signature processing.

[0135] When performing electronic signatures, the cloud electronic signature system and the edge computing electronic signature system interact using electronic signature instructions; when performing electronic seal processing, electronic signature instructions are used for interaction.

[0136] In addition, it should be noted that the cloud-based electronic signature system mentioned in this method can be deployed not only in the cloud, but also in private cloud, hybrid cloud, stand-alone deployment and other deployment methods. The deployment area can be in a public cloud, private cloud, virtual machine or physical server device.

[0137] In addition, it should be noted that all relevant business data in the signing process are uniformly encapsulated using business instructions, and the transmission of business instructions is pre-processed by compression, encryption, and re-compression.

[0138] On the other hand, the present invention also discloses a large file signing technology device based on an edge computing electronic signature system, which is used to execute the large file signing technology method based on an edge computing electronic signature system of the above embodiment, including a cloud electronic signature system and an edge computing electronic signature system. The cloud electronic signature system and the edge computing electronic signature system adopt a "one center and multiple nodes" architecture, that is, a cloud electronic signature system or data center can collaborate with multiple distributed edge computing electronic signature system nodes to process business, and is used to provide private edge electronic signature service access to multiple different customers. This structure makes the system highly available and fault-tolerant. Even if a node fails, other nodes can still continue to work.

[0139] It should be noted at this point that the cloud-based electronic signature system and the edge computing electronic signature system also support a single-center, single-node approach.

[0140] The cloud-based electronic signature system and the edge computing electronic signature system serve as the center and node of the system framework respectively. Data flows bidirectionally between the center and the nodes. The edge nodes are used to send key information back to the center, and the center is used to push updates or instructions to the edge.

[0141] Therefore, by integrating the dual processing capabilities of cloud computing and edge computing in the electronic signature system, and adopting the flexible architecture of "one center and multiple nodes" and single center and single node, combined with an efficient two-way intercommunication protocol, the unified processing and secure transmission of signature instructions and seal instructions are achieved. Compared with the traditional secure electronic signature system, the present invention is not only compatible with electronic signature and electronic seal operations, but also optimizes the data processing process.

[0142] Specifically, the present invention can realize local encryption processing of the data to be signed by integrating edge computing devices and cloud platforms in system design, effectively reducing the computing burden of the cloud and improving the response speed. The edge computing device first encrypts the data, and then transmits it to the cloud platform through a secure channel for further decryption and signing operations. This process ensures the confidentiality of the data during transmission and processing.

[0143] It should be noted at this point that

[0144] At this point in the use of the device:

[0145] The cloud electronic signature system is triggered by the application or user. During the electronic signature process, the cloud electronic signature system is used to communicate in two directions in the form of signature business instructions through a two-way collaborative electronic signature protocol. In addition to supporting full-duplex communication, the two-way communication protocol also supports collaborative interaction in the form of request response, such as polling operations based on the HTTP protocol:

[0146] When edge computing is needed, the cloud electronic signature system sends instructions to the edge computing electronic signature system to complete corresponding business processing such as content rendering, synthesis of data to be signed, synthesis of file signature results, and file signature verification;

[0147] When cloud business processing is required, the edge computing electronic signature system sends instructions to the cloud electronic signature system to complete corresponding business processing such as signature business creation, query, modification, deletion, and signature verification result synchronization;

[0148] In the process of information exchange, attribute information related to the file signature business, such as signature summary, signature coordinates, signature appearance, signature verification results, etc., are all merged into the signature instruction in the form of attributes or parameters, and then the instruction is compressed and encrypted as a whole through the two-way collaborative electronic signature protocol for package transmission;

[0149] When the user needs to view the content of the electronically signed file, the cloud-based electronic signature system sends rendering instructions for the file page content to the edge computing electronic signature system through a two-way collaborative electronic signature protocol, uses edge computing to render the file content page, and provides the cloud-based electronic signature system with rendering content results, which then displays the content to the user.

[0150] In summary, this method and system equipment can achieve the following effects: (1) By adding a data encryption link to the edge computing device, it can play a preliminary protective role, effectively resist potential threats in network transmission, and improve data security; (2) The collaborative working mode of the cloud and the edge realizes efficient resource utilization and load balancing, greatly improves the processing efficiency and response time of the overall system, and makes the electronic signature process faster and smoother; (3) The system equipment ensures the stable operation and wide applicability of the system in different scenarios through flexible architecture design and comprehensive communication protocol support, ultimately achieving the effect of improving user experience and business processing capabilities, and promoting the widespread application and deep integration of electronic signature technology in multiple fields.

[0151] On the other hand, the present invention further discloses a computer-readable storage medium storing a computer program, wherein when the computer program is executed by a processor, the processor executes the steps of the above method.

[0152] On the other hand, the present invention further discloses a computer device, including a memory and a processor, wherein the memory stores a computer program, and when the computer program is executed by the processor, the processor executes the steps of the above method.

[0153] In another embodiment provided in the present application, a computer program product containing instructions is also provided. When the computer is run on a computer, the computer executes any of the large file signing technical methods based on the edge computing electronic signature system in the above embodiments.

[0154] It is understandable that the system provided by the embodiment of the present invention corresponds to the method provided by the embodiment of the present invention, and the explanation, examples and beneficial effects of the relevant contents can refer to the corresponding parts in the above method.

[0155] The embodiment of the present application also provides an electronic device, including a processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface and the memory communicate with each other through the communication bus.

[0156] Memory, used to store computer programs;

[0157] The processor is used to implement the above-mentioned large file signing technical method based on the edge computing electronic signature system when executing the program stored in the memory.

[0158] The communication bus mentioned in the above electronic device can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. The communication bus can be divided into an address bus, a data bus, a control bus, etc.

[0159] The communication interface is used for communication between the above electronic device and other devices.

[0160] The memory may include a random access memory (RAM) or a non-volatile memory (NVM), such as at least one disk memory. Optionally, the memory may also be at least one storage device located away from the aforementioned processor.

[0161] The above-mentioned processor can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, and discrete hardware components.

[0162] It should also be noted that electronic devices also include terminal devices, which can also be called terminals, user equipment (UE), mobile stations (MS), mobile terminals (MT), etc. Terminal devices can be mobile phones, smart TVs, wearable devices, tablet computers (Pad), computers with wireless transceiver functions, virtual reality (VR) terminal devices, augmented reality (AR) terminal devices, wireless terminals in industrial control, wireless terminals in self-driving, wireless terminals in remote medical surgery, wireless terminals in smart grids, wireless terminals in transportation safety, wireless terminals in smart cities, wireless terminals in smart homes, etc. The embodiments of the present application do not limit the specific technology and specific device form adopted by the terminal devices.

[0163] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions may be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium, for example, the computer instructions may be transmitted from a website site, computer, server or data center by wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) mode to another website site, computer, server or data center. The computer-readable storage medium may be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more available media integrated. The available medium may be a magnetic medium, (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state drive Solid State Disk (SSD)), etc.

[0164] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principle of the present invention should be included in the protection scope of the present invention.

[0165] In addition, it should be noted that if the embodiments of the present invention involve directional indications (such as up, down, left, right, front, back, etc.), the directional indications are only used to explain the relative position relationship, movement status, etc. between the components in a certain specific posture. If the specific posture changes, the directional indication will also change accordingly.

[0166] In addition, if there are descriptions involving "first", "second", etc. in the embodiments of the present invention, the descriptions of "first", "second", etc. are only used for descriptive purposes and cannot be understood as indicating or implying their relative importance or implicitly indicating the number of technical features indicated. Therefore, the features defined as "first" and "second" may explicitly or implicitly include at least one of the features. In addition, the meaning of "and / or" appearing in the full text includes three parallel schemes. Taking "A and / or B" as an example, it includes scheme A, or scheme B, or schemes that A and B meet at the same time. In addition, in the embodiments of the present invention, "multiple" refers to more than two. In addition, the technical solutions between the various embodiments can be combined with each other, but it must be based on the ability of ordinary technicians in the field to implement. When the combination of technical solutions is contradictory or cannot be implemented, it should be considered that such a combination of technical solutions does not exist and is not within the scope of protection required by the present invention.

Claims

1. A large file signing technology method based on an edge computing electronic signature system is implemented based on a cloud electronic signature system and an edge computing electronic signature system, and is characterized by: include: S1. The edge computing electronic signature system registers with the cloud electronic signature system and applies to create a two-way collaborative electronic signature agreement channel; S2. Applications that require electronic signatures initiate electronic document signing through the SDK; S3.SDK determines whether the electronic document needs to be signed using edge computing; S4. The edge computing electronic signature system receives the electronic file from the SDK; S5. The edge computing electronic signature system sends a request to the cloud electronic signature system to apply for creating an edge computing signing service in the cloud electronic signature system; S6. The cloud electronic signature system completes the creation of the edge computing signing business. At this time, the electronic file is saved in the edge computing electronic signature system and will not be sent to the cloud electronic signature system. The signing process requires user participation and jumps to step S7. The signing process does not require user participation and jumps to step S10; S7. The cloud electronic signature system provides users with an interactive interface for signing; S8. When the user needs to view the content of the file, the cloud electronic signature system sends instructions to the edge computing electronic signature system, and the edge computing signing service generates a rendering result for the user to view; S9. The cloud electronic signature system records the user's electronic document operation behavior and forms an electronic document signing instruction. Through the two-way collaborative electronic signature protocol, the electronic document signing related processing is performed, and then jumps to step S11; S10. The edge computing electronic signature system and the cloud electronic signature system perform electronic document signing related processing through a two-way collaborative electronic signature protocol, and then execute step S11; S11. The cloud electronic signature system sends an electronic signature preprocessing instruction, and the edge computing electronic signature system completes the signature preprocessing of the file and provides the signature summary to the cloud electronic signature system; S12. The cloud electronic signature system provides the user with a signature summary of the electronic document, which is digitally signed by the user to generate a digital signature result; S13. The cloud electronic signature system sends the digital signature result to the edge computing electronic signature system, which synthesizes the electronic document signature and finally completes the electronic document signature.

2. The large file signing technology method based on edge computing electronic signature system as claimed in claim 1 is characterized in that: The specific method for determining whether the electronic file needs to be signed by edge computing in step S3 includes: S31. Determine whether the file size is greater than 50MB. If so, use edge computing to sign. S32. Determine whether the application specifies the mandatory use of edge computing when calling the interface. If edge computing signature is used, forward the file to the edge computing electronic signature system deployed locally in the application or in the same local area network.

3. The large file signing technology method based on edge computing electronic signature system as claimed in claim 1 is characterized in that: The transmission in the two-way collaborative electronic signature protocol channel in step S1 adopts a two-way collaborative electronic signature protocol data packet structure, and the data message of the data packet structure includes, in byte sequence, the following: Protocol header, length 10 bytes; Version number and type, length 1 byte; Random number, length 8 bytes; Message identifier, length 8 bytes; Timestamp, length 8 bytes; The length of the compressed encrypted data message is 8 bytes.

4. The large file signing technology method based on edge computing electronic signature system as claimed in claim 3 is characterized in that: The portion of the data message starting from the 35th byte to the data length is set as the data packet actually transmitted.

5. The large file signing technology method based on edge computing electronic signature system as claimed in claim 4 is characterized in that: The data message needs to be compressed and restored during the transmission process, including: Before sending the data message, the MessagePack algorithm is used to compress the message instruction first, and then the SM4 symmetric encryption algorithm is used to encrypt it. The Deflate algorithm is used to compress the ciphertext twice, and the compressed data is sent when sending. The party receiving the data message uses the reverse process of the sender to perform the following steps on the secondary compressed data: Deflate decompression, SM4 decryption, and MessagePack decompression to restore the original data.

6. The large file signing technology method based on edge computing electronic signature system as claimed in claim 1 is characterized in that: The two-way collaborative electronic signature protocol in step S9 and step S10 is provided with a layered model consisting of a business layer, an instruction layer, a compression layer, an encryption layer, and a network layer. The layered model includes, from bottom to top: The business layer is used to initiate business processing requests and complete business processing. It generates electronic signature collaborative processing requests based on the electronic signature application scenario. The instruction layer is used for the compilation and parsing of electronic signature collaborative processing requests, and compiles the requests into instructions according to the business requirements between the cloud electronic signature system and the edge computing electronic signature system; The compression layer is used for message compression to reduce the bandwidth occupied during instruction transmission and increase the speed of information transmission; The encryption layer is used to convert compression instructions into encryption and decryption information to form an abstract encrypted transmission channel to ensure the confidentiality of information transmission; The network layer is set as the model framework basis of the layered model, and is used to send the encrypted message to the receiver or to receive the encrypted message sent by the sender as the receiver.

7. The large file signing technology method based on edge computing electronic signature system as claimed in claim 6 is characterized in that: The process of sending a message to a recipient in the hierarchical model includes: a1. At the business layer, generate an electronic signature business processing request; a2. At the instruction layer, convert the electronic signature business processing request into a transmittable electronic signature instruction data message; a3. In the compression layer, data messages are compressed to improve information transmission efficiency; a4. At the encryption layer, the compressed data is encrypted to ensure data confidentiality; a5. Use the network layer to send information requests.

8. The large file signing technology method based on edge computing electronic signature system as claimed in claim 6 is characterized in that: The processing flow of receiving an encrypted message sent by a sender in the hierarchical model includes: b1. Use the network layer to receive the request sent; b2. In the encryption layer, the requested data message is decrypted to obtain compressed data; b3. In the compression layer, the compressed data is decompressed and restored to the command data message; b4. At the instruction layer, complete the parsing of the instruction data message and generate a business request; b5. At the business layer, complete business processing according to business requests.

9. An electronic signature system, characterized in that: A large file signing technical method based on an edge computing electronic signature system for executing any one of claims 1 to 8 above, comprising a cloud electronic signature system and an edge computing electronic signature system, wherein the cloud electronic signature system or data center can collaborate with multiple distributed edge computing electronic signature system nodes to process services, and is used to provide private edge electronic signature service access to multiple different customers; The cloud-based electronic signature system and the edge computing electronic signature system serve as the center and node of the system framework respectively. Data flows bidirectionally between the center and the nodes. The edge node is used to send key information back to the center, and the center is used to push updates or instructions to the edge.

10. The electronic signature system according to claim 9, characterized in that: During use: The cloud electronic signature system is triggered by the application or user. During the electronic signature process, the cloud electronic signature system is used to communicate in both directions in the form of signature business instructions through a two-way collaborative electronic signature protocol: When edge computing is needed, the cloud-based electronic signature system sends instructions to the edge computing electronic signature system to complete the corresponding business processing; When cloud business processing is required, the edge computing electronic signature system sends instructions to the cloud electronic signature system to complete the corresponding business processing; In the process of information exchange, attribute information related to the file signature business is merged into the signature instruction in the form of attributes or parameters, and then the instruction is compressed and encrypted as a whole for package transmission through the two-way collaborative electronic signature protocol; When the user needs to view the content of the electronically signed file, the cloud-based electronic signature system sends a rendering instruction for the file page content to the edge computing electronic signature system through a two-way collaborative electronic signature protocol. The edge computing electronic signature system uses edge computing to render the file page content and provides the cloud-based electronic signature system with the rendering content result, which then displays the content to the user.

Citation Information

Patent Citations

  • Multi-thread local signing method, system and device based on WASM and medium

    CN116346808A

  • Electronic bidding document processing method and device, electronic equipment and storage medium

    CN118611920A