Method and system for realizing electronic signature at mobile equipment end, mobile equipment and medium
The key pairs are generated and split by the mobile device, combined with the server certificate application and secondary authentication, the problem of user identity failure in existing electronic signature technology is solved, and efficient and secure electronic signatures are achieved.
Patent Information
- Application Number
- CN202510225995.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-27
- Publication Date
- 2025-06-03
AI Technical Summary
In the existing electronic signature technology, the user's identity cannot be strictly verified, resulting in frequent forgery, impersonation and theft of electronic signatures, and the usbkey is not easy to carry.
The key pair is generated by the mobile device side, and the private key is split into two parts, and the first private key is retained on the mobile device side, and the second private key is sent to the server for storage with the certificate request. When using electronic signatures, the mobile device needs to feedback the corresponding certificate and private keys on the server, and perform decryption and merging verification.
It effectively solves the problems of forgery, impersonation and tampering, improves the security of electronic signatures, and avoids attackers from obtaining private keys through either end, thereby realizing the operation of electronic seals. At the same time, it saves computing resources, reduces hardware equipment restrictions, and realizes low-cost, high-efficiency and high data security electronic signatures.
Smart Images

Figure CN120090804A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data encryption, and particularly to a method, system, mobile device and medium for implementing electronic signature on a mobile device side. Background Art
[0002] With the development of computer information technology, people use the Internet application platforms more and more in their lives. At the same time, the data sources of each platform system mostly come from users, among which there are a large number of privacy data, and many of these data are crucial. Especially nowadays, with the promotion of paperless office and the support of various high-quality platforms, electronic signature has emerged, enabling the use of signatures or seals on documents through the PC side or mobile terminal.
[0003] In order to avoid the situations of forgery, misappropriation, and theft of electronic signatures of electronic seals, when using an electronic signature to stamp an electronic document, it is particularly important to verify the use of the electronic signature. Currently, the electronic signature mainly stores the public and private keys in the user's usbkey, and the right to use is completely controlled by the holder of the key. However, the user identity is not strictly verified, resulting in the inability to confirm the user identity. As long as the usbkey is held and the PIN code is entered, the signature can be completed, and there is no restriction on the device used, which easily leads to the situations of misappropriation and theft of electronic signatures. In addition, the usbkey is not easy to carry. Summary of the Invention
[0004] To overcome the problems existing in the related technologies, the present disclosure provides a method, system, mobile device and medium for implementing electronic signature on a mobile device side to solve the technical problems in the related technologies.
[0005] One or more embodiments of the present specification provide a method for implementing electronic signature on a mobile device side, including the following steps:
[0006] Certificate generation step: When the user registers, a key pair is generated through the mobile device side, the private key is split to obtain a first private key and a second private key, and they are encrypted respectively; the first private key is retained on the mobile device side, and the P10 request, the second private key and the certificate application subject information are sent to the server, and the server applies for a certificate from the CA certification center and feeds it back to the mobile device side;
[0007] Seal selection step: When the user requests to stamp through the mobile device side, after the user selects the electronic seal, the mobile device side sends a seal use request to the server; and
[0008] Authentication and stamping steps: The server verifies the information according to the stamping request from the client. After successful verification, the certificate and the second private key are fed back to the mobile device. The mobile device decrypts the first private key stored locally and the second private key fed back by the server and restores the parity bits to obtain the complete private key of the certificate. Then the verification is passed, and the requested electronic seal is used to stamp on the signing page.
[0009] Further, the specific steps for splitting the private key to obtain the first private key and the second private key are as follows:
[0010] The private key string is split by parity bits or randomly to obtain the first private key and the second private key respectively.
[0011] Further, when the user requests stamping through the mobile device, the following steps are also executed on the mobile device:
[0012] The user logs in to the electronic seal service system through the subject information.
[0013] The subject information of the user is authenticated again, including face recognition, gesture password or UnionPay card authentication methods selected by the user. After successful authentication, the list of authorized electronic seals is retrieved and displayed. After the user selects the seal to be used, a stamping request is generated and sent to the server.
[0014] Further, the encryption methods for encrypting the first private key and the second private key include Base64, MD5, AES, DES, Rabbit, RC4 or TripleDES algorithms.
[0015] One or more embodiments of this specification provide an electronic signature system implemented on a mobile device, including a mobile device and a server;
[0016] When used for user registration, the mobile device generates a key pair, splits the private key to obtain the first private key and the second private key, and encrypts them respectively. The first private key is retained locally, and the P10 request, the second part of the private key and the certificate application subject information are sent to the server, and the signature certificate returned by the server is saved;
[0017] When the user requests stamping through the mobile device, a stamping request is sent to the server according to the selected electronic seal by the user. According to the certificate and the second private key fed back by the server, the mobile device decrypts the first private key stored locally and the second private key fed back by the server and restores the parity bits to obtain the complete private key of the certificate. Then the verification is passed, and the requested electronic seal is used to stamp on the signing page;
[0018] The server is used to apply for a certificate from the certification center according to the P10 request, the second private key and the certificate application subject information sent by the mobile device. After the application is successful, the server returns the signed certificate to the mobile device; and according to the seal - using request of the user terminal, it verifies the information, and after the verification is passed, the obtained certificate and the second private key are fed back to the mobile device.
[0019] Further, the specific steps for the mobile device to split the private key into two parts are as follows:
[0020] The private key string is split into odd - numbered and even - numbered bits or randomly split to obtain the first private key and the second private key respectively, where the random split means an average split or a non - average split of the private key.
[0021] Further, when the user requests to use the seal through the mobile device, the mobile device also performs the following steps:
[0022] The user logs in to the electronic seal service system through the mobile device using the subject information, and performs secondary authentication on the user's subject information, including face recognition, gesture password or UnionPay card authentication methods selected by the user. After the authentication is passed, the list of authorized electronic seals is retrieved and displayed. After the user selects the seal to be used, a seal - using request is generated and sent to the server.
[0023] Further, the encryption methods for encrypting the first private key and the second private key include Base64, MD5, AES, DES, Rabbit, RC4 or TripleDES algorithms.
[0024] One or more embodiments of this specification provide a mobile device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the electronic signature and seal method of the mobile device end as described in any one of the above.
[0025] One or more embodiments of this specification provide a computer - readable storage medium. The computer - readable storage medium stores a computer program, and when the computer program is executed by a processor, it implements the electronic signature and seal method of the mobile device end as described in any one of the above.
[0026] A method, system, mobile device, and medium for implementing electronic signature on a mobile device provided by the present disclosure have the advantage that a method for protecting user privacy data is implemented. During the certificate generation process, the private key in the generated key pair is split into two parts. One part is stored on the mobile device side, and the other part of the private key is sent to the server for storage along with the certificate request. During the application process for using the electronic seal, the mobile device side needs the server to feedback the corresponding certificate and the other part of the private key, decrypt the other part of the private key, and merge the decrypted part of the private key with the part of the private key stored on the mobile device side to determine whether the private key is correct. If it is correct, the verification is passed. In this way, problems such as forgery, impersonation, and tampering can be effectively solved, and it is difficult for attackers to obtain the private key through either the mobile device side or the server side to implement the operation of the electronic seal. Moreover, in this embodiment method, the private key is disassembled into two parts and stored separately on the user's mobile device side and the server side. Each authentication only needs to confirm the two parts of the private key. This avoids regenerating the key pair and performing authentication during each application process for using the electronic signature as in the prior art, saving computing resources. And this method is not restricted by hardware devices and does not require holding an additional hardware carrier. After installing the application on a PC, mobile device side, etc., it can be used normally. It realizes an electronic signature with low cost, high efficiency, and high data security. BRIEF DESCRIPTION OF THE DRAWINGS
[0027] In order to more clearly illustrate the technical solutions in one or more embodiments of this specification or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments recorded in this specification. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0028] Figure 1 It is a flowchart of a method for implementing electronic signature on a mobile device provided by one or more embodiments of this specification;
[0029] Figure 2 It is an information flowchart of a method for implementing electronic signature on a mobile device provided by one or more embodiments of this specification; and
[0030] Figure 3 It is a schematic block diagram of a system for implementing electronic signature on a mobile device provided by one or more embodiments of this specification. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0031] To enable those skilled in the art to better understand the technical solutions in one or more embodiments of this specification, the following will clearly and completely describe the technical solutions in one or more embodiments of this specification in conjunction with the accompanying drawings in one or more embodiments of this specification. Obviously, the described embodiments are only a part of the embodiments of this specification, rather than all of the embodiments. Based on one or more embodiments of this specification, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0032] The following will make a detailed description of the present invention in conjunction with the specific implementation manners and the accompanying drawings of the specification.
[0033] Method Embodiment
[0034] According to an embodiment of the present invention, a method for implementing an electronic signature on a mobile device is provided. As Figure 1 shown, it is a flowchart of the method for implementing an electronic signature on a mobile device provided in this embodiment. The method for implementing an electronic signature on a mobile device according to an embodiment of the present invention includes the following steps:
[0035] Step S10, certificate generation step; when a user registers, a key pair is generated through the mobile device, and the private key is split to obtain a first private key and a second private key, which are respectively encrypted. The first private key is retained on the mobile device, and the P10 request, the second private key, and the certificate application subject information are sent to the server. The server applies for a certificate from the certification center. After the application is successful, the server returns the signature certificate to the mobile device.
[0036] In this embodiment, the server applying for a certificate from the CA certification center specifically includes: after receiving the certificate request file from the server, the CA certification center binds the public key with the user's identity information, signs it, and then forms a certificate and sends it back to the server. The server retains the public key certificate and the second private key, and the server feeds back the certificate to the mobile device.
[0037] In this embodiment, after the second private key and the public key are encrypted, a certificate request file is generated and sent to the server.
[0038] Step S11, seal selection step; when the user requests to stamp through the mobile device, after the user selects the electronic seal, the mobile device sends a seal request to the server.
[0039] Step S12, authentication and stamping step; the server verifies the information according to the seal request from the user side. After the verification is passed, the certificate and the second private key are fed back to the mobile device. The mobile device decrypts and restores the parity bits of the stored first private key and the second private key fed back by the server to obtain the complete private key of the certificate, then the authentication is passed, and the requested electronic seal is used to stamp on the signing page.
[0040] In this embodiment, the authentication and verification adopt triple authentication and verification of CA certificate, seal picture, and HASH value.
[0041] The method for implementing electronic signature on the mobile device side provided in this embodiment realizes a method for protecting the privacy data of users. During the certificate generation process, the private key in the generated key pair is split into two parts. One part is stored on the mobile device side, and the other part of the private key is sent to the server for storage along with the certificate request. During the application process for using the electronic seal, the mobile device side needs the server to feedback the corresponding certificate and the other part of the private key, decrypt the other part of the private key, and merge the decrypted part of the private key with the part of the private key stored on the mobile device side to determine whether the private key is correct. If it is correct, the verification is passed. This can not only effectively solve problems such as forgery, impersonation, and tampering, but also make it difficult for attackers to obtain the private key through either the mobile device side or the server side to implement the operation of the electronic seal. Moreover, in this embodiment method, the private key is disassembled into two parts and stored separately on the user's mobile device side and the server side. Each authentication only needs to confirm the two parts of the private key, thus avoiding the need to generate a new key pair and perform authentication during each application process for using the electronic signature as in the prior art, saving computing resources. And this method is not limited by hardware devices and does not require holding an additional hardware carrier (such as a usbkey). After installing the application on a PC, mobile device side, etc., it can be used normally. It realizes an electronic signature with low cost, high efficiency, and high data security.
[0042] In step S10 of this embodiment, splitting the private key into two parts specifically is: splitting the private key string by odd and even bits or randomly, respectively obtaining the first private key and the second private key, where random splitting is to split the private key evenly or unevenly; then encrypting the first private key and the second private key respectively through an encryption algorithm, and sending the encrypted second private key and the public key to the server to apply for a certificate.
[0043] In this embodiment, the private key is a randomly generated string not exceeding a preset length. By using the odd and even bit identifiers, the position of a single character in the string in the entire string is split into two strings, obtaining the odd-bit string and the even-bit string. In this embodiment, splitting by odd and even bits makes the data more secure.
[0044] In step S12 of this embodiment, when the user requests to stamp through the mobile device side, the following steps are also executed on the mobile device side:
[0045] Step S121, the user logs in to the electronic seal service system through the subject information; in this embodiment, the user can log in through the app on the mobile device side or scan the code on the mobile device side to log in to the PC side, and the subject information may include information such as account and password.
[0046] Step S122: Perform secondary authentication on the user's principal information, including authenticating the user's face recognition, gesture password, or UnionPay card authentication method selected by the user. After successful authentication, retrieve and display the list of authorized electronic seals. After the user selects the seal to be used, generate a seal usage request and send it to the server.
[0047] In this embodiment, the two-factor authentication is performed to ensure that each subsequent operation for obtaining private data such as certificates is carried out by the certificate holder himself / herself, thereby ensuring the reliability of information authentication.
[0048] In this embodiment, the encryption algorithm can be selected from Base64, MD5, AES, DES, Rabbit, RC4, or TripleDES algorithms.
[0049] Between step S11 and step S12 of this embodiment, there is also a key confirmation step, which specifically includes the following steps:
[0050] When the user selects an electronic seal, the mobile device needs to determine whether the certificate corresponding to the electronic seal is stored locally. If it is stored, send a seal usage request to the server; if not, jump to step S10 to execute the certificate generation step.
[0051] In a specific embodiment, referring to Figure 2 As shown, it is the specific flowchart of the mobile device implementing electronic signature in this embodiment. Taking the process of implementing electronic signature authentication by splitting the private key by parity bits as an example, this embodiment illustrates the process of the mobile device implementing electronic signature. However, the splitting method of the private key is not limited to splitting by parity bits, and other methods can also be used as long as the private key can be split into two parts to implement this embodiment. Therefore, the mobile device implementing electronic signature specifically includes the following steps:
[0052] Step A1: The user logs in with the principal information, determines the list of electronic seals handled or authorized by the corresponding principal, and the user selects the corresponding signature method according to the document to be signed. Among them, the signature methods include personal signature and electronic seal stamping;
[0053] Step A2: The mobile terminal initiates real-person authentication (secondary authentication) for the user. After successful authentication, determine whether the mobile terminal stores a certificate. If not, go to step A3; otherwise, go to step A5.
[0054] Step A3: The mobile device generates a corresponding key pair, splits the private key into two parts and encrypts them separately. The first private key is retained on the mobile device, and the P10 request, the second private key, and the certificate application principal information are sent to the server.
[0055] Step A4: The server applies for a certificate from the CA certification center. After successful application, the server returns the signed certificate to the mobile device and goes to step A2.
[0056] Step A5: The mobile device sends a seal - using request to the server, where the seal - using request includes information such as real - person authentication information and the unique device identifier.
[0057] Step A6: The server performs CA authentication based on the information in the user - side seal - using request. After successful authentication, the server feeds back the certificate and the second private key to the mobile device.
[0058] Step A7: The mobile device decrypts the second private key fed back by the server, stores the decrypted second private key, restores the parity bits of the first private key stored on the mobile device, determines whether the private key is correct. If so, it passes the CA verification and stamps or signs personally with the requested electronic seal on the signing page.
[0059] Device Embodiment
[0060] According to an embodiment of the present invention, there is provided an electronic seal - signing system implemented on a mobile device. As Figure 3 shown, it is a block diagram of the electronic seal - signing system implemented on the mobile device provided in this embodiment. The electronic seal - signing system implemented on the mobile device according to the embodiment of the present invention includes a mobile device and a server.
[0061] When used for user registration, the mobile device generates a key pair, splits the private key to obtain the first private key and the second private key, encrypts them respectively. The first private key is retained locally, and the P10 request, the second part of the private key, and the certificate application subject information are sent to the server, and the signature certificate returned by the server is saved.
[0062] When the user requests to stamp through the mobile device, after selecting the electronic seal, the mobile device sends a seal - using request to the server. According to the certificate and the second private key fed back by the server, the mobile device decrypts and restores the parity bits of the first private key stored and the second private key fed back by the server to obtain the complete private key of the certificate. Then, the verification passes, and the requested electronic seal is used to stamp on the signing page.
[0063] The server is used to apply for a certificate from the certification center according to the P10 request, the second private key, and the certificate application subject information sent by the mobile device. After successful application, the server returns the signature certificate to the mobile device; and according to the user - side seal - using request, it performs information verification, and after successful verification, feeds back the obtained certificate and the second private key to the mobile device.
[0064] The system for implementing electronic signature on the mobile device side provided in this embodiment realizes a method for protecting the privacy data of users. During the certificate generation process, the private key in the generated key pair is split into two parts. One part is stored on the mobile device side, and the other part of the private key is sent to the server for storage along with the certificate request. During the application process for using the electronic seal, the mobile device side needs the server to feedback the corresponding certificate and the other part of the private key, decrypt the other part of the private key, and merge the decrypted part of the private key with the part of the private key stored on the mobile device side to determine whether the private key is correct. If it is correct, it passes the CA verification, for example. In this way, it can not only effectively solve problems such as forgery, impersonation, and tampering, but also it is difficult for attackers to obtain the private key through either the mobile device side or the server side to implement the operation of the electronic seal. Moreover, the method in this embodiment disassembles the private key into two parts and stores them separately on the user's mobile device side and the server side. Each authentication only needs to confirm the two parts of the private key, thus avoiding the need to generate a new key pair and perform authentication during each application process for using the electronic signature as in the prior art, saving computing resources. And this method is not restricted by hardware devices and does not require holding an additional hardware carrier. After installing the application on a PC, mobile device side, etc., it can be used normally. It realizes an electronic signature with low cost, high efficiency, and high data security
[0065] In this embodiment, splitting the private key into two parts specifically means: splitting the private key string into odd and even bits or randomly, respectively obtaining the first private key and the second private key, where the random split can be an average split or a non - average split of the private key; then encrypting the first private key and the second private key respectively through an encryption algorithm, and after encryption, sending the second private key and the public key to the server to apply for a certificate
[0066] When the user requests to seal with the mobile device side in this embodiment, the mobile device side also performs the following steps
[0067] The user logs in to the electronic seal service system using the subject information through the mobile device side, performs secondary authentication on the user's subject information, including selecting face recognition, gesture password, or UnionPay card authentication method according to the user's independent choice. After passing the authentication, the list of authorized electronic seals is retrieved and displayed, and after the user selects the seal to be used, a seal - using request is generated and sent to the server
[0068] In this embodiment, the user can log in through the app on the mobile device side or scan the code on the mobile device side to log in to the PC side, and the subject information can include information such as account and password
[0069] In this embodiment, the encryption algorithm can select Base64, MD5, AES, DES, Rabbit, RC4, and TripleDES algorithms
[0070] In this embodiment, when the user requests to seal with the mobile device side, the mobile device side also performs a key confirmation step, specifically
[0071] When the electronic seal selected by the user is selected, the mobile device needs to determine whether a certificate is stored locally. If it is stored, a seal-using request is sent to the server; if not, the certificate generation step is executed.
[0072] The embodiments of the present invention are system embodiments corresponding to the above method embodiments. The specific operations of each terminal processing step can be understood with reference to the description of the method embodiments and will not be elaborated here.
[0073] The present invention also provides a mobile device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the method for implementing electronic signature on the mobile device side in the above embodiments is realized.
[0074] The present invention also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the method for implementing electronic signature on the mobile device side in the above embodiments is realized, or when the computer program is executed by a processor, the method for implementing electronic signature on the mobile device side in the above embodiments is realized.
[0075] Those of ordinary skill in the art can understand that all or part of the processes of implementing the methods in the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the method embodiments as described above. Among them, any reference to a memory, storage, database, or other medium used in the embodiments provided in the present application can include non-volatile and / or volatile memories. Non-volatile memories can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memories can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink) DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.
[0076] Each embodiment in this specification is described in a progressive manner. For the same or similar parts among the embodiments, reference can be made to each other, and the key point of each embodiment is to illustrate the differences from other embodiments. In particular, for the device or system embodiments, since they are basically similar to the method embodiments, the description is relatively simple. For the relevant parts, reference can be made to the corresponding descriptions in the method embodiments. The device and system embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement it without creative efforts.
[0077] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or equivalently replace some or all of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of the present invention, and the content not described in detail in this specification of the present invention belongs to the well-known technology of those skilled in the art.
Claims
1. A method for implementing electronic signature on a mobile device, characterized in that The following steps are involved: Certificate generation steps: When a user registers, a key pair is generated through the mobile device, the private key is split to obtain the first private key and the second private key, and they are encrypted separately; the first private key is retained on the mobile device, the P10 request, the second private key and the certificate application subject information are sent to the server, and the server applies for a certificate from the CA certification center and feeds back to the mobile device; Seal selection step: when the user requests a seal through the mobile device, the mobile device sends a seal request to the server according to the electronic seal selected by the user; and Authentication and stamping steps: The server verifies the information based on the user's request for a seal, and after the verification is passed, the certificate and the second private key are fed back to the mobile device. The mobile device decrypts and restores the parity bits of the stored first private key and the second private key fed back by the server to obtain the complete private key of the certificate. If the verification is passed, the signature page is stamped with the requested electronic seal.
2. The method for implementing electronic signature on a mobile device as claimed in claim 1, characterized in that: The step of splitting the private key to obtain the first private key and the second private key is as follows: The private key character string is split by odd-even bits or randomly split to obtain the first private key and the second private key respectively.
3. The method for implementing electronic signature on a mobile device as claimed in claim 1, characterized in that: When the user requests a stamp through a mobile device, the mobile device also performs the following steps: The user logs into the electronic seal service system through the subject information; The user's principal information is authenticated twice, including face recognition, gesture password or UnionPay card authentication methods selected by the user. After the authentication is passed, the list of authorized electronic seals is called up and displayed. After the user selects the seal to be used, a seal request is generated and sent to the server.
4. The method for implementing electronic signature on a mobile device as claimed in claim 1, characterized in that: The encryption method for encrypting the first private key and the second private key includes Base64, MD5, AES, DES, Rabbit, RC4 or TripleDES algorithm.
5. A mobile device implements an electronic signature system, characterized in that: Including mobile device side and server side; When the mobile device is used for user registration, a key pair is generated, and the private key is split to obtain the first private key and the second private key, and they are encrypted separately. The first private key is retained locally, and the P10 request, the second part of the private key and the certificate application subject information are sent to the server, and the server returns the signed certificate for storage; When the user requests a seal through a mobile device, the user sends a seal request to the server according to the electronic seal selected by the user, and according to the certificate and the second private key fed back by the server, the mobile device decrypts and restores the parity bits of the stored first private key and the second private key fed back by the server to obtain the complete private key of the certificate. If the verification is passed, the signature page is stamped with the requested electronic seal; The server is used to apply for a certificate from the certification center based on the P10 request, the second private key and the certificate application subject information sent by the mobile device. After the application is successful, the server returns the signed certificate to the mobile device; and performs information verification based on the user's seal request. After the verification is passed, the certificate and the second private key obtained are fed back to the mobile device.
6. The electronic signature system implemented on a mobile device as claimed in claim 5, characterized in that: The specific steps of splitting the private key into two parts on the mobile device are as follows: The private key character string is split by odd and even bits or randomly split to obtain a first private key and a second private key respectively, wherein the random splitting includes even splitting or uneven splitting of the private key.
7. The electronic signature system implemented on a mobile device as claimed in claim 5, characterized in that: When the user requests a stamp through a mobile device, the mobile device further performs the following steps: The user logs in to the electronic seal service system using the subject information on the mobile device and performs a secondary authentication of the user's subject information, including facial recognition, gesture password or UnionPay card authentication methods selected by the user. After the authentication is passed, the list of authorized electronic seals is called up and displayed. The user selects the seal to be used and a seal request is generated and sent to the server.
8. The electronic signature system implemented on a mobile device as claimed in claim 5, characterized in that: The encryption method for encrypting the first private key and the second private key includes Base64, MD5, AES, DES, Rabbit, RC4 or TripleDES algorithm.
9. A mobile device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the method for implementing an electronic signature on a mobile device as described in any one of claims 1 to 4 is implemented.
10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the method for implementing an electronic signature on a mobile device as described in any one of claims 1 to 4 is implemented.