Handwritten signature method based on collaborative signature technology

By adopting SM2 single-time collaborative signature technology and natural handwritten signature method in electronic signature technology, the problems of cumbersome and key security risks in the existing technology are solved, and a convenient and high-security electronic signature solution is achieved, which complies with national standards.

CN120124112AActive Publication Date: 2025-06-10杭州脉讯科技有限公司
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
CN202510231122.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-28
Publication Date
2025-06-10
Estimated Expiration
2045-02-28

AI Technical Summary

Technical Problem

The existing electronic signature technology has cumbersome operation and key security risks in the high-frequency and scenario-based signature requirements, and has failed to meet the requirements of the national cryptographic specifications and GM/T 0031-2014 standards.

Method used

The handwritten signature method based on SM2 single-time collaborative signature technology is adopted. Through the collaborative signature between the client and the server, combined with the natural handwritten signature method, an electronic signature that meets the standards is generated to ensure that the key is used in a single interaction and is destroyed in a timely manner.

Benefits of technology

It realizes the convenience of high-frequency and scenario-based signatures and high-key security, complies with national cryptographic specifications and relevant standards, and reduces the risk of key theft.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120124112A_ABST
    Figure CN120124112A_ABST
Patent Text Reader

Abstract

The invention discloses a handwritten signature method based on a collaborative signature technology. The handwritten signature method comprises the following steps: S1, collecting identity information and biological characteristics of a user through a client; s2, the client initializes a random number generator, generates a collaborative signature key component d1 of the client SM2 and a public key negotiation parameter P1, and sends the collaborative signature key component d1 and the public key negotiation parameter P1 to the server; s3, the server generates a server SM2 collaborative signature key component d2, negotiates with the client public key negotiation parameter P1 to generate a public key P, and applies for an event certificate from a certificate issuing mechanism; s4, the server generates an electronic seal based on the handwritten signature track picture, and assembles to-be-electronically-signed data in combination with the to-be-signed original text, the timestamp and the event certificate; s5, the server side and the client side complete SM2 collaborative signature of the data to be electronically signed through single interaction, a signature value is generated, and the electronic signature data is assembled; and S6, the client and the server destroy the generated data. The method has better operation convenience and higher key security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of communication security technology, and particularly relates to a handwritten signature method based on collaborative signature technology. Background Art

[0002] With the rapid development of e-government and e-commerce, electronic signature technology has become the core technical means to ensure the legal validity of electronic documents. Traditional electronic signature systems mostly adopt digital certificate technology based on PKI. Its implementation usually requires users to pre-generate and store digital certificate private keys on the client side, and complete electronic signatures through local signature algorithms. However, there are certain problems with such solutions: First, digital certificates need to be applied for in advance and managed for a long time, which is cumbersome for high-frequency and scenario-based signature requirements; Second, the local storage of signature private keys poses a security risk of being stolen by malware. In addition, existing handwritten signature solutions have deficiencies in compliance. Some solutions fail to meet the mandatory requirements of GM / T 0031-2014 standard for electronic signature data formats, cryptographic algorithms, and certificate management. The above problems restrict the popularization and application of electronic signature technology in high-security and high-convenience scenarios. There is an urgent need for a new type of electronic signature solution that complies with national cryptographic specifications, has high key security, supports dynamic certificate management, and integrates natural interaction methods. Summary of the Invention

[0003] The purpose of the present invention is to provide a handwritten signature method based on collaborative signature technology. The present invention can effectively solve high-frequency and scenario-based signature requirements. The present invention takes SM2 single-time collaborative signature as the core, combines compliant electronic signatures and natural handwritten signature methods, has better operation convenience and high key security, and complies with national cryptographic specifications.

[0004] The technical solution of the present invention: A handwritten signature method based on collaborative signature technology, including a client and a server, is carried out according to the following steps:

[0005] S1. Collect the user's identity information and biometric features through the client;

[0006] S2. The client initializes the random number generator, generates the client SM2 collaborative signature key component d 1 and the public key negotiation parameter P 1 , and sends them to the server;

[0007] S3. The server generates the server SM2 collaborative signature key component d 2 , negotiates with the client public key negotiation parameter P 1 to generate the public key P, and applies for an event certificate from the certificate authority;

[0008] S4. The server generates an electronic seal based on the handwritten signature trajectory picture, combines the original text to be signed, the timestamp, and the event certificate, and assembles the data to be electronically signed.

[0009] S5. The server and the client complete the SM2 collaborative signature of the data to be electronically signed through a single interaction, generate a signature value, and assemble the electronically signed data.

[0010] S7. The client and the server destroy the generated data.

[0011] In the above-mentioned handwritten signature method based on collaborative signature technology, the user's identity information includes the user's name, ID number, handwritten signature trajectory picture, and mobile phone number; the user's biometric features include face and fingerprint; the biometric features are collected through at least one of the following devices: ID card reader, camera, fingerprint collector, and graphics tablet.

[0012] In the aforementioned handwritten signature method based on collaborative signature technology, all communication processes between the client, the server, and the certificate authority are protected by the TLCP protocol compliant with GB / T 38636-2020.

[0013] In the aforementioned handwritten signature method based on collaborative signature technology, the generation of the SM2 collaborative signature key components in steps S2 and S3 is both based on a software random number generator compliant with GM / T 0105-2021. During the operation of the software random number generator, entropy is continuously accumulated in the entropy pool, and the entropy pool is accumulated from the system entropy source and the hardware random number input obtained from the server.

[0014] In the aforementioned handwritten signature method based on collaborative signature technology, in step S4, the generation of the electronic seal complies with the GM / T0031-2014 standard, including using the handwritten signature trajectory picture as the seal body, embedding the user certificate into the seal information structure, and storing the face and / or fingerprint information through a custom data field.

[0015] In the aforementioned handwritten signature method based on collaborative signature technology, in step S5, the single interaction process of the SM2 collaborative signature includes:

[0016] Using the key component d generated by the client in S2 1 and the public key negotiation parameter P 1 = d 1 -1 *G, calculate Q 1 = k 1 *G, where k 1 ∈[1,n - 1] is a random number generated by the client, and G is the generator in the SM2 algorithm;

[0017] Send P 1 and Q 1and the original text is sent to the server, and the server uses the public key P = d 2 -1 *P 1 -G and the random number k 2 ∈[1, n - 1] to calculate Q 2 = k 2 *G and the preprocessed value e = P_Hash(P, plaintext, UserID), where: P_Hash is the preprocessing function, plaintext is the original text, and UserID is the user ID;

[0018] The server generates a random number k 3 ∈[1, n - 1], and calculates (x 1 , y 1 ) = k 3 *Q 1 +Q 2 and r = (x 1 +e) mod n. If r = 0, then regenerate k 3 Calculate r until r ≠ 0;

[0019] Finally, the server calculates S 2 = (d 2 *k 3 ) mod n, S 3 = (d 2 *(r + k 2 )) mod n, and returns the signature parameters r, S 2 and S 3 to the client;

[0020] The client calculates S according to S 2 and S 3 :

[0021] s = ((d 1 *k 1 )*S 2 +d 1 *S 3 -r) mod n

[0022] If S ≠ 0 and S ≠ n - r, then generate the signature value (r, s).

[0023] In the handwritten signature method based on the collaborative signature technology described above, in step S7, the complete destruction operation of the data includes performing at least 3 alternating overwrites of 0 and 1 on the volatile memory to ensure that the key components and temporary parameters cannot be recovered.

[0024] Compared with the prior art, the present invention has the following beneficial effects:

[0025] 1. Operational convenience: Users do not need to pre-generate keys or make certificates. They can electronically sign data only by handwritten signature, which greatly simplifies the operation process and meets the high-frequency and scenario-based signature requirements.

[0026] 2. Key security: Based on the one-time key principle, the key is only used in a single interaction and is immediately destroyed after use. Moreover, the key-related parameters are stored in volatile memory, effectively reducing the risk of key theft and improving key security.

[0027] 3. Compliance: It strictly follows GM / T 0031-2014 "Technical Specification for Secure Electronic Signature Cryptography" for electronic seal production, data format processing, and certificate management, and GB / T 38636-2020 "Information Security Technology - Transport Layer Cryptographic Protocol" for communication protection to ensure that the entire handwritten signature process complies with national cryptographic specifications. Description of the Drawings

[0028] Figure 1 is the process schematic diagram of the present invention;

[0029] Figure 2 is the schematic diagram of the SM2 collaborative signature process of the present invention. Detailed Embodiments

[0030] The present invention will be further described below in conjunction with the drawings and embodiments, but it shall not be used as a basis for limiting the present invention.

[0031] Embodiment: A handwritten signature method based on collaborative signature technology, as Figure 1 shown, includes a client and a server, and is carried out according to the following steps:

[0032] S1. Collect the user's identity information and biometric features through the client; in this step, the client can collect the user's identity information and biometric features in various ways. Read the name and ID number through an ID card reader, collect a face photo through a camera, collect the user's fingerprint through a fingerprint collector, collect a handwritten signature trajectory picture through a graphics tablet, or collect identity information such as the user's mobile phone number through form filling. This step needs to ensure that the collected information includes the name, ID number, mobile phone number, and signature trajectory picture, and these information will be used to apply for a certificate and make an electronic seal.

[0033] S2. The client initializes the random number generator and generates the client SM2 collaborative signature key component d 1 and the public key negotiation parameter P 1, and send it to the server; In this step, to ensure the security of the key, the client embeds a software random number generator (RNG). The random number generator is designed to meet the RNG design based on the SM3 algorithm in GM / T 0105-2021 "Design Guide for Software Random Number Generators". During the operation of the RNG, entropy needs to be continuously accumulated in the entropy pool, and the entropy pool is accumulated from the system entropy source and the hardware random numbers obtained from the server. Only after the RNG is initialized can relevant cryptographic operations be performed. If the initialization fails, all subsequent processes will be terminated. The client uses the RNG to generate the client SM2 collaborative signature key component d 1 ∈[1,n - 1], calculate P 1 =d 1 -1 *G as the SM2 collaborative signature client request parameter, the client generates a random number k 1 ∈[1,n - 1], calculate Q 1 =k 1 *G, and send P 1 , Q 1 the original text to be signed, user identity information, and biometric features to the server;

[0034] S3. The server generates the server SM2 collaborative signature key component d 2 , and negotiates the parameter P 1 with the client's public key to generate the public key P, and applies for an event certificate from the certificate authority; In this step, after the server receives P 1 sent by the client, it generates a random number d 2 ∈[1,n - 1] through the hardware random number generator in the device, and uses d 2 as the server SM2 collaborative signature key component, and negotiates the parameter P 1 with the client's public key to generate the public key P:

[0035] P = d 2 -1 *P 1 -G;

[0036] Subsequently, the server uses the public key P and user identity information to apply for an event certificate from the certificate authority CA;

[0037] S4. The server generates an electronic seal based on the handwritten signature trace picture, combines the original text to be signed, the timestamp and the event certificate, and assembles the data to be electronically signed; in this step, the server uses the handwritten signature trace picture as the seal picture according to GM / T 0031-2014 "Security Electronic Seal Cryptography Technical Specification", puts the user event certificate into the corresponding structure of the seal information (SES_SealInfo), sets the seal validity period to be the same as the certificate validity period. If information such as face and fingerprint is carried and these information are not in the same picture as the signature trace picture, then these information will be stored in the seal information in the form of custom data (ExtensionDatas), and the seal information structure will be signed by the seal maker to generate the electronic seal (SESeal).

[0038] S5. The server and the client complete the SM2 collaborative signature of the data to be electronically signed through a single interaction, generate a signature value, and assemble the electronically signed data;

[0039] In this step, for the preparation of the electronic seal and the data to be signed, the server needs to calculate the SM3 hash value of the original text to be signed as the original text hash value, generate a timestamp through the timestamp server, and assemble information such as the electronic seal, the original text hash value, the timestamp, and the event certificate into the data to be electronically signed (TBS_Sign). Note that the generation process of TBS_Sign should meet the requirements of the electronic seal generation process in Section 6.2.2 of GM / T0031-2014 "Security Electronic Seal Cryptography Technical Specification"; after TBS_Sign is generated, start the SM2 single collaborative signature of the electronic seal. As Figure 2 shown, it includes the following steps:

[0040] Step 1. Use the key component d 1 generated by the client in S2 1 and the public key negotiation parameter P 1 -1 = d 1 *G to calculate Q 1 = k 1 *G, where k

[0041] ∈[1,n - 1] is a random number generated by the client again, and G is the generator in the SM2 algorithm; 1 Step 2. Send P 1 , Q 2 -1 and the original text to the server. The server uses the public key P = d 1 *P 2 - G and the random number k 2 = k 2*G and the pre - processed value e = P_Hash(P, plaintext, UserID), where: P_Hash is the pre - processing function, plaintext is the original text, and UserID is the user ID;

[0042] The server generates a random number k 3 ∈[1, n - 1], calculate (x 1 , y 1 ) = k 3 *Q 1 +Q 2 and r = (x 1 +e) mod n. If r = 0, regenerate k 3 Calculate r until r≠0;

[0043] Finally, the server calculates S 2 =(d 2 *k 3 ) mod n, S 3 =(d 2 *(r + k 2 )) mod n. Return the signature parameters r, S 2 and S 3 to the client;

[0044] Step 3: The client calculates S according to S 2 and S 3 :

[0045] s = ((d 1 *k 1 )*S 2 +d 1 *S 3 -r) mod n

[0046] If S≠0 and S≠n - r, generate the signature value (r, s).

[0047] After generating the signature value, form the electronic signature data according to the electronic signature data format and return the electronic signature data to the caller;

[0048] In this step, the SM2 algorithm is based on the elliptic curve equation y 2 =x 3 +ax + b over a finite field. The base point G (generator), curve parameter n, curve parameters a, b are defined in Part 5: Parameter Definitions of GM / T 0003 - 2012 "SM2 Elliptic Curve Public - Key Cryptography Algorithm".

[0049] Points on the elliptic curve over a finite field are represented by (x, y) or capital letters. For example, (x 1 , y 1)、P, Q; The k - fold point operation of point P on the elliptic curve can be expressed as k*P, that is k is a positive integer.

[0050] The SM2 signature algorithm needs to pre - process the original text. P_Hash is the pre - processing function, and the implementation is as follows: Let x||y be the concatenation of x and y, H 256 () is the SM3 cryptographic hash function with a message length of 256 bits, the original text to be processed is M, the user's public key is P A 、The user A has a distinguishable identifier ID with a length of entlen A bits, denoted as ENTL A which is two bytes converted from the integer entlen A . Convert the data types of the coordinates x A 、y G of the elliptic curve equation parameters a, b, G, and the coordinates x G 、y A of the public key P A 、y A to bit strings (the conversion method can be found in GM / T 0003), and calculate Z A = H 256 (ENTLEN A ||ID A ||a||b||x G ||y G ||x A ||y A ); e is the pre - processed value.

[0051] S6. The client and the server destroy the generated data. In this step, the content destroyed by the server includes d 2 、k 2 、k 3 、e, r, S 2 、S 3 and TBS_Sign; The data destroyed by the client includes d 1 、k 1 、r, S 2 、S 3 and TBS_Sign. Among them, the client and the server adopt the same data - destruction process, and the destruction method is to repeatedly overwrite 0 and 1 on the volatile memory storing the relevant data more than 3 times in an alternating manner to prevent recovery.

[0052] The following combines specific scenarios to elaborate in detail on the handwritten signature - seal method based on the collaborative signature technology of the present invention.

[0053] Suppose an employee of an enterprise needs to affix a handwritten signature seal to an electronic contract. First, the employee uses the equipment within the enterprise to read their name and ID number with an ID card reader, capture a face photo through a camera, place their finger on a fingerprint collector to collect fingerprints, write their signature on a digital tablet to obtain a picture of the handwritten signature trajectory, and fill in their mobile phone number in the form. These information are input into the client.

[0054] After receiving this information, the client inputs the original text of the electronic contract to be signed and initializes the random number generator. The random number generator operates according to the GM / T 0105-2021 standard, accumulates entropy to the entropy pool, which is accumulated by the system entropy source and the hardware random numbers obtained from the server. After initialization, the client generates the client SM2 collaborative signature key component d 1 , calculates P 1 = d 1 -1 * G, generates a random number k 1 ∈ [1, n - 1] and calculates Q 1 = k 1 * G, and sends P 1 , Q 1 , the original text of the electronic contract, the employee's identity information, and biometric features to the server.

[0055] After receiving the data, the server generates the server SM2 collaborative signature key component d 2 through the hardware random number generator, and calculates the negotiated public key P according to the client parameters. Then, the server uses the public key and the employee's identity information to apply for an event certificate from the CA. According to the GM / T 0031-2014 standard, the picture of the employee's handwritten signature trajectory is made into an electronic seal, the certificate is placed in the seal information structure, and the seal validity period is set to be the same as the certificate validity period. The server calculates the SM3 hash value of the original text of the electronic contract, obtains the timestamp, and assembles the electronic seal, the original text hash value, the timestamp, the event certificate, etc. into the data to be electronically signed (TBS_Sign). The server performs SM2 signature preprocessing on TBS_Sign to generate e, and then generates random numbers k 2 ∈ [1, n - 1] and k 3 ∈ [1, n - 1], calculates r, S 2 and S 3 , returns these parameters and the TBS_Sign structure to the client, and at the same time destroys the relevant keys and data generated during this operation on the server.

[0056] After receiving the parameters returned by the server, the client performs a single SM2 collaborative signature, calculates s = ((d 1 * k 1 ) * S 2 + d 1 * S3 (r) mod n. If S ≠ 0 and S ≠ n - r, a signature value (r, s) is generated, and an electronic signature data is formed according to the electronic signature data format and returned to the caller (such as the contract management system of an enterprise). Subsequently, the client also destroys the relevant keys and data generated during this operation.

[0057] Through the above steps, the enterprise employee has successfully completed the handwritten signature on the electronic contract, and the whole process is safe, convenient and compliant with relevant standards and specifications.

[0058] In summary, the present invention can effectively solve the signature requirements of high frequency and scenarios. The present invention takes the SM2 single - time collaborative signature as the core, combines the standard - compliant electronic signature and the natural handwritten signature method, has better operation convenience and higher key security, and complies with the national cryptography specifications.

Claims

1. A handwritten signature method based on collaborative signature technology, including a client and a server, characterized in that: Follow these steps: S1. Collect the user's identity information and biometrics through the client; S2. The client initializes the random number generator, generates the client SM2 collaborative signature key component d1 and the public key negotiation parameter P1, and sends them to the server; S3. The server generates the server SM2 collaborative signature key component d2, negotiates with the client public key negotiation parameter P1 to generate the public key P, and applies for an event certificate from the certificate authority; S4. The server generates an electronic seal based on the handwritten signature trajectory image, and assembles the data to be electronically signed by combining the original text to be signed, the timestamp and the event certificate; S5. The server and the client complete the SM2 collaborative signature of the data to be electronically signed through a single interaction, generate a signature value, and assemble the electronic signature data; S6. The client and the server destroy the generated data.

2. The handwritten signature method based on collaborative signature technology according to claim 1 is characterized in that: The user's identity information includes the user's name, ID number, handwritten signature trajectory image and mobile phone number; the user's biometric features include face and fingerprint; the biometric feature collection is completed through at least one of the following devices: ID card reader, camera, fingerprint collector, handwriting tablet.

3. The handwritten signature method based on collaborative signature technology according to claim 2 is characterized in that: All communication processes between the client, server, and certificate authority are protected by the TLCP protocol that complies with GB / T 38636-2020.

4. The handwritten signature method based on collaborative signature technology according to claim 2 is characterized in that: The generation of the SM2 collaborative signature key component in step S2 and step S3 is based on a software random number generator that complies with GM / T 0105-2021. The software random number generator continuously accumulates entropy into the entropy pool during operation. The entropy pool is accumulated by the system entropy source and the hardware random number input obtained from the server.

5. The handwritten signature method based on collaborative signature technology according to claim 1 is characterized in that: In step S4, the generation of the electronic seal complies with the GM / T 0031-2014 standard, including using the handwritten signature trajectory image as the seal body, embedding the user certificate into the seal information structure, and storing the face and / or fingerprint information through the custom data field.

6. The handwritten signature method based on collaborative signature technology according to claim 1 is characterized in that: In step S5, the single interaction process of SM2 collaborative signature includes: Use the key component d1 generated by the client in S2 and the public key to negotiate the parameter P1=d1 -1 *G, calculate Q1 = k1 * G, where k1∈[1,n-1] is the random number generated by the client and G is the generator in the SM2 algorithm; Send P1, Q1 and the original text to the server, which uses the public key P = d2 -1 *P1-G and random number k2∈[1,n-1] calculate Q2=k2*G and preprocessing value e=P_Hash(P,plaintext,UserID), where: P_Hash is the preprocessing function, plaintext is the original text, and UserID is the user ID; The server generates a random number k3∈[1,n-1], calculates (x1,y1)=k3*Q1+Q2 and r=(x1+e)modn, and if r=0, regenerates k3 and calculates r until r≠0; Finally, the server calculates S2 = (d2*k3) mod n, S3 = (d2*(r+k2)) mod n, and returns the signature parameters r, S2 and S3 to the client; The client calculates S based on S2 and S3: s=((d1*k1)*S2+d1*S3-r)modn If S≠0 and S≠nr, a signature value (r,s) is generated.

7. The handwritten signature method based on collaborative signature technology according to claim 1 is characterized in that: In step S6, the complete destruction of data includes alternating overwriting 0 and 1 in the volatile memory at least three times to ensure that the key components and temporary parameters are irrecoverable.

Citation Information

Patent Citations

  • SM2 algorithm collaborative signature and decryption method, device and system

    CN109672539A

  • Electronic document signing method based on electronic notarization and SM2 collaborative signature and server adopted by electronic document signing method

    CN111817857A

  • Mobile terminal PDF (Portable Document Format) electronic signature method and system based on key collaborative signature

    CN114338035A

  • SM2 collaborative signature method, device and system based on homomorphic operation

    CN115037441A

  • Implicit certificate issuing method and system supporting collaborative signature

    CN117544316A