Electronic signature application method, device and system, storage medium and electronic equipment

By randomly storing in a dedicated password device and determining the storage location based on seal information, the problem of difficulty in achieving unified management in traditional electronic seal system is solved, and efficient and trustworthy electronic seal service is achieved.

CN120162833AActive Publication Date: 2025-06-17BEIJING BIG DATA CENT
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510224744.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-27
Publication Date
2025-06-17
Estimated Expiration
2045-02-27

AI Technical Summary

Technical Problem

The traditional electronic seal system adopts the "separate construction and independent application" model, making it difficult to achieve unified management and efficient processing of seals, and cannot meet the increasingly open business needs.

Method used

By randomly storing the private key of the seal in a dedicated password device and determining the storage location based on the seal information, unified management of the seal and efficient seal signature operation are achieved.

Benefits of technology

It realizes independent, secure and flexible storage and unified management of seals, and provides efficient, trustworthy, reliable and scalable electronic signature and seal verification services.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120162833A_ABST
    Figure CN120162833A_ABST
Patent Text Reader

Abstract

The invention relates to the field of electronic signature, and particularly provides an electronic signature application method, device and system, a storage medium and electronic device.The method can comprise the steps that after to-be-signed information of a service system side is obtained, a storage position for storing an electronic seal private key is determined based on seal information in the to-be-signed information; wherein the to-be-signed information comprises a to-be-signed file verification value and seal information, the to-be-signed file verification value is obtained by calculating a to-be-signed file, the seal information comprises a seal name and a seal number, and the storage position is any one of a plurality of special password devices; acquiring the private key from the storage position, and performing signature operation on the to-be-signed file by using the private key to obtain a signed file; and sending the signed file to the service system side through a front gateway. Some embodiments of the application can flexibly store the private key and provide reliable signature service on the premise of security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of electronic signatures, and in particular to a method, device, system, storage medium and electronic device for electronic signature application. Background Art

[0002] Electronic seal is a form of electronic signature, which uses image processing technology to transform the electronic signature operation into the same visual effect as the paper document stamping operation, and uses electronic signature technology to ensure the authenticity and integrity of electronic information and the non-repudiation of the signatory. With the continuous application of electronic signature technology in various industries, the security of electronic seals in the centralized storage process has become an extremely important part of the electronic signature field.

[0003] Traditional electronic seals adopt the construction mode of "separate construction, independent application". With the complex changes in business handling, this mode is gradually unable to meet the increasingly open business needs. In the current business handling process, there is an urgent need to achieve mutual trust and recognition of electronic seals and unified management of electronic seals. However, the current construction mode of "separate construction, independent application" advocates the decentralized construction of electronic seal systems, which cannot achieve unified management of seals, and thus cannot achieve efficient handling of signature business.

[0004] Therefore, how to provide a technical solution for a method of electronic signature application that can be uniformly managed and efficient has become a technical problem that needs to be solved urgently. Summary of the invention

[0005] The purpose of some embodiments of the present application is to provide a method, device, system, storage medium and electronic device for electronic signature application. Through the technical solution of the embodiments of the present application, by randomly storing the seal private key in a dedicated cryptographic device, it is possible to achieve independent, secure and flexible storage of the seal private key, realize unified management of the seal, and provide efficient, trustworthy, reliable and scalable electronic signature and verification services for seal users.

[0006] In the first aspect, some embodiments of the present application provide a method for applying an electronic signature, comprising: after obtaining the information to be signed from the business system side, determining the storage location for storing the electronic seal private key based on the seal information in the information to be signed; wherein the information to be signed includes: a verification value of the file to be signed and the seal information, the verification value of the file to be signed is obtained by calculating the file to be signed, the seal information includes a seal name and a seal number, and the storage location is any one of a plurality of dedicated cryptographic devices; obtaining the private key from the storage location, and using the private key to sign the file to be signed to obtain a signed file; and sending the signed file to the business system side through a front-end gateway.

[0007] Some embodiments of the present application determine the storage location of the seal private key through the seal information, and can obtain the private key from the dedicated cryptographic device corresponding to the storage location to sign the document to be signed to obtain the signed document; finally, it is sent to the business system side through the front-end gateway. Some embodiments of the present application determine the storage location of the private key through the seal information, which has high randomness and does not need to directly store the serial number of the device corresponding to the private key, so as to realize the unified management of the seal, thereby improving the security of the private key storage; moreover, the private key and the public key are stored independently, which can also ensure the security of the storage and use of the private key.

[0008] In some embodiments, determining the storage location of the electronic seal private key based on the seal information in the information to be signed includes: calculating the seal information to obtain a calculation result; converting the data at a preset location in the calculation result to obtain the storage location.

[0009] Some embodiments of the present application obtain the calculation result by calculating the seal information and then converting it to obtain the storage location, so as to accurately store the private key. Compared with the solution of directly using the device number to determine the storage location of the private key, it is more secure.

[0010] In some embodiments, the preset position is the last i digits in the calculation result, where i is a positive integer; wherein, converting the data at the preset position in the calculation result to obtain the storage position includes: converting the data corresponding to the last i digits in the calculation result into decimal data to obtain the storage position.

[0011] Some embodiments of the present application set a preset position, perform conversion calculations on the data at the preset position in the calculation result, obtain the storage position, and achieve accurate acquisition of the storage position.

[0012] In some embodiments, before determining the storage location of the electronic seal private key based on the seal information in the information to be signed, the method also includes: receiving the information to be signed sent by the application interface front-end gateway; wherein the application interface front-end gateway sends the information to be signed after verifying the authentication data sent by the signature front-end gateway; wherein the verification value of the file to be signed is obtained by the signature front-end gateway calculating the file to be signed on the business system side.

[0013] Some embodiments of the present application send the information to be signed through an application program interface front-end gateway, wherein the application program interface front-end gateway can also authenticate the signed signature gateway to ensure the security of data transmission and prevent malicious tampering.

[0014] In some embodiments, before obtaining the information to be signed on the business system side, the method also includes: obtaining seal production information of the seal to be stored, wherein the seal production information includes: a mold, a name of the seal to be produced, a number of the seal to be produced, and production information; based on the name of the seal to be produced and the number of the seal to be produced, obtaining the storage location address of the private key of the seal to be stored; storing the private key of the seal to be stored in a private key storage device corresponding to the storage location address, wherein the private key storage device is any one of the multiple dedicated cryptographic devices.

[0015] Some embodiments of the present application calculate the relevant parameters in the seal production information of the stored seal before signing, determine the storage location address of the private key, and then store the private key in the corresponding private key storage device; this method can be implemented in the electronic signature system without storing information such as the private key serial number, and at the same time achieve random storage of the private key, thereby ensuring the security and controllability of the private key.

[0016] In some embodiments, obtaining the storage location address of the private key of the seal to be stored based on the name of the seal to be made and the number of the seal to be made includes: performing operations on the name of the seal to be made and the number of the seal to be made to obtain a key value; converting the data at a preset position in the key value into a decimal number to obtain the storage location address.

[0017] Some embodiments of the present application calculate the key value through the name of the seal to be produced and the number of the seal to be produced, convert the corresponding data in combination with the set preset position, and determine the storage location address, thereby realizing precise calculation of the storage location address, which is more secure than the method of storing private key serial numbers in the prior art.

[0018] In the second aspect, some embodiments of the present application provide an apparatus for electronic signature application, comprising: a determination module, configured to determine the storage location for storing the electronic seal private key based on the seal information in the information to be signed after obtaining the information to be signed from the business system side; wherein the information to be signed includes: a verification value of the file to be signed and the seal information, the verification value of the file to be signed is obtained by calculating the file to be signed, the seal information includes the seal name and the seal number, and the storage location is any one of a plurality of dedicated cryptographic devices; a signing module, configured to obtain the private key from the storage location, and use the private key to sign the file to be signed to obtain a signed file; a transmission module, configured to send the signed file to the business system side via a front-end gateway.

[0019] On the third aspect, some embodiments of the present application provide a system for electronic signature application, including: a business system side, a signature front-end gateway, an application program interface front-end gateway and an electronic signature system; the business system side is used to send the original file and seal information to the signature front-end gateway, and the seal information includes the seal name and the seal number; the signature front-end gateway is used to calculate the original file to obtain the file to be signed; wherein the file to be signed and the seal information constitute the information to be signed; the information to be signed and the authentication data are sent to the application program interface front-end gateway; the application A program interface front-end gateway is used to receive the information to be signed and the authentication data, and after confirming that the verification result of the authentication data is passed, the information to be signed is sent to the electronic signature system; the electronic signature system is used to determine the storage location of the electronic seal private key based on the seal information in the information to be signed; obtain the private key from the storage location, and use the private key to sign the file to be signed to obtain a signed file; wherein the storage location is any one of a plurality of dedicated cryptographic devices, and the signed file is used to be transmitted to the business system side.

[0020] In a fourth aspect, some embodiments of the present application provide a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, can implement the method described in any embodiment of the first aspect.

[0021] In a fifth aspect, some embodiments of the present application provide an electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor, when executing the program, can implement a method as described in any embodiment of the first aspect.

[0022] In a sixth aspect, some embodiments of the present application provide a computer program product, wherein the computer program product comprises a computer program, wherein the computer program, when executed by a processor, can implement the method described in any embodiment of the first aspect. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] In order to more clearly illustrate the technical solutions of some embodiments of the present application, the drawings required for use in some embodiments of the present application will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying creative work.

[0024] Figure 1 A system diagram of an electronic signature application provided for some embodiments of the present application;

[0025] Figure 2A flow chart of a method for storing a seal private key provided for some embodiments of the present application;

[0026] Figure 3 One of the flow charts of the method for applying electronic signature provided in some embodiments of the present application;

[0027] Figure 4 A second flowchart of a method for applying an electronic signature provided in some embodiments of the present application;

[0028] Figure 5 A block diagram of the electronic signature application provided in some embodiments of the present application;

[0029] Figure 6 A schematic diagram of an electronic device is provided for some embodiments of the present application. DETAILED DESCRIPTION

[0030] The technical solutions in some embodiments of the present application will be described below in conjunction with the drawings in some embodiments of the present application.

[0031] It should be noted that similar reference numerals and letters represent similar items in the following drawings, so once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. At the same time, in the description of this application, the terms "first", "second", etc. are only used to distinguish the description and cannot be understood as indicating or implying relative importance.

[0032] In related technologies, the traditional electronic signature model of "separate construction and independent application" is gradually unable to meet the increasingly open business needs. When electronic signatures require mutual trust and recognition among multiple parties, coordination among multiple parties is required, which increases the difficulty of mutual recognition of signatures, that is, it is currently impossible to achieve unified management of seals. Moreover, in this model, when deploying traditional electronic seal systems on various cloud platforms, it is impossible to directly use designated cryptographic devices, or only use fixed cryptographic devices provided by the cloud platform. Therefore, when deploying, it is impossible to store public and private keys separately or on the cloud platform.

[0033] Moreover, in the process of providing government services to natural persons and legal persons, it is necessary to stamp all kinds of electronic documents and electronic certificates with the electronic seals of various commissions and offices. If multiple units are involved in stamping, multiple signature systems are required to realize the electronic signature function. The signature documents need to be transmitted to the electronic signature system through the network, and the system security authentication is required when signing. This will obviously lead to low efficiency of business system signature, and when a large number of electronic documents need to be signed, it is impossible to achieve rapid expansion and support large-scale signatures. The encryption technology of traditional electronic seals is relatively single. With the development of technology, its encryption algorithm may be cracked, and the seal image and related information are at risk of being tampered with or forged. Once the attacker has mastered the corresponding technology and tools, it may illegally obtain the key of the electronic seal or tamper with the seal data, resulting in the authenticity and integrity of the seal cannot be guaranteed.

[0034] In view of this, some embodiments of the present application provide a method for electronic signature application, in which the private key of the seal can be stored in any one of the special cryptographic devices in the early stage of signing, and the storage address can be determined based on the seal information. When signing a file, after the electronic signature system obtains the information to be signed, it is necessary to determine the storage location of the private key by calculating the seal information, read the private key from the special cryptographic device corresponding to the storage location to sign the file to be signed, and finally transmit the signed file back to the business system side. The private key of the seal in this application is a storage location determined by calculating the seal information, and the storage location only stores the private key of the seal, which is stored separately from the public key, so as to ensure that the seal is authentic and valid during use and is not tampered with. When the public key is stored, there is no need to save the information or related identification of the storage private key. If the storage of the private key is to be expanded later, a server can be directly added, the seal is stored in the cloud service platform through an algorithm, and its corresponding private key is randomly stored in a special cryptographic device corresponding to the storage location after the seal information is calculated. In other words, the seal private key in this application is centrally stored, and the professional cryptographic equipment for storing private keys is quickly expanded through cryptographic algorithms, thereby achieving centralized, efficient and secure management of seals.

[0035] The following is combined with Figure 1 The overall composition structure of the electronic signature application system provided by some embodiments of the present application is exemplified.

[0036] like Figure 1As shown, some embodiments of the present application provide a system diagram of an electronic signature application, and the system of the electronic signature application may include: a business system side 110 and an electronic signature system side 120. Among them, the business system side 110 includes: multiple business systems 111 and a signature front gateway 112. The electronic signature system side 120 includes an API interface front gateway 121 (as a specific example of an application program interface front gateway) and an electronic signature system 122, wherein the electronic signature system 122 is connected to multiple dedicated cryptographic devices 123. It should be understood that multiple business systems 111 can implement different business processing, and multiple dedicated cryptographic devices 123 can store private keys corresponding to different seals. Moreover, the number of dedicated cryptographic devices 123 can be expanded according to the actual number of seals, so as to store the private keys corresponding to the newly added seals in the dedicated cryptographic devices 123 in the expanded electronic signature system 122, so as to realize the centralized management of the private keys of all seals.

[0037] In some embodiments of the present application, the business system side 110 is used to send the original document and seal information to the signature front gateway, and the seal information includes the seal name and seal number.

[0038] In some embodiments of the present application, the signature front-end gateway 112 is used to calculate the original file to obtain the file to be signed; wherein, the file to be signed includes a verification value and seal information, and the verification value of the file to be signed is obtained by calculating the file to be signed to constitute the information to be signed; and the information to be signed and the authentication data are sent to the application interface front-end gateway.

[0039] In some embodiments of the present application, the API interface front gateway 121 is used to receive the information to be signed and the authentication data, and after confirming that the verification result of the authentication data is passed, send the information to be signed to the electronic signature system.

[0040] In some embodiments of the present application, the electronic signature system 122 is used to determine the storage location of the electronic seal private key based on the seal information; obtain the private key from the storage location, and use the private key to sign the file to be signed to obtain the signed file; wherein the storage location is any one of a plurality of dedicated cryptographic devices, and the signed file is used to be transmitted to the business system side.

[0041] It should be noted that Figure 1 The electronic signature application system shown can realize that the business system 111 calls the electronic signature system 122 to complete the signature and seal verification in the process of handling the business process. It can realize the scenario where users complete the online submission of materials, event approval, OA process, and many other online stamping of documents to be signed through the business system 111. It should be understood that the application scenarios of the embodiments of the present application are not limited.

[0042] The following is an example of Figure 1 The specific functions of each unit in it.

[0043] In order to accurately process the signature service, in some embodiments of the present application, the private key of the seal needs to be randomly stored in the corresponding dedicated cryptographic device 123. Figure 2 The implementation process of storing the seal private key before electronic signature, which is performed by the electronic signature system 122 and provided in some embodiments of the present application, is exemplified.

[0044] Please see attached Figure 2 , Figure 2 A flow chart of a method for storing a seal private key provided for some embodiments of the present application, the method for storing a seal private key may include:

[0045] S210, obtaining seal making information of the seal to be stored, wherein the seal making information includes: a stamp, a name of the seal to be made, a number of the seal to be made, and making information.

[0046] For example, in some embodiments of the present application, when making a seal in the electronic signature system 122, it is necessary to upload the stamp, the name of the seal to be made, the number of the seal to be made, and related production information in the electronic signature system 122. The production information may be the size of the seal, the shape of the seal, etc. It should be understood that the production information can be expanded according to the actual application scenario, and the embodiments of the present application are not specifically limited here.

[0047] S220, based on the name of the seal to be made and the number of the seal to be made, obtaining a storage location address of the seal private key to be stored.

[0048] For example, in some embodiments of the present application, before storing the seal private key, the storage location address of the seal private key to be stored can be calculated based on the name of the seal to be made and the number of the seal to be made. Alternatively, the storage location address can also be calculated based on the name of the seal to be made, the number of the seal to be made and other parameters. Other parameters can be content related to the seal making information. In other words, the parameters required to obtain the storage location address can be flexibly adjusted, and the embodiments of the present application are not specifically limited here.

[0049] In some embodiments of the present application, S220 may include: performing calculations on the name of the seal to be produced and the number of the seal to be produced to obtain a key value; converting the data at a preset position in the key value into a decimal number to obtain the storage location address.

[0050] For example, in some embodiments of the present application, an HMAC value (i.e., a hash value with a key, as a specific example of a key value) is calculated based on the name of the seal to be produced and the number of the seal to be produced. The last i bits of the HMAC value are intercepted (as a specific example of a preset position), and the i bits are converted into a decimal number, which is the number of the dedicated cryptographic device storing the private key of the seal to be stored (as a specific example of the storage location address). The value of i can be 3, 4, etc., and the embodiments of the present application do not make specific limitations here.

[0051] As a specific example, suppose i=3, after conversion to a decimal number, the conversion result belongs to any number from 0 to 7. At this time, the electronic signature system 122 is connected to 8 special cryptographic devices (one special cryptographic device has a number), and these 8 special cryptographic devices are numbered according to 0 to 7; according to the number corresponding to the conversion result, it is stored in the special cryptographic device with the same number, that is, the private key is stored in one of the 8 devices. Suppose i=4, after conversion to a decimal number, the conversion result belongs to any number from 0 to 15, and the corresponding electronic signature system 122 is connected to 16 special cryptographic devices, and so on. The value of i can be set according to the actual scenario, and the embodiments of the present application are not limited to this.

[0052] S230, storing the seal private key to be stored in a private key storage device corresponding to the storage location address, wherein the private key storage device is any one of the multiple dedicated cryptographic devices.

[0053] For example, in some embodiments of the present application, multiple dedicated cryptographic devices may have been numbered, and the corresponding dedicated cryptographic device may be found through the number of the dedicated cryptographic device for storing the seal private key calculated above, and the seal private key to be stored may be stored in it. Alternatively, if multiple dedicated cryptographic devices do not have clear numbers, one may be randomly selected from the multiple dedicated cryptographic devices to store the seal private key to be stored, and the dedicated cryptographic device may be marked with the number of the dedicated cryptographic device for storing the seal private key calculated above. Before storage, the electronic signature system 122 calls the interface of the certificate issuance structure to apply for a certificate for the electronic seal. After completion, the electronic signature system 122 integrates the certificate and other related information into a seal structure, and stores the seal private key in the dedicated cryptographic device.

[0054] Through the above calculations, it is possible to implement an electronic signature system without storing information such as private key serial numbers, while achieving random storage of private keys to ensure the security and controllability of private keys.

[0055] In addition, in some embodiments of the present application, if the number of seals on the electronic signature system side 120 increases significantly, the electronic signature system side 120 can be rapidly expanded by adding special cryptographic devices. For example, the new special cryptographic device is connected to the network of the original special cryptographic device, and the last i bits of the HMAC value calculated by the electronic signature system 122 according to the name of the seal to be produced and the number of the seal to be produced are adjusted. The address of the corresponding special cryptographic device is calculated by the last i bits. In this way, the private key is randomly stored on one of the servers on the electronic signature system side 120, and according to this calculation, the number of private keys stored in multiple special cryptographic devices is not much different, thereby realizing the rapid expansion of private keys and enhancing the robustness, controllability and scalability of electronic signatures.

[0056] After completing the centralized storage of the above-mentioned seal private key, Figure 3 The implementation process of the electronic signature application performed by the electronic signature system 122 provided in some embodiments of the present application is exemplified.

[0057] Please see attached Figure 3 , Figure 3 A flow chart of a method for applying an electronic signature is provided for some embodiments of the present application. The method for applying an electronic signature may include:

[0058] S310, after obtaining the information to be signed from the business system side, determine the storage location for storing the electronic seal private key based on the seal information in the information to be signed; wherein, the information to be signed includes: a verification value of the file to be signed and the seal information, the verification value of the file to be signed is obtained by calculating the file to be signed, the seal information includes a seal name and a seal number, and the storage location is any one of a plurality of dedicated cryptographic devices.

[0059] For example, in some embodiments of the present application, after the electronic signature system 122 obtains the information to be signed from the business system, it first needs to determine the storage location of the electronic seal private key through the seal information. Figure 2 The method embodiment shown is pre-stored in a dedicated cryptographic device.

[0060] In some embodiments of the present application, before executing S310, the method of electronic signature application may further include: receiving the information to be signed sent by the application interface front-end gateway; wherein the application interface front-end gateway sends the information to be signed after verifying the authentication data sent by the signature front-end gateway; the verification value of the file to be signed is obtained by the signature front-end gateway calculating the file to be signed on the business system side.

[0061] For example, in some embodiments of the present application, the information to be signed is sent by the API front gateway (as a specific example of the API interface front gateway 121) to the electronic signature system 122. The process of obtaining the information to be signed is as follows:

[0062] First, a signature front gateway 112 is deployed on the business system side 110, which can calculate the file to be signed of the business system 111, obtain the hash value to be signed (as a specific example of the verification value of the file to be signed), and pass the hash value to be signed, authentication parameters, and seal information to the API front gateway through the signature front gateway 112, so that the file to be signed does not leave the local network and the risk of being intercepted is reduced. The API front gateway authenticates the signature front gateway 112 through the authentication parameters. After the authentication is passed, the hash value to be signed and the seal information are passed to the electronic signature system 122. The electronic signature system 122 can extract the file to be signed after verifying the hash value to be signed (similar to the principle of file encryption and decryption); or the hash value to be signed, the file to be signed and the seal information can be sent to the electronic signature system 122 together. After the electronic signature system 122 verifies that the hash value to be signed is passed, the signature operation is directly performed on the file to be signed. It is understandable that, in addition to the hash algorithm, other algorithms may be used for the verification value of the file to be signed, and the embodiments of the present application are not limited thereto.

[0063] It can be seen that the API front-end gateway realizes the gateway authentication on the user business system side, which improves the security of transmission.

[0064] In some embodiments of the present application, S310 may include: calculating the seal information to obtain a calculation result; converting data at a preset position in the calculation result to obtain the storage position.

[0065] For example, in some embodiments of the present application, the electronic signature system 122 adopts and Figure 2 The method embodiment shown calculates the seal private key to be stored in the same manner as the serial number, calculates the seal information to obtain the calculation result, and converts the relevant data in the calculation result to obtain the storage location of the seal private key.

[0066] In some embodiments of the present application, the preset position is the last i bits in the calculation result, where i is a positive integer; S310 may include: converting the data corresponding to the last i bits in the calculation result into decimal data to obtain the storage position.

[0067] For example, in some embodiments of the present application, the electronic signature system 122 performs an HMAC operation on information such as the seal name and seal number to obtain a calculation result, and intercepts the last i digits of the calculation result (as a specific example of a preset position), converts the intercepted i digits into decimal, and obtains the storage location of the private key corresponding to the seal.

[0068] S320, obtaining the private key from the storage location, and using the private key to sign the file to be signed to obtain a signed file.

[0069] For example, in some embodiments of the present application, the electronic signature system 122 can read the private key from the dedicated password device corresponding to the storage location. After obtaining the public key and private key of the seal, the hash value of the file to be signed transmitted by the API front gateway is calculated to obtain the signed file.

[0070] S330, sending the signed file to the business system side through the front-end gateway.

[0071] For example, in some embodiments of the present application, the signed file is transmitted back to the signature front gateway 112 through the API front gateway, and the signature front gateway 112 converts the signed file into a set format file (for example, a base64 file) and returns it to the business system 111 to complete the signing operation. It should be understood that the signed file can be securely transmitted under encryption. After receiving the set format file corresponding to the signed file, the business system 111 can verify it to determine that it has not been tampered with during the transmission process. For example, the electronic signature system 122 will calculate the verification value and store it in the signed file. The business system 111 can calculate the verification value of the set format file and determine that it is consistent with the signed file, so that it can be known that the file has not been tampered with.

[0072] Through some of the above embodiments of the present application, it can be known that in the application of a private key controllable and extensible electronic signature provided by the present application, the private key and the public key are stored separately, used in combination, and can be quickly expanded. This application can achieve rapid expansion when business data grows rapidly, and ensure the security of storage and use. The method adopts a private key random storage method, and completes the storage and use of the private key through an algorithm; by storing the public key and the private key separately, it is ensured that the seal is authentic and valid during use and is not tampered with. When storing the private key, there is no need to save the need to store the private key or the related identification. The calculation is performed according to the seal number and name to determine the server and location of the corresponding seal private key storage. If you want to expand the storage of the private key, you can directly add a server, store the seal on the cloud service platform through an algorithm, and randomly store the corresponding private key in a dedicated cryptographic device, which is more flexible.

[0073] The following is combined with Figure 4The specific process of electronic signature application provided by some embodiments of the present application is exemplified.

[0074] Please see attached Figure 4 , Figure 4 A flow chart of a method for applying an electronic signature provided for some embodiments of the present application.

[0075] The above process is explained below as an example.

[0076] S400, the electronic signature system obtains seal production information of the seal to be stored.

[0077] S410, based on the name of the seal to be made and the number of the seal to be made, obtaining the storage location address of the seal private key to be stored.

[0078] S420, storing the seal private key to be stored in a private key storage device corresponding to the storage location address.

[0079] S430, the business system sends the document to be signed and the seal information to the signature front-end gateway.

[0080] S440, the pre-signing gateway calculates the file to be signed to obtain a verification value of the file to be signed.

[0081] S450, the signature front-end gateway sends the verification value of the document to be signed, the document to be signed, the seal information and the authentication data to the API front-end gateway.

[0082] S460, after the API front-end gateway confirms that the authentication data has passed the verification, it sends the verification value of the document to be signed and the seal information to the electronic signature system.

[0083] S470, after determining that the check value of the document to be signed has passed the verification, after determining the storage location of the electronic seal private key based on the seal information, read the private key.

[0084] S480, using the private key to sign the file to be signed, to obtain the signed file.

[0085] S490, send the signed file to the business system through the API front gateway and the signature front gateway.

[0086] It can be understood that the specific implementation process of S400 to S490 can refer to the method embodiment provided above. To avoid repetition, some descriptions are omitted here.

[0087] Through some of the above embodiments of the present application, it can be known that the present application stores the private key of the electronic seal in a dedicated cryptographic device, which not only complies with relevant regulations, but also realizes the credibility, security and scalability of the electronic signature system. The present application can be applied to the centralized storage of large quantities of electronic seals, solving the problems of decentralized construction of electronic signatures, high costs, and difficult maintenance. By using the method of the present application, the key of the electronic seal is stored without the need for the relevant identification of the key, which enhances the overall security of the system, ensures the security and rapid expansion of the key, etc.

[0088] Please refer to Figure 5 , Figure 5 The following is a block diagram of the electronic signature application device provided by some embodiments of the present application. It should be understood that the electronic signature application device corresponds to the above method embodiment and can execute each step involved in the above method embodiment. The specific functions of the electronic signature application device can be found in the above description. To avoid repetition, the detailed description is appropriately omitted here.

[0089] Figure 5 The electronic signature application device includes at least one software function module that can be stored in a memory in the form of software or firmware or solidified in the electronic signature application device. The electronic signature application device includes: a determination module 510, which is configured to determine the storage location for storing the electronic seal private key based on the seal information in the information to be signed after obtaining the information to be signed from the business system side; wherein the information to be signed includes: a verification value of the file to be signed and the seal information, the verification value of the file to be signed is obtained by calculating the file to be signed, the seal information includes the seal name and the seal number, and the storage location is any one of a plurality of dedicated cryptographic devices; a signing module 520, which is configured to obtain the private key from the storage location, and use the private key to sign the file to be signed to obtain a signed file; a transmission module 530, which is configured to send the signed file to the business system side through a front-end gateway.

[0090] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the device described above can refer to the corresponding process in the aforementioned method, and will not be described in detail here.

[0091] Some embodiments of the present application further provide a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, can implement the operations of the method corresponding to any of the above methods provided in the above embodiments.

[0092] Some embodiments of the present application further provide a computer program product, which includes a computer program, wherein when the computer program is executed by a processor, it can implement the operations corresponding to any of the above methods provided in the above embodiments.

[0093] like Figure 6 As shown, some embodiments of the present application provide an electronic device 600, which includes: a memory 610, a processor 620, and a computer program stored in the memory 610 and executable on the processor 620, wherein the processor 620 can implement a method as described in any of the above embodiments when reading the program from the memory 610 through a bus 630 and executing the program.

[0094] Processor 620 can process digital signals and can include various computing structures, such as complex instruction set computer structure, reduced instruction set computer structure, or a structure that implements a combination of multiple instruction sets. In some examples, processor 620 can be a microprocessor.

[0095] The memory 610 may be used to store instructions executed by the processor 620 or data related to the execution of instructions. These instructions and / or data may include codes for implementing some or all functions of one or more modules described in the embodiments of the present application. The processor 620 of the disclosed embodiment may be used to execute instructions in the memory 610 to implement the method shown above. The memory 610 includes a dynamic random access memory, a static random access memory, a flash memory, an optical memory, or other memory known to those skilled in the art.

[0096] The above description is only an embodiment of the present application and is not intended to limit the scope of protection of the present application. For those skilled in the art, the present application may have various changes and variations. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present application should be included in the scope of protection of the present application. It should be noted that similar reference numerals and letters represent similar items in the following drawings, so once an item is defined in one drawing, it does not need to be further defined and explained in the subsequent drawings.

[0097] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art who is familiar with the present technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.

[0098] It should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the existence of other identical elements in the process, method, article or device including the elements.

Claims

1. A method for applying an electronic signature, characterized in that: include: After obtaining the information to be signed from the business system side, the storage location for storing the electronic seal private key is determined based on the seal information in the information to be signed; wherein the information to be signed includes: a check value of the document to be signed and the seal information, the check value of the document to be signed is obtained by calculating the document to be signed, the seal information includes a seal name and a seal number, and the storage location is any one of a plurality of dedicated cryptographic devices; Obtaining the private key from the storage location, and using the private key to sign the file to be signed to obtain a signed file; The signed file is sent to the business system side through the front-end gateway.

2. The method according to claim 1, characterized in that The step of determining a storage location for storing an electronic seal private key based on the seal information in the information to be signed includes: Calculating the seal information to obtain a calculation result; The data at the preset position in the calculation result is converted to obtain the storage position.

3. The method according to claim 2, characterized in that The preset position is the last i bits in the calculation result, where i is a positive integer; wherein converting the data at the preset position in the calculation result to obtain the storage position includes: The data corresponding to the last i bits in the calculation result are converted into decimal data to obtain the storage location.

4. The method according to any one of claims 1 to 3, characterized in that Before determining the storage location for storing the electronic seal private key based on the seal information in the information to be signed, the method further includes: Receive the information to be signed sent by the application interface front-end gateway; wherein, the application interface front-end gateway sends the information to be signed after verifying the authentication data sent by the signature front-end gateway; the verification value of the file to be signed is obtained by the signature front-end gateway after calculating the file to be signed on the business system side.

5. The method according to any one of claims 1 to 3, characterized in that Before obtaining the information to be signed from the business system, the method further includes: Acquire the seal making information of the seal to be stored, wherein the seal making information includes: a stamp, a name of the seal to be made, a number of the seal to be made and making information; Based on the name of the seal to be made and the number of the seal to be made, obtaining the storage location address of the seal private key to be stored; The seal private key to be stored is stored in a private key storage device corresponding to the storage location address, wherein the private key storage device is any one of the multiple dedicated cryptographic devices.

6. The method according to claim 5, characterized in that The step of obtaining the storage location address of the seal private key to be stored based on the name of the seal to be made and the number of the seal to be made includes: Calculate the name of the seal to be made and the number of the seal to be made to obtain a key value; The data at the preset position in the key value is converted into a decimal number to obtain the storage location address.

7. A device for applying electronic signature, characterized in that: include: The determination module is configured to determine the storage location of the electronic seal private key based on the seal information in the information to be signed after obtaining the information to be signed from the business system side; wherein the information to be signed includes: a check value of the document to be signed and the seal information, the check value of the document to be signed is obtained by calculating the document to be signed, the seal information includes a seal name and a seal number, and the storage location is any one of a plurality of dedicated cryptographic devices; A signing module is configured to obtain the private key from the storage location, and use the private key to sign the file to be signed to obtain a signed file; The transmission module is configured to send the signed file to the business system side through the front-end gateway.

8. A system for electronic signature application, characterized in that: include: Business system side, signature front-end gateway, application interface front-end gateway and electronic signature system; The business system side is used to send the original document and seal information to the signature front-end gateway, and the seal information includes the seal name and seal number; The signature front-end gateway is used to calculate the original file to obtain the file to be signed; wherein the file to be signed and the seal information constitute the information to be signed; and send the information to be signed and the authentication data to the application program interface front-end gateway; The application program interface front-end gateway is used to receive the information to be signed and the authentication data, and after confirming that the verification result of the authentication data is passed, send the information to be signed to the electronic signature system; The electronic signature system is used to determine the storage location of the electronic seal private key based on the seal information in the information to be signed; obtain the private key from the storage location, and use the private key to sign the file to be signed to obtain a signed file; wherein the storage location is any one of a plurality of dedicated cryptographic devices, and the signed file is used to be transmitted to the business system side.

9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, wherein the computer program executes the method according to any one of claims 1 to 6 when executed by a processor.

10. An electronic device, characterized in that: The method comprises a memory, a processor, and a computer program stored in the memory and running on the processor, wherein the computer program executes the method according to any one of claims 1 to 6 when being run by the processor.

Citation Information

Patent Citations

  • Block chain-based data processing method and apparatus

    CN113327142A

  • Secure electronic signature and verification method based on preposed gateway

    CN118118275A

  • Portable cipher key storage device

    JP1991162152A