Method, device, system, storage medium and electronic device for electronic signature application

By randomly storing the private key of the seal in a dedicated cryptographic device and using the seal information to determine the storage location, combined with the method of separate storage of the public key and the private key, the problem of inconsistent seal management and insufficient security in the traditional electronic seal system is solved, and efficient and secure electronic seal service is achieved, supporting rapid expansion and data tamper-proof.

CN120162833BActive Publication Date: 2025-08-29BEIJING BIG DATA CENT
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510224744.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-27
Publication Date
2025-08-29
Estimated Expiration
2045-02-27

AI Technical Summary

Technical Problem

The traditional electronic sealing system cannot achieve unified management of seals, resulting in inefficient and security risks in sealing business, which cannot meet the needs of mutual trust, mutual recognition and rapid expansion between multiple parties.

Method used

By randomly storing the private key of the seal in a dedicated password device, using the seal information to determine the storage location, the unified management and security of the seal is realized, and the public key and private key are separated to avoid directly storing the device number of the private key, and data transmission and authentication are combined with the front gateway to ensure data security and expansion.

Benefits of technology

It realizes unified management of seals and efficient and trustworthy seal signature services, improves the security of private key storage and the robustness of the system, supports rapid expansion and prevents seal data from being tampered with, and ensures the authenticity and integrity of the seal.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120162833B_ABST
    Figure CN120162833B_ABST
Patent Text Reader

Abstract

The present application relates to the field of electronic signatures, and specifically provides a method, device, system, storage medium, and electronic device for electronic signature application. The method may include: after obtaining the information to be signed from the business system side, determining the storage location for storing the electronic seal private key based on the seal information in the information to be signed; wherein the information to be signed includes: a check value of the document to be signed and seal information, the check value of the document to be signed is obtained by calculating the document to be signed, the seal information includes the seal name and seal number, and the storage location is any one of a plurality of dedicated cryptographic devices; obtaining the private key from the storage location, and using the private key to sign the document to be signed to obtain a signed document; and sending the signed document to the business system side via a front-end gateway. Some embodiments of the present application can flexibly store private keys and provide reliable signature services under the premise of security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of electronic signatures, and more specifically, to a method, device, system, storage medium, and electronic device for electronic signature applications. Background Art

[0002] An electronic seal is a form of electronic signature that utilizes image processing technology to transform an electronic signature into a visual equivalent to a paper document stamp. This technology also ensures the authenticity and integrity of electronic information and the non-repudiation of the signatory. As electronic signature technology continues to be applied across various industries, the security of electronic seals during centralized storage has become a crucial aspect of the electronic signature industry.

[0003] Traditional electronic signature systems utilize a "separate development, independent application" model. As business operations become more complex and complex, this model is increasingly unable to meet the needs of increasingly open businesses. Current business processes urgently require mutual trust and recognition of electronic seals, as well as unified management of electronic seals. However, the current "separate development, independent application" model, which advocates for decentralized electronic signature systems, fails to achieve unified seal management and, consequently, hinders efficient signature business operations.

[0004] Therefore, how to provide a technical solution for a method of electronic signature application that can be uniformly managed and efficient has become a technical problem that needs to be solved urgently. Summary of the Invention

[0005] The purpose of some embodiments of the present application is to provide a method, device, system, storage medium and electronic device for electronic signature application. Through the technical solution of the embodiments of the present application, by randomly storing the seal private key in a dedicated cryptographic device, the independent, secure and flexible storage of the seal private key can be achieved, the unified management of the seal can be achieved, and efficient, trustworthy, reliable and scalable electronic signature and verification services can be provided for seal users.

[0006] In the first aspect, some embodiments of the present application provide a method for applying an electronic signature, comprising: after obtaining the information to be signed from the business system side, determining the storage location for storing the electronic seal private key based on the seal information in the information to be signed; wherein the information to be signed includes: a verification value of the file to be signed and seal information, the verification value of the file to be signed is obtained by calculating the file to be signed, the seal information includes a seal name and a seal number, and the storage location is any one of a plurality of dedicated cryptographic devices; obtaining the private key from the storage location, and using the private key to sign the file to be signed to obtain a signed file; and sending the signed file to the business system side through a front-end gateway.

[0007] Some embodiments of the present application determine the storage location of the seal private key through seal information, and can obtain the private key from the dedicated cryptographic device corresponding to the storage location to sign the document to be signed to obtain the signed document; finally, the document is sent to the business system side through the front-end gateway. Some embodiments of the present application determine the storage location of the private key through seal information, which has high randomness and does not require direct storage of the device number corresponding to the private key, thereby achieving unified management of the seal and improving the security of private key storage. Moreover, the independent storage of private and public keys can also ensure the security of private key storage and use.

[0008] In some embodiments, determining the storage location of the electronic seal private key based on the seal information in the information to be signed includes: calculating the seal information to obtain a calculation result; converting the data at a preset location in the calculation result to obtain the storage location.

[0009] Some embodiments of the present application obtain the calculation results of the seal information and convert them to obtain the storage location, so as to accurately store the private key. Compared with the solution of directly using the device number to determine the storage location of the private key, it is more secure.

[0010] In some embodiments, the preset position is the last i digits in the calculation result, where i is a positive integer; wherein, converting the data at the preset position in the calculation result to obtain the storage position includes: converting the data corresponding to the last i digits in the calculation result into decimal data to obtain the storage position.

[0011] Some embodiments of the present application set a preset position, perform conversion calculations on the data at the preset position in the calculation result, obtain the storage position, and achieve accurate acquisition of the storage position.

[0012] In some embodiments, before determining the storage location of the electronic seal private key based on the seal information in the information to be signed, the method also includes: receiving the information to be signed sent by the application interface front-end gateway; wherein the application interface front-end gateway verifies the authentication data sent by the signature front-end gateway and then sends the information to be signed; the verification value of the file to be signed is obtained by the signature front-end gateway after calculating the file to be signed on the business system side.

[0013] Some embodiments of the present application send the information to be signed through the application interface front-end gateway, wherein the application interface front-end gateway can also authenticate the signed signature gateway to ensure the security of data transmission and prevent malicious tampering.

[0014] In some embodiments, before obtaining the information to be signed from the business system side, the method further includes: obtaining seal production information of the seal to be stored, wherein the seal production information includes: a mold, a name of the seal to be produced, a number of the seal to be produced, and production information; based on the name of the seal to be produced and the number of the seal to be produced, obtaining the storage location address of the private key of the seal to be stored; storing the private key of the seal to be stored in a private key storage device corresponding to the storage location address, wherein the private key storage device is any one of the multiple dedicated cryptographic devices.

[0015] Some embodiments of the present application calculate the relevant parameters in the seal production information of the stored seal before signing, determine the storage location address of the private key, and then store the private key in the corresponding private key storage device; this method can be implemented in the electronic signature system without storing information such as the private key serial number, and at the same time achieve random storage of the private key, thereby ensuring the security and controllability of the private key.

[0016] In some embodiments, obtaining the storage location address of the private key of the seal to be stored based on the name of the seal to be produced and the number of the seal to be produced includes: performing operations on the name of the seal to be produced and the number of the seal to be produced to obtain a key value; converting the data at a preset position in the key value into a decimal number to obtain the storage location address.

[0017] Some embodiments of the present application calculate the key value by the name of the seal to be produced and the number of the seal to be produced, convert the corresponding data in combination with the set preset position, and determine the storage location address, thereby realizing precise calculation of the storage location address, which is more secure than the method of storing private key serial numbers in the prior art.

[0018] In the second aspect, some embodiments of the present application provide a device for electronic signature application, including: a determination module, configured to determine the storage location of the electronic seal private key based on the seal information in the information to be signed after obtaining the information to be signed from the business system side; wherein, the information to be signed includes: a verification value of the file to be signed and seal information, the verification value of the file to be signed is obtained by calculating the file to be signed, the seal information includes a seal name and a seal number, and the storage location is any one of a plurality of dedicated cryptographic devices; a signing module, configured to obtain the private key from the storage location, and use the private key to sign the file to be signed to obtain a signed file; a transmission module, configured to send the signed file to the business system side through a front-end gateway.

[0019] On the third aspect, some embodiments of the present application provide a system for electronic signature application, including: a business system side, a signature front-end gateway, an application program interface front-end gateway and an electronic signature system; the business system side is used to send the original file and seal information to the signature front-end gateway, and the seal information includes the seal name and seal number; the signature front-end gateway is used to calculate the original file to obtain the file to be signed; wherein the file to be signed and the seal information constitute the information to be signed; the information to be signed and the authentication data are sent to the application program interface front-end gateway; the application A program interface front-end gateway is used to receive the information to be signed and the authentication data, and after confirming that the verification result of the authentication data is passed, the information to be signed is sent to the electronic signature system; the electronic signature system is used to determine the storage location of the electronic seal private key based on the seal information in the information to be signed; obtain the private key from the storage location, and use the private key to sign the file to be signed to obtain the signed file; wherein, the storage location is any one of a plurality of dedicated cryptographic devices, and the signed file is used to be transmitted to the business system side.

[0020] In a fourth aspect, some embodiments of the present application provide a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, can implement the method described in any embodiment of the first aspect.

[0021] In a fifth aspect, some embodiments of the present application provide an electronic device comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein the processor can implement a method as described in any embodiment of the first aspect when executing the program.

[0022] In a sixth aspect, some embodiments of the present application provide a computer program product, comprising a computer program, wherein the computer program, when executed by a processor, can implement the method described in any embodiment of the first aspect. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] In order to more clearly illustrate the technical solutions of some embodiments of the present application, the following is a brief introduction to the drawings required for use in some embodiments of the present application. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other relevant drawings can be obtained based on these drawings without paying any creative work.

[0024] Figure 1 A system diagram of an electronic signature application provided for some embodiments of the present application;

[0025] Figure 2A flow chart of a method for storing a seal private key provided in some embodiments of the present application;

[0026] Figure 3 One of the flow charts of the electronic signature application method provided in some embodiments of the present application;

[0027] Figure 4 Flowchart 2 of the method for applying electronic signatures provided in some embodiments of the present application;

[0028] Figure 5 A block diagram of the electronic signature application provided in some embodiments of the present application;

[0029] Figure 6 A schematic diagram of an electronic device is provided for some embodiments of the present application. DETAILED DESCRIPTION

[0030] The technical solutions in some embodiments of the present application will be described below in conjunction with the drawings in some embodiments of the present application.

[0031] It should be noted that similar reference numerals and letters represent similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined or explained in subsequent drawings. At the same time, in the description of this application, the terms "first", "second", etc. are only used to distinguish the description and should not be understood as indicating or implying relative importance.

[0032] In related technologies, the traditional electronic signature model of "independent construction and independent application" is gradually unable to meet the needs of increasingly open businesses. When electronic signatures require mutual trust and recognition among multiple parties, coordination among multiple parties is required, which increases the difficulty of mutual recognition of signatures and seals. In other words, unified management of seals is currently impossible. Moreover, under this model, when deploying traditional electronic seal systems on various cloud platforms, it is impossible to directly use designated cryptographic devices, or only use fixed cryptographic devices provided by the cloud platform. Therefore, during deployment, it is impossible to store public and private keys separately or on the cloud platform.

[0033] Furthermore, when providing government services to individuals and legal entities, various electronic documents and certificates must be stamped with the electronic seals of various commissions and offices. If multiple entities are involved, multiple signature systems are required to implement the electronic signature function. The signed documents must be transmitted to the electronic signature system via the network, and system security authentication is required during the signing process. This significantly reduces the efficiency of business system signatures and prevents rapid scalability to support large volumes of electronic documents requiring signatures. Traditional electronic seal encryption technology is relatively simple, and as technology evolves, its encryption algorithm can be cracked, posing the risk of tampering with or forging seal images and related information. Once an attacker gains access to the appropriate technology and tools, they could illegally obtain the electronic seal's key or tamper with the seal data, compromising the authenticity and integrity of the seal.

[0034] In view of this, some embodiments of the present application provide a method for electronic signature application, in which the private key of the seal can be stored in any one of the dedicated cryptographic devices in the early stage of signing, and the storage address can be determined based on the seal information. When signing a document, after the electronic signature system obtains the information to be signed, it is necessary to determine the storage location of the private key by calculating the seal information, read the private key from the dedicated cryptographic device corresponding to the storage location to sign the document to be signed, and finally transmit the signed file back to the business system side. In this application, the private key of the seal is a storage location determined by calculating the seal information. The storage location only stores the private key of the seal, which is stored separately from the public key to ensure that the seal is authentic and valid during use and is not tampered with. When the public key is stored, there is no need to save the information or related identification of the private key. If the storage of the private key is to be expanded later, a server can be directly added, the seal can be stored on the cloud service platform through an algorithm, and its corresponding private key can be randomly stored in a dedicated cryptographic device corresponding to the storage location after the seal information is calculated. In other words, the seal private key in this application is centrally stored, and the professional cryptographic equipment for storing the private key is quickly expanded through cryptographic algorithms, thereby realizing centralized, efficient and secure management of the seal.

[0035] The following is combined with Figure 1 The overall composition structure of the electronic signature application system provided by some embodiments of the present application is exemplified.

[0036] like Figure 1As shown, some embodiments of the present application provide a system diagram of an electronic signature application, and the system of the electronic signature application may include: a business system side 110 and an electronic signature system side 120. Among them, the business system side 110 includes: multiple business systems 111 and a signature front gateway 112. The electronic signature system side 120 includes an API interface front gateway 121 (as a specific example of an application program interface front gateway) and an electronic signature system 122, wherein the electronic signature system 122 is connected to multiple dedicated cryptographic devices 123. It should be understood that multiple business systems 111 can implement different business processing, and multiple dedicated cryptographic devices 123 can store private keys corresponding to different seals. Moreover, the number of dedicated cryptographic devices 123 can be expanded according to the actual number of seals, so that the private keys corresponding to the newly added seals can be stored in the dedicated cryptographic devices 123 in the expanded electronic signature system 122, thereby realizing centralized management of the private keys of all seals.

[0037] In some embodiments of the present application, the business system side 110 is used to send the original document and seal information to the signature front-end gateway, where the seal information includes the seal name and seal number.

[0038] In some embodiments of the present application, the signature front-end gateway 112 is used to calculate the original file to obtain the file to be signed; wherein, the file to be signed has a verification value and seal information, and the verification value of the file to be signed is obtained by calculating the file to be signed to constitute the information to be signed; and the information to be signed and the authentication data are sent to the application interface front-end gateway.

[0039] In some embodiments of the present application, the API interface front gateway 121 is used to receive the information to be signed and the authentication data, and after confirming that the verification result of the authentication data is passed, send the information to be signed to the electronic signature system.

[0040] In some embodiments of the present application, the electronic signature system 122 is used to determine the storage location of the electronic seal private key based on the seal information; obtain the private key from the storage location, and use the private key to sign the file to be signed to obtain the signed file; wherein the storage location is any one of a plurality of dedicated cryptographic devices, and the signed file is used to be transmitted to the business system side.

[0041] It should be noted that Figure 1 The illustrated electronic signature application system enables the business system 111 to call the electronic signature system 122 to complete the signing and seal verification process during the business process. This allows users to complete numerous online scenarios for stamping documents for signature, such as online submission of materials, event approval, and OA process stamping, through the business system 111. It should be understood that the application scenarios of the embodiments of this application are not limited to this.

[0042] The following is an example of Figure 1 The specific functions of each unit in it.

[0043] In order to achieve accurate processing of the signature business, in some embodiments of the present application, the private key of the seal needs to be randomly stored in the corresponding dedicated password device 123. Figure 2 The implementation process of storing the seal private key before electronic signing, which is performed by the electronic signature system 122 and provided in some embodiments of the present application, is exemplified.

[0044] Please see the attached Figure 2 , Figure 2 A flow chart of a method for storing a seal private key is provided for some embodiments of the present application. The method for storing a seal private key may include:

[0045] S210: Acquire seal production information of the seal to be stored, wherein the seal production information includes: a mold, a name of the seal to be produced, a number of the seal to be produced, and production information.

[0046] For example, in some embodiments of the present application, when creating a seal in the electronic signature system 122, it is necessary to upload the stamp, the name of the seal to be created, the seal number to be created, and related creation information to the electronic signature system 122. The creation information may include seal size, seal shape, etc. It should be understood that the creation information can be expanded based on actual application scenarios and is not specifically limited in the present embodiments.

[0047] S220: Based on the name of the seal to be made and the number of the seal to be made, obtain a storage location address of a private key of the seal to be stored.

[0048] For example, in some embodiments of the present application, before storing the seal private key, the storage location address of the seal private key to be stored can be calculated based on the name of the seal to be produced and the number of the seal to be produced. Alternatively, the storage location address can be calculated based on the name of the seal to be produced, the number of the seal to be produced, and other parameters. The other parameters can be content related to the seal production information. In other words, the parameters required to obtain the storage location address can be flexibly adjusted and are not specifically limited in the embodiments of the present application.

[0049] In some embodiments of the present application, S220 may include: performing calculations on the name of the seal to be produced and the number of the seal to be produced to obtain a key value; converting the data at a preset position in the key value into a decimal number to obtain the storage location address.

[0050] For example, in some embodiments of the present application, an HMAC value (i.e., a hash value with a key, as a specific example of a key value) is calculated based on the name of the seal to be produced and the number of the seal to be produced. The last i bits of the HMAC value are intercepted (as a specific example of a preset position), and these i bits are converted into a decimal number. This number is the number of the dedicated cryptographic device that stores the private key of the seal to be stored (as a specific example of the storage location address). The value of i can be 3, 4, etc., and the embodiments of the present application do not specifically limit this.

[0051] As a specific example, assuming i = 3, after conversion to a decimal number, the conversion result is any number from 0 to 7. At this time, the electronic signature system 122 is connected to 8 dedicated cryptographic devices (each dedicated cryptographic device has a number), and these 8 dedicated cryptographic devices are numbered from 0 to 7. The number corresponding to the conversion result is stored in the dedicated cryptographic device with the same number, that is, the private key is stored in one of the 8 devices. Assuming i = 4, after conversion to a decimal number, the conversion result is any number from 0 to 15. The corresponding electronic signature system 122 is connected to 16 dedicated cryptographic devices, and so on. The value of i can be set according to the actual scenario, and the embodiments of the present application are not limited to this.

[0052] S230: Store the seal private key to be stored in a private key storage device corresponding to the storage location address, wherein the private key storage device is any one of the multiple dedicated cryptographic devices.

[0053] For example, in some embodiments of the present application, multiple dedicated cryptographic devices may have been numbered, and the corresponding dedicated cryptographic device may be found through the number of the dedicated cryptographic device for storing the seal private key calculated above, and the seal private key to be stored may be stored therein. Alternatively, if multiple dedicated cryptographic devices do not have clear numbers, one may be randomly selected from the multiple dedicated cryptographic devices to store the seal private key to be stored, and the dedicated cryptographic device may be marked with the number of the dedicated cryptographic device for storing the seal private key calculated above. Before storage, the electronic signature system 122 calls the interface of the certificate issuance structure to apply for a certificate for the electronic seal. After completion, the electronic signature system 122 integrates the certificate and other related information into a seal structure, and stores the seal private key in the dedicated cryptographic device.

[0054] Through the above calculations, it is possible to implement an electronic signature system without storing information such as the private key serial number, while achieving random storage of the private key to ensure the security and controllability of the private key.

[0055] In addition, in some embodiments of the present application, if the number of seals on the electronic signature system side 120 increases significantly, the electronic signature system side 120 can be rapidly expanded by adding dedicated cryptographic devices. For example, the new dedicated cryptographic device is connected to the network of the original dedicated cryptographic device, and the last i bits of the HMAC value calculated by the electronic signature system 122 based on the name of the seal to be produced and the number of the seal to be produced are adjusted. The address of the corresponding dedicated cryptographic device is calculated using the last i bits. This achieves the random storage of private keys on one of the servers on the electronic signature system side 120, and based on this calculation, the number of private keys stored on multiple dedicated cryptographic devices is not much different, thereby achieving rapid expansion of private keys and enhancing the robustness, controllability and scalability of electronic signatures.

[0056] After completing the centralized storage of the above-mentioned seal private key, Figure 3 The implementation process of the electronic signature application performed by the electronic signature system 122 provided in some embodiments of the present application is exemplified.

[0057] Please see the attached Figure 3 , Figure 3 A flowchart of a method for applying an electronic signature is provided for some embodiments of the present application. The method for applying an electronic signature may include:

[0058] S310, after obtaining the information to be signed from the business system side, determines the storage location for storing the electronic seal private key based on the seal information in the information to be signed; wherein, the information to be signed includes: a verification value of the file to be signed and seal information, the verification value of the file to be signed is obtained by calculating the file to be signed, the seal information includes a seal name and a seal number, and the storage location is any one of a plurality of dedicated cryptographic devices.

[0059] For example, in some embodiments of the present application, after the electronic signature system 122 obtains the information to be signed from the business system, it first needs to determine the storage location of the electronic seal private key through the seal information. Figure 2 The illustrated method embodiment is pre-stored in a dedicated cryptographic device.

[0060] In some embodiments of the present application, before executing S310, the method of electronic signature application may further include: receiving the information to be signed sent by the application interface front-end gateway; wherein, the application interface front-end gateway verifies the authentication data sent by the signature front-end gateway and sends the information to be signed; the verification value of the file to be signed is obtained by the signature front-end gateway after calculating the file to be signed on the business system side.

[0061] For example, in some embodiments of the present application, the information to be signed is sent by the API front gateway (as a specific example of the API interface front gateway 121) to the electronic signature system 122. The process of obtaining the information to be signed is as follows:

[0062] First, a signature front-end gateway 112 is deployed on the business system side 110. It can calculate the file to be signed in the business system 111 and obtain the hash value to be signed (as a specific example of the verification value of the file to be signed). The hash value to be signed, the authentication parameters, and the seal information are passed to the API front-end gateway through the signature front-end gateway 112, so that the file to be signed does not leave the local network and the risk of being intercepted is reduced. The API front-end gateway authenticates the signature front-end gateway 112 using the authentication parameters. After the authentication is passed, the hash value to be signed and the seal information are passed to the electronic signature system 122. The electronic signature system 122 can extract the file to be signed after verifying the hash value to be signed (similar to the principle of file encryption and decryption); or the hash value to be signed, the file to be signed, and the seal information can be sent to the electronic signature system 122 together. After the electronic signature system 122 verifies the hash value to be signed and passes the verification, it will directly perform the signature operation on the file to be signed. It is understandable that, in addition to the hash algorithm, other algorithms may also be used for the verification value of the file to be signed, and the embodiments of the present application are not limited thereto.

[0063] It can be seen that the API front-end gateway realizes the gateway authentication on the user business system side, which improves the security of transmission.

[0064] In some embodiments of the present application, S310 may include: calculating the seal information to obtain a calculation result; and converting data at a preset position in the calculation result to obtain the storage location.

[0065] For example, in some embodiments of the present application, the electronic signature system 122 adopts Figure 2 The method embodiment shown calculates the seal private key to be stored in the same manner as the number, calculates the seal information to obtain a calculation result, and converts the relevant data in the calculation result to obtain the storage location of the seal private key.

[0066] In some embodiments of the present application, the preset position is the last i digits in the calculation result, where i is a positive integer; S310 may include: converting the data corresponding to the last i digits in the calculation result into decimal data to obtain the storage position.

[0067] For example, in some embodiments of the present application, the electronic signature system 122 performs an HMAC operation on information such as the seal name and seal number to obtain a calculation result, and intercepts the last i digits of the calculation result (as a specific example of a preset position), converts the intercepted i digits into decimal, and obtains the storage location of the private key corresponding to the seal.

[0068] S320: Obtain the private key from the storage location, and use the private key to sign the file to be signed to obtain a signed file.

[0069] For example, in some embodiments of the present application, the electronic signature system 122 can read the private key from the dedicated cryptographic device corresponding to the storage location. After obtaining the public and private keys of the seal, the hash value of the file to be signed transmitted by the API front-end gateway is calculated to obtain the signed file.

[0070] S330: Send the signed file to the business system side through the front-end gateway.

[0071] For example, in some embodiments of the present application, the signed file is transmitted back to the signature front gateway 112 through the API front gateway, and the signature front gateway 112 converts the signed file into a set format file (for example, a base64 file) and returns it to the business system 111 to complete the signing operation. It should be understood that the signed file can be securely transmitted under encryption. After receiving the set format file corresponding to the signed file, the business system 111 can verify it to determine that it has not been tampered with during the transmission process. For example, the electronic signature system 122 will calculate the verification value and store it in the signed file. The business system 111 can calculate the verification value of the set format file and determine that it is consistent with the signed file, so that it can be known that the file has not been tampered with.

[0072] Through some of the above-mentioned embodiments of the present application, it can be known that in the application of a private key controllable and extensible electronic signature provided by the present application, the private key and the public key are stored separately, used in combination, and can be quickly expanded. This application can achieve rapid expansion when business data grows rapidly, and ensure the security of storage and use. The method adopts a random storage method for private keys, and completes the storage and use of private keys through algorithms; by storing public keys and private keys separately, it ensures that the seal is authentic and valid during use and is not tampered with. When storing private keys, there is no need to save the need to store private keys or related identifications. Calculations are performed based on the seal number and name to determine the server and location for storing the corresponding seal private key. If you want to expand the storage of private keys, you can directly add a server, store the seal on the cloud service platform through an algorithm, and randomly store the corresponding private key in a dedicated cryptographic device, which is highly flexible.

[0073] The following is combined with Figure 4The specific process of electronic signature application provided by some embodiments of the present application is exemplified.

[0074] Please see the attached Figure 4 , Figure 4 A flowchart of a method for applying an electronic signature is provided for some embodiments of the present application.

[0075] The above process is explained below as an example.

[0076] S400: The electronic signature system obtains seal production information of the seal to be stored.

[0077] S410: Based on the name and number of the seal to be produced, obtain the storage location address of the seal private key to be stored.

[0078] S420: Store the seal private key to be stored in a private key storage device corresponding to the storage location address.

[0079] S430, the business system sends the document to be signed and the seal information to the signature front-end gateway.

[0080] S440: The pre-signing gateway calculates the file to be signed to obtain a verification value of the file to be signed.

[0081] S450, the signature front gateway sends the verification value of the document to be signed, the document to be signed, the seal information and the authentication data to the API front gateway.

[0082] S460, after the API front-end gateway confirms that the authentication data has passed the verification, it sends the verification value of the document to be signed and the seal information to the electronic signature system.

[0083] S470: After determining that the checksum of the document to be signed passes the verification, the storage location of the electronic seal private key is determined based on the seal information, and the private key is read.

[0084] S480: Use the private key to sign the document to be signed, and obtain the signed document.

[0085] S490: Send the signed document to the business system through the API front-end gateway and the signature front-end gateway.

[0086] It can be understood that the specific implementation process of S400 to S490 can refer to the method embodiment provided above. To avoid repetition, some descriptions are omitted here.

[0087] As can be seen from some of the above-mentioned embodiments of this application, this application stores the private key of the electronic seal in a dedicated cryptographic device, which not only complies with relevant regulations but also achieves the trustworthiness, security, and scalability of the electronic signature system. This application can be applied to the centralized storage of large quantities of electronic seals, solving the problems of decentralized construction of electronic signatures, high costs, and difficult maintenance. By using the method of this application to store the key of the electronic seal, there is no need for the relevant identification of the key, which enhances the overall security of the system and ensures the security and rapid expansion of the key.

[0088] Please refer to Figure 5 , Figure 5 The following is a block diagram illustrating the components of an electronic signature application device provided in some embodiments of the present application. It should be understood that the electronic signature application device corresponds to the aforementioned method embodiment and is capable of executing each step involved in the aforementioned method embodiment. The specific functions of the electronic signature application device can be found in the description above, and a detailed description is omitted here to avoid repetition.

[0089] Figure 5 The device for electronic signature application includes at least one software functional module that can be stored in a memory in the form of software or firmware or solidified in the device for electronic signature application. The device for electronic signature application includes: a determination module 510, which is configured to determine the storage location for storing the electronic seal private key based on the seal information in the information to be signed after obtaining the information to be signed from the business system side; wherein the information to be signed includes: a verification value of the file to be signed and seal information, the verification value of the file to be signed is obtained by calculating the file to be signed, the seal information includes a seal name and a seal number, and the storage location is any one of a plurality of dedicated cryptographic devices; a signature module 520, which is configured to obtain the private key from the storage location, and use the private key to sign the file to be signed to obtain a signed file; a transmission module 530, which is configured to send the signed file to the business system side through a front-end gateway.

[0090] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working process of the device described above can refer to the corresponding process in the aforementioned method, and will not be described in detail here.

[0091] Some embodiments of the present application further provide a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, can implement the operations corresponding to any of the above methods provided in the above embodiments.

[0092] Some embodiments of the present application further provide a computer program product, which includes a computer program, wherein when the computer program is executed by a processor, it can implement the operations corresponding to any of the above methods provided in the above embodiments.

[0093] like Figure 6 As shown, some embodiments of the present application provide an electronic device 600, which includes: a memory 610, a processor 620, and a computer program stored in the memory 610 and executable on the processor 620, wherein the processor 620 can implement a method as described in any of the above embodiments when reading the program from the memory 610 through the bus 630 and executing the program.

[0094] Processor 620 can process digital signals and can include various computing architectures, such as a complex instruction set computer architecture, a reduced instruction set computer architecture, or an architecture that implements a combination of multiple instruction sets. In some examples, processor 620 can be a microprocessor.

[0095] The memory 610 can be used to store instructions executed by the processor 620 or data related to the execution of instructions. These instructions and / or data may include code for implementing some or all functions of one or more modules described in the embodiments of this application. The processor 620 of the embodiment of the present disclosure can be used to execute the instructions in the memory 610 to implement the method shown above. The memory 610 includes dynamic random access memory, static random access memory, flash memory, optical storage, or other memory known to those skilled in the art.

[0096] The foregoing is merely an embodiment of the present application and is not intended to limit the scope of protection of the present application. Various modifications and variations are possible for those skilled in the art. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present application shall be included within the scope of protection of the present application. It should be noted that similar reference numerals and letters represent similar items in the following figures. Therefore, once an item is defined in one figure, it does not need to be further defined or explained in subsequent figures.

[0097] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.

[0098] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply the existence of any such actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or device comprising the element.

Claims

1. A method for applying an electronic signature, characterized in that: include: After obtaining the information to be signed from the business system, determining a storage location for storing the electronic seal private key based on the seal information in the information to be signed; wherein the information to be signed includes: a check value of the document to be signed and seal information, the check value of the document to be signed being obtained by calculating the document to be signed, the seal information including a seal name and a seal number, and the storage location is any one of a plurality of dedicated cryptographic devices; Obtaining the private key from the storage location, and using the private key to sign the file to be signed to obtain a signed file; The signed file is sent to the business system side through the front-end gateway.

2. The method according to claim 1, wherein The determining of a storage location for storing the electronic seal private key based on the seal information in the information to be signed includes: Calculating the seal information to obtain a calculation result; The data at the preset position in the calculation result is converted to obtain the storage position.

3. The method according to claim 2, wherein The preset position is the last i digits in the calculation result, where i is a positive integer; wherein converting the data at the preset position in the calculation result to obtain the storage position includes: The data corresponding to the last i bits in the calculation result are converted into decimal data to obtain the storage location.

4. The method according to any one of claims 1 to 3, wherein Before determining the storage location for storing the electronic seal private key based on the seal information in the information to be signed, the method further includes: Receive the information to be signed sent by the application interface front-end gateway; wherein, the application interface front-end gateway verifies the authentication data sent by the signature front-end gateway and then sends the information to be signed; the verification value of the file to be signed is obtained by the signature front-end gateway after calculating the file to be signed on the business system side.

5. The method according to any one of claims 1 to 3, wherein Before obtaining the information to be signed from the business system, the method further includes: Acquire seal production information of the seal to be stored, wherein the seal production information includes: a mold, a name of the seal to be produced, a number of the seal to be produced, and production information; Based on the name of the seal to be made and the number of the seal to be made, obtaining the storage location address of the seal private key to be stored; The seal private key to be stored is stored in a private key storage device corresponding to the storage location address, wherein the private key storage device is any one of the multiple dedicated cryptographic devices.

6. The method according to claim 5, wherein The step of obtaining the storage location address of the seal private key to be stored based on the name of the seal to be made and the number of the seal to be made includes: Performing an operation on the name of the seal to be produced and the number of the seal to be produced to obtain a key value; The data at the preset position in the key value is converted into a decimal number to obtain the storage location address.

7. A device for electronic signature application, characterized in that: include: The determination module is configured to, after obtaining the information to be signed from the business system, determine a storage location for storing the electronic seal private key based on the seal information in the information to be signed; wherein the information to be signed includes: a check value of the document to be signed and the seal information, the check value of the document to be signed being obtained by calculating the document to be signed, the seal information including the seal name and the seal number, and the storage location is any one of a plurality of dedicated cryptographic devices; a signing module configured to obtain the private key from the storage location and use the private key to sign the file to be signed to obtain a signed file; The transmission module is configured to send the signed file to the business system side through the front-end gateway.

8. A system for electronic signature application, characterized in that: include: Business system side, signature front-end gateway, application interface front-end gateway and electronic signature system; The business system side is used to send the original document and seal information to the signature front-end gateway, and the seal information includes the seal name and seal number; The signature front-end gateway is used to calculate the original document to obtain the document to be signed; wherein the document to be signed and the seal information constitute the information to be signed; and send the information to be signed and the authentication data to the application program interface front-end gateway; The application program interface front-end gateway is used to receive the information to be signed and the authentication data, and after confirming that the verification result of the authentication data is passed, send the information to be signed to the electronic signature system; The electronic signature system is used to determine the storage location for storing the electronic seal private key based on the seal information in the information to be signed; obtain the private key from the storage location, and use the private key to sign the file to be signed to obtain a signed file; wherein, the storage location is any one of multiple dedicated cryptographic devices, and the signed file is used to be transmitted to the business system side.

9. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, wherein the computer program is executed by a processor to perform the method according to any one of claims 1 to 6.

10. An electronic device, characterized in that: The method comprises a memory, a processor, and a computer program stored in the memory and running on the processor, wherein the computer program executes the method according to any one of claims 1 to 6 when being run by the processor.

Citation Information

Patent Citations

  • Block chain-based data processing method and apparatus

    CN113327142A

  • Secure electronic signature and verification method based on preposed gateway

    CN118118275A