A secure method for generating electronic signatures based on multi-factor authentication

Through the dynamic adjustment of multi-factor authentication and path index chain, the shortcomings of existing electronic signature technology in dynamic authentication and permission control have been solved, and higher security and traceability have been achieved, and the flexibility and robustness of the signature system have been improved.

CN120433935BActive Publication Date: 2025-09-02JIANGSU SMART DIGITAL CERTIFICATION CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510933962.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-07-08
Publication Date
2025-09-02
Estimated Expiration
2045-07-08

AI Technical Summary

Technical Problem

In the face of cyber attacks and account theft, existing electronic signature technology lacks dynamic identity verification, behavior status tracking and permission inheritance control capabilities, resulting in insufficient security.

Method used

The multi-factor authentication mechanism is adopted to calculate the stability transfer coefficient and path index chain, dynamically adjust the verification path, combine the user's historical behavior characteristics, generate the signature permission level, and bind the signature chain tracking structure to realize real-time evaluation of the identity factor behavior status and flexible control of permissions.

Benefits of technology

It improves the security and attack resistance of the electronic signature system, has good signature traceability and asymmetric verification capabilities, reduces the risk of human configuration errors, and enhances the flexibility of permission control and the robustness of verification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120433935B_ABST
    Figure CN120433935B_ABST
Patent Text Reader

Abstract

The present invention discloses a method for securely generating an electronic signature based on multi-factor identity authentication, and relates to the technical field of signature generation. The method includes: based on the user's historical identity authentication behavior, statistics of various identity factor parameters, calculation of stability transfer coefficient, and formation of an initial verification path index chain; identification of identity factor status, generation of behavior state sequence, and construction of signature authority level through a preset mapping table; triggering state rollback based on the identity factor behavior state sequence, updating the verification path index chain and signature authority level; if the new level has an inheritance relationship with the historical level, marking the current signature as generated by state migration; generating a path state summary and binding it to a signature structure; if it is generated by state migration, extracting the last signature identifier, and jointly constructing a signature chain tracking structure with the path state summary. The present invention has good signature traceability and asymmetric verification capabilities, which is convenient for later auditing and evidence collection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of signature generation, and in particular to a method for securely generating an electronic signature based on multi-factor identity authentication. Background Art

[0002] With the acceleration of digital office processes, electronic signature technology has become a crucial tool for ensuring document authenticity and legal validity in a variety of industries, including government, finance, and healthcare. Traditional electronic signatures primarily rely on single identity authentication mechanisms (such as account passwords and mobile phone verification codes) for verification. While these mechanisms offer strong security, they still face security risks such as forgery, tampering, and illegal use in scenarios prone to cyberattacks and account theft. In particular, practical application requirements such as continuous signatures, inherited authority control, and behavioral consistency verification lack adaptability, traceability, and dynamic update capabilities for electronic signatures.

[0003] CN119397609B discloses a method for generating and verifying electronic signatures. This method generates first signature information from an initial file, and through multi-layered nested signature operations and a trusted timestamp mechanism, ultimately forms a target file embedded with multi-level signature information. This method can, to a certain extent, enhance the signature's tamper-proof and anti-counterfeiting capabilities. However, this method focuses on the hierarchical encapsulation and time-node recording of document content during the signing process. It does not dynamically analyze the signing user's identity verification path, lacks modeling and utilization of the evolution of identity factor behavior states, and is particularly unable to dynamically modify and inherit the current identity state through historical signing behavior. This results in insufficient signature security protection capabilities in the face of identity drift and non-static scenarios.

[0004] CN115618805A proposes a self-service electronic signature generation system and method that can automatically identify the signature area and perform security verification of the signature scenario. This method improves the convenience of signing, is applicable to multiple signing scenarios, and also strengthens the security verification during the signing operation to a certain extent. However, the identity verification mechanism still focuses on static verification or scenario matching, lacks the quantification and utilization of the stability of user historical behavior, and does not address the dynamic priority sorting of identity verification paths. It cannot achieve the generation of a status summary of the verification path and deep binding with the signature structure, and it is even more impossible to construct a signature chain structure for the traceability of signature behavior. Summary of the Invention

[0005] In view of the problem that the existing technology cannot effectively realize the dynamic update of authentication path, behavior status tracking and permission inheritance control, the present invention is proposed.

[0006] Therefore, the problem to be solved by the present invention is how to significantly improve the security and anti-attack capability of the electronic signature system through a multi-factor identity authentication mechanism combined with user historical behavior characteristics.

[0007] In order to solve the above technical problems, the present invention provides the following technical solutions:

[0008] In the first aspect, the present invention provides a method for securely generating electronic signatures based on multi-factor authentication, which includes: based on the user's historical authentication behavior, separately counting the parameters of each identity factor, calculating the stability transfer coefficient, and forming an initial verification path index chain from high to low; based on the initial verification path index chain, performing state identification on each identity factor in the current session, generating an identity factor behavior state sequence, and constructing a corresponding signature authority level based on a preset factor combination level mapping table; triggering state rollback based on the identity factor behavior state sequence, updating the verification path index chain and the signature authority level; if there is an inheritance mapping relationship between the updated signature authority level and the historical signature level, marking the current signature session as being generated based on the state migration of the previous signature session; generating a path state summary for the verification path index chain, and binding it to the summary field of the current signature structure; if the current signature session is generated based on the state migration of the previous signature session, extracting the previous signature session identifier, and constructing a signature chain tracking structure together with the path state summary.

[0009] As a preferred solution of the electronic signature security generation method based on multi-factor authentication of the present invention, the calculation process of the stability transfer coefficient includes: extracting the verification status of each identity factor in different sessions based on the user's historical session data, and constructing the identity factor behavior state sequence matrix , the elements in the matrix are In each identity factor behavior state sequence, a fixed-length sliding window is applied for segmented processing. In each sliding window, the total number of state transition events is calculated, and the transition density of the corresponding segment is obtained using the sliding window time length as the denominator. The time weighting factor is calculated and weighted summed with the transition density of each segment to calculate the drift penalty coefficient of the identity factor. The historical failure rate of each identity factor is calculated by dividing the number of valid verifications by the number of failed attempts. The stability transfer coefficient is calculated using the drift penalty coefficient and the historical failure rate.

[0010] As a preferred solution of the method for securely generating an electronic signature based on multi-factor authentication described in the present invention, the calculation of the stability transfer coefficient through the drift penalty coefficient and the historical failure rate includes: multiplying the drift penalty coefficient and the historical failure rate by the corresponding weight coefficient respectively, adding them to the constant 1, and taking the inverse as the stability transfer coefficient.

[0011] As a preferred solution of the method for securely generating an electronic signature based on multi-factor authentication of the present invention, the state identification of each identity factor in the current session includes: selecting the state of the corresponding identity factor in the most recent The multi-dimensional behavioral features extracted from the complete historical sessions are used to construct a high-dimensional behavioral confidence envelope based on statistical distribution. is a constant; the key behavioral features of the identity factor are extracted in the current session as the input feature group, and compared with the high-dimensional behavioral confidence envelope. If the Euclidean distance deviation of the input feature group exceeds the preset distance threshold, it is determined that the identity factor has drifted, and the drift label is set to ,otherwise ; Count the number of times the corresponding identity factor is marked as drifted or not drifted in multiple historical sessions, and use the majority voting principle to select the label value with the highest frequency as the historical dominant label; if the number of occurrences is the same, the most recent label is preferred; set the label consistency label , if the drift label in the current session is consistent with the historical dominant label, then +1; if the two are inconsistent, then .

[0012] As a preferred solution of the method for securely generating an electronic signature based on multi-factor authentication of the present invention, the generating of the identity factor behavior state sequence includes: performing each identity factor In pairs, a double-label sequence is finally formed. According to the stability transfer coefficient corresponding to each identity factor, the top M identity factors with the highest stability transfer coefficient are selected, and the corresponding behavior state structure is extracted from the double-label sequence to construct a valid identity factor behavior state sequence, where: is a constant.

[0013] As a preferred solution of the method for securely generating an electronic signature based on multi-factor authentication of the present invention, the triggering of the state rollback flag includes: extracting all the elements that meet the requirements in the identity factor behavior state sequence. and The identity factor of , constitutes a drift factor set, and extracts all the factors that satisfy and The identity factors of the session are used to form a drift factor set; the number of elements in the drift factor set is counted and the ratio is calculated with the total number of identity factors in the identity factor behavior state sequence to obtain a drift density index; if the drift density index is greater than the drift threshold, the current session trigger state rollback flag is marked.

[0014] As a preferred solution of the method for securely generating an electronic signature based on multi-factor identity authentication described in the present invention, the updating of the verification path index chain includes: if the state rollback flag is triggered, the verification path index chain is updated and generated: the identity factors in the non-drift factor set are sorted in descending order according to the corresponding stability transfer coefficients to form a priority verification sub-path, and used as the head of the path chain; the initial verification path index chain is traversed, all identity factors belonging to the drift factor set are eliminated, and the relative order in the initial verification path index chain is maintained and appended to the end of the priority verification sub-path to form a rearranged verification path index chain.

[0015] As a preferred solution of the electronic signature security generation method based on multi-factor authentication of the present invention, wherein: generating a path status summary for the verification path index chain and binding it to the summary field of the current signature structure includes: extracting the stability transfer coefficient set of the corresponding identity factor based on the updated verification path index chain, and normalizing it to generate a stability fingerprint vector; according to the stability of each identity factor Represented in pairs, combined with the index order in the verification path index chain, a path state vector is generated; the stability fingerprint vector and the path state vector are input into the preset path summary hash compression function to generate a path state summary code, and the generated path state summary code is written into the summary field of the current signature structure.

[0016] In a second aspect, the present invention provides a computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: when the computer program instructions are executed by the processor, the steps of the method for securely generating an electronic signature based on multi-factor authentication as described in the first aspect of the present invention are implemented.

[0017] In a third aspect, the present invention provides a computer-readable storage medium having a computer program stored thereon, wherein: when the computer program instructions are executed by a processor, the steps of the method for securely generating an electronic signature based on multi-factor authentication as described in the first aspect of the present invention are implemented.

[0018] The beneficial effects of the present invention are as follows: by constructing a stability transfer coefficient and a path index chain, and dynamically adjusting the verification path structure, the present invention can evaluate the identity credibility level in real time according to the user's actual behavior status, thereby effectively preventing risks such as impersonation and forgery; at the same time, the dynamic mapping mechanism of the signature authority level and the identity status enables flexible authority control capabilities, and can automatically upgrade or downgrade the signature authority according to the current identity factor performance, effectively reducing the risks brought by human configuration errors; in addition, through the binding of the signature chain tracking structure and the path status summary, the present invention has good signature traceability capabilities and asymmetric verification capabilities, which is convenient for later auditing and evidence collection. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0020] Figure 1 A flowchart of a method for securely generating an electronic signature based on multi-factor authentication;

[0021] Figure 2 Flowchart for calculating the stability transfer coefficient in the secure generation method of electronic signature based on multi-factor authentication. DETAILED DESCRIPTION

[0022] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, the specific embodiments of the present invention are described in detail below with reference to the accompanying drawings.

[0023] In the following description, many specific details are set forth to facilitate a full understanding of the present invention. However, the present invention may also be implemented in other ways different from those described herein. Those skilled in the art may make similar generalizations without violating the connotation of the present invention. Therefore, the present invention is not limited to the specific embodiments disclosed below.

[0024] Secondly, the term "one embodiment" or "embodiment" herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation of the present invention. The phrase "in one embodiment" appearing in various places throughout this specification does not necessarily refer to the same embodiment, nor does it refer to a separate or selective embodiment that is mutually exclusive of other embodiments.

[0025] As mentioned in the background technology above, traditional electronic signatures primarily rely on single identity authentication mechanisms (such as account passwords and mobile phone verification codes) for identity verification. While these mechanisms offer strong security, they still face security risks such as forgery, tampering, and illegal use in scenarios prone to cyberattacks and account theft. In particular, for practical applications such as continuous signatures, inherited authority control, and behavioral consistency verification, there is a lack of electronic signature methods that are adaptable, traceable, and dynamically updateable.

[0026] Figure 1 FIG is a flow chart of a method for securely generating an electronic signature based on multi-factor authentication according to an embodiment of the present invention. Figure 1 As shown, the method for securely generating an electronic signature based on multi-factor authentication includes:

[0027] S1: Based on the user's historical identity authentication behavior, the parameters of each identity factor are counted separately, the stability transfer coefficient is calculated, and the initial verification path index chain is formed from high to low.

[0028] In the embodiment of the present invention, Figure 2 As shown, the calculation of the stability transfer coefficient includes the following steps:

[0029] First, based on the user's historical session data, the verification status of each identity factor in different sessions is extracted to construct the identity factor behavior state sequence matrix , the elements in the matrix are ,in, 、 、 Indicates success, failure, and missing respectively.

[0030] In each identity factor behavior state sequence, a fixed-length sliding window is applied for segmentation processing. In each sliding window, the total number of state jump events is calculated, and the time length of the sliding window is used as the denominator to obtain the jump density of the corresponding segment, which is used to characterize the state change frequency per unit time. The above operation can capture the local volatility characteristics of the identity factor state change, and has a higher change sensitivity than the overall statistical method.

[0031] In order to enhance the reference value of recent behavior, a time weighting factor is calculated. The time weighting factor adopts an exponential decay form and is weighted summed with the jump density to calculate the drift penalty coefficient of each identity factor.

[0032] Furthermore, to comprehensively measure the stability of identity factors, the historical failure rate is calculated by dividing the number of failed attempts by the number of valid verifications for each identity factor. The drift penalty coefficient and the historical failure rate are each multiplied by their corresponding weight coefficients, added to a constant of 1, and the reciprocal is taken to form the stability transfer coefficient. For example, if the drift penalty coefficient is 0.2, the historical failure rate is 0.1, and the weight coefficients are 2 and 3, respectively, the stability transfer coefficient is approximately 0.588, indicating that this identity factor has a certain drift and failure history, and will be ranked lower in subsequent verification paths.

[0033] Finally, all identity factors are sorted in descending order according to their stability transfer coefficients to generate an initial verification path index chain.

[0034] As can be seen, this invention can pre-identify factors with unstable behavior characteristics during the user identity verification process, providing a pre-judgment basis for path planning, thereby effectively reducing the impact of abnormal factors on the overall stability of the system during the verification process. Furthermore, it quantifies the historical dynamic trends of user behavior, helping to improve the sensitivity and accuracy of identity judgments, and providing greater adaptability and anti-interference capabilities in handling high-frequency conversations or frequently changing behavior scenarios.

[0035] S2: Based on the initial verification path index chain, identify the status of each identity factor in the current session, generate an identity factor behavior state sequence, and construct the corresponding signature authority level based on the preset factor combination level mapping table.

[0036] In an embodiment of the present invention, generating the identity factor behavior state sequence includes the following steps:

[0037] To determine the status of the identity factor in the current session, the present invention has extracted local jump density features and formed a stability transfer coefficient based on the single historical behavior sequence of each identity factor in S1 through a fixed-length sliding window. In this step, in order to determine the degree of deviation between the current identity status and historical behavior, the session-level sliding aggregation window is used, that is, the corresponding identity factor is selected in the recent The key behavioral features in the complete historical session (including activation frequency, response delay, operation duration, jump density, etc.) are used to construct a high-dimensional behavioral confidence envelope based on statistical distribution (for example, these historical features are formed into a high-dimensional behavioral sample set, and the mean and standard deviation are calculated in the feature space).

[0038] The key behavioral features of the identity factor are extracted in the current session as the input feature group, and compared with the above high-dimensional behavioral confidence envelope. If the Euclidean distance deviation of the input feature group exceeds the preset distance threshold, it is determined that the identity factor has drifted, and the drift label is set to ,otherwise It should be noted that The length of the historical lookback window is adjustable, with a default setting of 5 to 10, and will be dynamically adjusted with the frequency of changes in user behavior; the high-dimensional behavior confidence envelope is constructed based on the historical mean and standard deviation of each dimensional feature.

[0039] In addition, in order to improve the stability and context continuity of drift judgment, we further count the number of times the corresponding identity factor is marked as drifted or not drifted in multiple historical sessions, and adopt the majority voting principle to select the label value with the highest frequency as the historical dominant label; if the number of occurrences is the same, the most recent label is preferred; set the label consistency label ,If the drift label in the current session is consistent with the historical dominant label, it means that the current behavior pattern continues the historical trend, and thus the identity factor behavior is determined to be stable, that is, +1; if the two are inconsistent, it will be recorded as a state mutation behavior, then .

[0040] Finally, each identity factor is In pairs, a double-label sequence is finally formed, which is helpful for subsequent judgment of abnormal identity behavior. According to the stability transfer coefficient corresponding to each identity factor, the identity factors with the highest stability transfer coefficients are selected, and the corresponding behavior state structure is extracted from the double-label sequence to construct a valid identity factor behavior state sequence. is a constant.

[0041] Furthermore, the signature authority level corresponding to the current behavior is derived based on a preset factor combination level mapping table.

[0042] It should be noted that the present invention achieves a precise match between identity behavior and authority level, can flexibly adjust operating permissions according to changes in identity status, improve the security and compliance of business processes, and when facing complex or dynamic identity scenarios, can support more fine-grained risk management and control strategies, thereby improving adaptability.

[0043] S3: Trigger state rollback based on the identity factor behavior state sequence, update the verification path index chain and signature authority level; if the updated signature authority level has an inheritance mapping relationship with the historical signature level, mark the current signature session as a state migration generated based on the previous signature session.

[0044] In the embodiment of the present invention, in the identity factor behavior state sequence, all the elements that satisfy and The identity factor of , constitutes a drift factor set, and extracts all the factors that satisfy and The identity factors of the session are used to form a drift factor set; the number of elements in the drift factor set is counted and the ratio is calculated with the total number of identity factors in the identity factor behavior state sequence to obtain a drift density index; if the drift density index is greater than the drift threshold, the current session trigger state rollback flag is marked;

[0045] The initial verification path index chain is constructed by sorting the stability transfer coefficients of all identity factors in descending order. If the current state meets the fallback flag condition, the path update operation is triggered and the chain is re-sorted according to the following two types of identity factors:

[0046] The identity factors in the non-drift factor set are sorted in descending order according to the corresponding stability transfer coefficients to form a priority verification sub-path, which serves as the head of the path chain; then, the initial verification path index chain is traversed, all identity factors belonging to the drift factor set are eliminated, and the relative order in the initial verification path index chain is maintained and appended to the tail of the aforementioned priority verification sub-path to form a rearranged verification path index chain.

[0047] It can be seen that the strategy of the present invention is essentially an identity factor path rearrangement mechanism. On the premise of retaining the original path element structure, it prioritizes improving the leading position of the trusted identity factor in the verification process, reducing the probability of interference of the drift risk factor on the initial judgment result, thereby enhancing the anti-interference and dynamic adaptability of the entire verification sequence.

[0048] The merged verification path index chain replaces the initial verification path index chain for subsequent verification control strategy execution.

[0049] If the current signature behavior is the first session, that is, there is no historical signature behavior record, the inheritance relationship determination process is skipped, and the signature permission level is directly generated based on the current identity factor behavior state sequence, and the inheritance flag is set; otherwise, if there is a historical signature record, the current signature permission level is compared with the previous signature level, and the judgment is made based on the following inheritance mapping relationship:

[0050] First, define the change direction of the permission level pair, which is the difference between the current signature permission level and the previous signature permission level. This is used to quantify the change trend of the current level relative to the previous level.

[0051] Combined with the identity factor behavior state sequence consistency label Drift labels with state response collection

[0052] First: If the level difference is greater than 0, and the mean of the stability transfer coefficients in the current set of un-drifted factors is greater than or equal to the minimum consistency threshold, it means that the authority has been increased;

[0053] If the level difference is equal to 0, it means horizontal migration, which is tentatively considered as possible inheritance;

[0054] If the level difference is less than 0 and the drift density index in the current identity factor behavior state sequence is less than or equal to the maximum tolerable drift threshold, it indicates degraded inheritance.

[0055] Once the inheritance relationship is satisfied, the current signature session is marked as generated based on state migration, and the inheritance flag is set. At the same time, the verification path index chain number, signature authority level and timestamp bound to the previous signature structure are recorded.

[0056] This invention enhances the ability to quickly respond to sudden changes in identity behavior. While ensuring verification continuity and stability, it reduces path deviations and verification interruptions caused by untrusted identity states. Through a rational sequencing update and level recognition mechanism, it maintains the integrity and orderliness of the overall verification structure during path updates, improving the robustness of the verification chain. In scenarios involving multiple roles, multiple terminals, or multiple paths with concurrent signatures, it significantly improves path scheduling efficiency and fault tolerance, enhancing operational flexibility and security boundary control.

[0057] S4: Generate a path status summary for the verification path index chain and bind it to the summary field of the current signature structure; if the current signature session is generated based on the state migration of the previous signature session, extract the previous signature session identifier and construct the signature chain tracking structure together with the path status summary.

[0058] In the embodiment of the present invention, based on the updated verification path index chain, the stability transfer coefficient set of the corresponding identity factor is extracted and normalized to generate a stability fingerprint vector; The pairwise representation is combined with the index order in the verification path index chain to generate a path state vector; the stability fingerprint vector and the path state vector are sequentially spliced ​​according to the factor index order in the verification path index chain, and the spliced ​​structure is converted into a standard byte stream format through a serialization operation, and a preset path summary hash compression function (such as the Blake2b hash function, which is not limited to the embodiment of the present invention) is input to generate a path state summary code.

[0059] Furthermore, the generated path status summary code is written into the summary field of the current signature structure and bound to the current verification path index chain number and timestamp. It should be noted that this summary result has the ability to identify path uniqueness and stability redundancy, and embeds a timestamp to prevent replay attacks.

[0060] If the current signing session is generated based on the state transition of the previous signing session, the signature chain tracking structure is further constructed based on the previous signing session information and the current path state summary. The construction logic is as follows:

[0061] Extract the unique identifier of the previous signature session from the previous session structure, and input the identifier code, the current summary code, the time difference between the two signatures, and the previous summary into the cryptographic hash function to form signature chain association evidence, which is written into the current signature structure to describe the source relationship of the current signature session.

[0062] As can be seen, this invention, by summarizing the authentication path and related behavior states, maintains data simplicity while still maintaining a complete identity chain structure record, thereby enhancing the traceability and non-repudiation of authentication behavior. Furthermore, through the ordered mapping between historical states, the ability to ensure behavioral consistency in continuous sessions or inheritance scenarios is improved, facilitating the continued effectiveness of security policies.

[0063] This embodiment also provides a computer device suitable for the case of a method for securely generating an electronic signature based on multi-factor authentication, comprising a memory and a processor; the memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions to implement the method for securely generating an electronic signature based on multi-factor authentication as proposed in the above embodiment.

[0064] The computer device may be a terminal, comprising a processor, memory, a communication interface, a display, and an input device connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores an operating system and computer programs. The internal memory provides an environment for the operating system and computer programs stored in the non-volatile storage media. The communication interface of the computer device is used to communicate with external terminals via wired or wireless communication. Wireless communication may be achieved via Wi-Fi, a carrier network, NFC (near-field communication), or other technologies. The display of the computer device may be a liquid crystal display or an electronic ink display. The input device may be a touchscreen overlay on the display, buttons, a trackball, or a touchpad on the computer device housing, or an external keyboard, touchpad, or mouse.

[0065] This embodiment further provides a storage medium storing a computer program, which, when executed by a processor, implements the method for securely generating an electronic signature based on multi-factor authentication as proposed in the above embodiment.

[0066] In summary, the present invention constructs a stability transfer coefficient and a path index chain, and dynamically adjusts the verification path structure, so as to evaluate the identity credibility level of the user in real time according to the actual behavior status, thereby effectively preventing risks such as impersonation and forgery; at the same time, the dynamic mapping mechanism of the signature authority level and the identity status enables flexible authority control capabilities, and can automatically upgrade or downgrade the signature authority according to the current identity factor performance, effectively reducing the risks brought by human configuration errors; in addition, through the binding of the signature chain tracking structure and the path status summary, the present invention has good signature traceability capabilities and asymmetric verification capabilities, which is convenient for subsequent auditing and evidence collection.

[0067] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical solutions of the present invention, which should all be included in the scope of the claims of the present invention.

Claims

1. A method for securely generating an electronic signature based on multi-factor authentication, characterized by: include: Based on the user's historical identity verification behavior, the parameters of each identity factor are counted separately, the stability transfer coefficient is calculated, and the initial verification path index chain is formed from high to low; Based on the initial verification path index chain, the status of each identity factor in the current session is identified, an identity factor behavior state sequence is generated, and the corresponding signature authority level is constructed based on a preset factor combination level mapping table; Triggering state rollback based on the identity factor behavior state sequence, updating the verification path index chain and the signature authority level; if there is an inheritance mapping relationship between the updated signature authority level and the historical signature level, marking the current signature session as a state migration generated based on the previous signature session; Generate a path state summary for the verification path index chain and bind it to the summary field of the current signature structure; if the current signature session is generated based on the state migration of the previous signature session, extract the previous signature session identifier and construct a signature chain tracking structure together with the path state summary; The calculation process of the stability transfer coefficient includes: extracting the verification status of each identity factor in different sessions based on the user's historical session data, and constructing the identity factor behavior state sequence matrix , the elements in the matrix are In each identity factor behavior state sequence, a fixed-length sliding window is applied for segmentation processing; in each sliding window, the total number of state jump events is calculated, and the jump density of the corresponding segment is obtained with the time length of the sliding window as the denominator; the time weighting factor is calculated, and the weighted sum is taken with the jump density of each segment to calculate the drift penalty coefficient of the identity factor; the historical failure rate of each identity factor is calculated by dividing the number of failed verifications by the number of valid verifications; the stability transfer coefficient is calculated using the drift penalty coefficient and the historical failure rate; The updating of the verification path index chain includes: if the state rollback flag is triggered, updating and generating the verification path index chain: sorting the identity factors in the non-drift factor set in descending order according to the corresponding stability transfer coefficients to form a priority verification sub-path and serving as the head of the path chain; traversing the initial verification path index chain, eliminating all identity factors belonging to the drift factor set, and appending them to the end of the priority verification sub-path while maintaining their relative order in the initial verification path index chain, to form a rearranged verification path index chain; Generate a path status summary for the verification path index chain and bind it to the summary field of the current signature structure, including: extracting the stability transfer coefficient set of the corresponding identity factor based on the updated verification path index chain, and normalizing it to generate a stability fingerprint vector; based on the stability of each identity factor In pairs, the path state vector is generated by combining the index order in the verification path index chain; the stability fingerprint vector and the path state vector are input into the preset path summary hash compression function to generate a path state summary code, and the generated path state summary code is written into the summary field of the current signature structure.

2. The method for securely generating an electronic signature based on multi-factor authentication according to claim 1, wherein: The calculation of the stability transfer coefficient by using the drift penalty coefficient and the historical failure rate includes: Multiply the drift penalty coefficient and the historical failure rate by the corresponding weight coefficient, add them to the constant 1, and take the reciprocal as the stability transfer coefficient.

3. The method for securely generating an electronic signature based on multi-factor authentication according to claim 1, wherein: The state identification of each identity factor in the current session includes: Select the corresponding identity factor in the nearest The multi-dimensional behavioral features extracted from the complete historical sessions are used to construct a high-dimensional behavioral confidence envelope based on statistical distribution. is a constant; The key behavioral features of the identity factor are extracted in the current session as the input feature group and compared with the high-dimensional behavior confidence envelope. If the Euclidean distance deviation of the input feature group exceeds the preset distance threshold, it is determined that the identity factor has drifted, and the drift label is set to ,otherwise ; Count the number of times the corresponding identity factor is marked as drifted or not drifted in multiple historical sessions, and use the majority voting principle to select the label value with the highest frequency as the historical dominant label; If the number of occurrences is the same, the most recent label is preferred; set the label consistency , if the drift label in the current session is consistent with the historical dominant label, then +1; if the two are inconsistent, then .

4. The method for securely generating an electronic signature based on multi-factor authentication according to claim 3, wherein: Generating the identity factor behavior state sequence includes: Each identity factor is They are expressed in pairs, ultimately forming a double-label sequence; According to the stability transfer coefficient corresponding to each identity factor, select the identity factors with the highest stability transfer coefficients, extract the corresponding behavior state structure from the double-label sequence, and construct the effective identity factor behavior state sequence, where: is a constant.

5. The method for securely generating an electronic signature based on multi-factor authentication according to claim 1, wherein: The triggering of the state rollback flag includes: In the identity factor behavior state sequence, extract all and The identity factor of , constitutes a drift factor set, and extracts all the factors that satisfy and The identity factors of constitute the drift factor set; Count the number of elements in the drift factor set and calculate the ratio with the total number of identity factors in the identity factor behavior state sequence to obtain the drift density index; If the drift density index is greater than the drift threshold, the current session trigger state rollback flag is marked.

6. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method for securely generating an electronic signature based on multi-factor authentication according to any one of claims 1 to 5 are implemented.

7. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method for securely generating an electronic signature based on multi-factor authentication according to any one of claims 1 to 5 are implemented.

Citation Information

Patent Citations

  • A method for generating and verifying an electronic signature

    CN119397609B

  • Electronic file signing method and system for bid inviting and purchasing business

    CN118734329A

  • Electronic signature generation and anti-counterfeiting system based on multi-source information fusion

    CN119885294A