A mobile terminal dynamic key generation method and an electronic signature system
By generating dynamic keys using multi-sensor data and environmental awareness technology on mobile devices, the problems of static keys being vulnerable to attacks and insufficient environmental adaptability in existing electronic signature systems are solved. This achieves a dynamic balance between security and efficiency, enhancing the security and applicability of mobile electronic signatures.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- 广西壮族自治区信息中心
- Filing Date
- 2025-09-03
- Publication Date
- 2026-05-15
AI Technical Summary
Existing electronic signature systems on mobile devices suffer from problems such as static key management being vulnerable to attacks, inability to dynamically adjust security policies, and insufficient environmental adaptability, making it difficult to provide a balance between security and efficiency in complex and ever-changing mobile application environments.
By integrating multi-sensor data from mobile devices with environmental awareness technology, dynamic keys are generated and adaptive security policies are established. Accelerometers, gyroscopes, and magnetometers are used to capture user behavior characteristics, and the security level is adjusted in real time based on the network environment and device status, thereby realizing dynamic key generation and multi-layer key management.
It improves the system's resistance to attacks and security, achieves a dynamic balance between security and efficiency, enhances the reliability of identity authentication and the legal binding force of signatures, and provides flexible security guarantees.
Smart Images

Figure CN121000384B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the technical field of encryption algorithms, and in particular to a method for generating dynamic keys on a mobile device and an electronic signature system. Background Technology
[0002] With the rapid development of digital office and mobile internet technologies, electronic signatures, as a crucial component of digital document processing, have become an indispensable core technology in modern office systems and e-commerce platforms. Electronic signature technology, through digital signatures and encryption algorithms, provides electronic documents with identity authentication, data integrity protection, and non-repudiation guarantees, effectively replacing traditional paper-based document signing methods. Especially against the backdrop of increasingly prevalent mobile office scenarios, the demand for electronic signature applications based on mobile devices has experienced explosive growth, placing higher technical demands on the security, convenience, and adaptability of signature systems.
[0003] Currently, existing electronic signature technologies are mainly based on Public Key Infrastructure (PKI) systems and fixed cryptographic algorithms. For example, patent CN114638009A discloses an electronic signature system applicable to public key cryptography and supporting commercial cryptographic algorithms. This system, through a combination of infrastructure units, user service units, signature management units, and security protection units, implements electronic signature functions based on traditional cryptographic algorithms such as RSA and SM2. The system employs static digital certificates and a fixed key management method, provides signature services through pre-configured technical specifications and cryptographic algorithm modules, and uses blockchain technology for distributed data storage.
[0004] However, existing technologies have many shortcomings and limitations. First, traditional electronic signature systems generally adopt a static key management model, where key generation and distribution rely on preset algorithm parameters and fixed random number generation mechanisms. This lacks dynamic correlation with the actual application environment and user behavior characteristics, making them vulnerable to security threats such as key leakage and replay attacks. Second, the security strategies of existing systems are relatively rigid and cannot dynamically adjust security protection levels according to real-time network environment, device status, and application scenarios. When facing complex and ever-changing mobile application environments, this often results in either over-protection leading to inefficiency or insufficient protection posing security risks. Third, traditional identity authentication mechanisms mainly rely on static identity elements such as usernames, passwords, and digital certificates, lacking the ability to perceive user behavior characteristics and the physical environment, making it difficult to effectively prevent new security threats such as identity forgery and device theft.
[0005] Furthermore, existing mobile electronic signature systems suffer from significant shortcomings in environmental adaptability. The operating environment of mobile devices is highly dynamic and complex, characterized by frequent network connection switching, constantly changing device status, and diverse application scenarios. Traditional electronic signature systems lack the ability to perceive and adaptively adjust to these environmental factors in real time, making it difficult to provide a good user experience while ensuring security. Particularly when handling documents with different security levels and addressing application scenarios with varying risk levels, existing systems have limited policy adjustment capabilities, failing to achieve precise risk control and optimized resource allocation.
[0006] Therefore, there is an urgent need to develop a new type of mobile electronic signature technology that can fully utilize the sensor resources and computing power of mobile devices to achieve dynamic key generation based on physical behavior characteristics, establish intelligent environmental perception and adaptive security mechanisms, and provide a safer, more efficient and intelligent technical solution for electronic signature applications in mobile office environments. Summary of the Invention
[0007] In view of this, the present invention provides a mobile dynamic key generation method and an electronic signature system. The purpose is to establish a dynamic key generation mechanism and adaptive security strategy by integrating multi-sensor data from mobile devices and environmental perception technology, so as to achieve a comprehensive improvement in the security, reliability and applicability of the mobile electronic signature system, and provide a more secure and efficient technical solution for electronic signature applications in mobile office environments.
[0008] To achieve the above objectives, the present invention provides a method for generating dynamic keys on a mobile device, comprising the following steps:
[0009] S1: When a user initiates an electronic signature operation on a mobile device, the system simultaneously activates the multi-sensor data acquisition module to acquire data from various sensors on the mobile device, including accelerometers, gyroscopes, and magnetometers. The system then performs noise filtering and preprocessing on the acquired sensor data to obtain a sensor data matrix.
[0010] S2: Detect the network environment and mobile device status of electronic signature operations, analyze the security level and transmission requirements of signed documents, determine the corresponding security strategy based on the document type and signing mode, and generate an environment assessment parameter matrix.
[0011] S3: Based on the sensor data matrix and environmental assessment parameter matrix, a dynamic key is generated using a data fusion algorithm and hash function. The environmental risk level is assessed, and the dynamic key update frequency and encryption strength parameters are determined to establish an encrypted channel for the signing session.
[0012] S4: Perform electronic signature operations and implement full-process security monitoring, ensuring the authenticity and integrity of the signature through multiple verification mechanisms, and completing the entire electronic signature process.
[0013] As a further improvement of the present invention:
[0014] Optionally, step S1 includes:
[0015] S11: Initialize the signature session and establish a sensor data acquisition channel, and set the sensor data acquisition frequency to 100Hz;
[0016] S12: Collect sensor data including the three-axis acceleration values of the accelerometer, the three-axis angular velocity values of the gyroscope, and the three-axis magnetic field strength values of the magnetometer;
[0017] S13: Use a low-pass filter to smooth the data from each sensor. The cutoff frequency of the low-pass filter is set to 20Hz.
[0018] S14: Calculate the comprehensive change intensity index of sensor data, including the comprehensive intensity of acceleration, the comprehensive intensity of angular velocity, and the comprehensive value of magnetic field strength, to form a sensor data matrix.
[0019] Optionally, step S2 includes:
[0020] S21: Evaluate network environment detection and quantification, and obtain network connection type, signal strength, network bandwidth, network latency and network stability indicators;
[0021] S22: Evaluate the movement state of the mobile device, which includes the movement speed, attitude change rate, and movement stability of the mobile device;
[0022] S23: Analyze the security level of signed documents, assign security level weights according to the document type, and calculate the document complexity index;
[0023] S24: Generate an environment assessment parameter matrix containing 14 environment assessment parameters based on the network environment, the mobility status of mobile devices, and the security level of signed documents.
[0024] Optionally, step S3 includes:
[0025] S31: Sensor data matrix fusion and feature extraction, extracting time-domain and frequency-domain features and combining them into a motion feature vector;
[0026] S32: Based on the environmental assessment parameter matrix, assess the environmental risk level, calculate the network security risk coefficient, mobility risk coefficient, and document security risk coefficient, and obtain the environmental risk level;
[0027] S33: Determine the dynamic key parameters, and set the dynamic key update interval, key length, and hash iteration number according to the environmental risk level;
[0028] S34: Dynamic key generation and encryption channel establishment. The SHA-256 hash function is used to perform multiple iterative operations on the key seed to generate a dynamic key. The motion feature vector, the current timestamp, and the user identity identifier are combined into the key seed.
[0029] Optionally, step S4 includes:
[0030] S41: Pre-verification and authorization confirmation before signing, verifying the legitimacy of the user's identity and the legitimacy of the signing device;
[0031] S42: Dynamic signature data generation and encrypted transmission, generating signature data blocks containing spatiotemporal information, and using a dynamic key to encrypt the signature data using AES-GCM;
[0032] S43: Signature completion confirmation. Verify the correctness of the signature data by decryption and verify the integrity of the decrypted signature data structure.
[0033] Optionally, step S31 includes:
[0034] The time-domain characteristics include the mean characteristics of the triaxial acceleration values, the variance characteristics of the triaxial angular velocity values, and the peak characteristics of the triaxial magnetic field strength values;
[0035] The frequency domain features include the main frequency features of the triaxial acceleration values extracted by performing a Fast Fourier Transform (FFT) on the accelerometer data.
[0036] Optionally, step S42 includes:
[0037] A signature environment fingerprint is generated by using the SHA256 hash function to generate the sensor data matrix, environmental assessment parameter matrix, and dynamic key at the time of signature.
[0038] Construct a complete signature data structure that includes user identity, mobile device identity, signature timestamp, signature geolocation, signature environment fingerprint, and digital signature;
[0039] The signature data is encrypted with AES-GCM using a dynamic key generated based on sensor data, enabling the binding and verification of signature data with the motion status of the mobile device.
[0040] This invention also discloses an electronic signature system, comprising:
[0041] Data acquisition module: When a user initiates an electronic signature operation on a mobile device, the system synchronously activates the multi-sensor data acquisition module to acquire data from various sensors of the mobile device, including accelerometers, gyroscopes, and magnetometers, and performs noise filtering and preprocessing on the acquired sensor data.
[0042] Environment assessment module: Detects the network environment and mobile device status of electronic signature operations, analyzes the security level and transmission requirements of signed documents, and determines the corresponding security strategy based on the document type and signing mode;
[0043] Dynamic key generation module: Based on sensor data matrix and environmental assessment parameter matrix, dynamic keys are generated using data fusion algorithm and hash function. The dynamic key works in conjunction with the root key managed by the server cryptographic machine and the communication key managed by the gateway device. The in conjunction is to combine the dynamic key with the root key using XOR operation, and at the same time, the communication key is used for outer encryption during communication.
[0044] Electronic signature module: Performs electronic signature operations and implements full-process security monitoring. It ensures the authenticity and integrity of the signature through multiple verification mechanisms, and completes the entire electronic signature process.
[0045] Compared with the prior art, the present invention has at least the following beneficial effects:
[0046] This invention utilizes multi-sensor data from mobile devices, such as accelerometers, gyroscopes, and magnetometers, to capture unique motion characteristics and behavioral patterns when a user holds the device. These biophysical characteristics possess strong individual variability and are not easily replicated, providing a natural guarantee of randomness and uniqueness for dynamic key generation. Compared to traditional static key methods, the dynamic keys generated by this invention have spatiotemporal uniqueness. Each signing operation uses a different encryption key, meaning that even if an attacker obtains the key information for a particular operation, it cannot be used for other signing operations. This fundamentally eliminates the security risks associated with key reuse, significantly improving the system's resistance to attacks and overall security level.
[0047] The system in this invention establishes a complete environmental risk assessment system by real-time monitoring of multi-dimensional environmental parameters such as network environment, device mobility status, and document security level. It can dynamically adjust key strength, update frequency, and encryption parameters according to the current security environment. This adaptive mechanism enables the system to automatically upgrade security protection levels in high-risk environments and optimize performance in low-risk environments, achieving a dynamic balance between security and efficiency. Compared with traditional fixed security strategies, the intelligent sensing mechanism of this invention can effectively address the security needs of different application scenarios, avoiding both inefficiency caused by over-protection and security vulnerabilities that may result from insufficient protection, providing more flexible and accurate security for mobile electronic signatures. When optimizing key management, this invention considers the current product form: most keys are generated and managed by server cryptographic devices to ensure high-security storage and distribution; communication keys are generated and managed by gateway devices to support secure network transmission. The mobile-end dynamic key generation mechanism of this invention serves as a supplementary mechanism, integrating with these to form a multi-layered key management system, improving the overall system robustness.
[0048] The system in this invention introduces environmental fingerprinting technology, fusing sensor data, environmental parameters, and a dynamic key at the moment of signing to generate a unique environmental fingerprint, ensuring that each signature has an uncopyable spatiotemporal identifier. Combined with multiple security mechanisms such as user authentication, device legitimacy verification, and digital signature verification, a comprehensive identity authentication and behavior verification system is formed. This anti-counterfeiting technology based on physical environment and behavioral characteristics not only effectively prevents signature forgery and tampering but also provides strong technical evidence for the authenticity of signatures, enhancing the legal binding force of electronic signatures. Attached Figure Description
[0049] Figure 1 This is a flowchart illustrating a mobile terminal dynamic key generation method according to an embodiment of the present invention;
[0050] Figure 2 This is a schematic diagram of the data acquisition module according to an embodiment of the present invention;
[0051] Figure 3 This is a schematic diagram of the environmental assessment module flow according to an embodiment of the present invention;
[0052] Figure 4 This is a schematic diagram of the dynamic key generation module according to an embodiment of the present invention;
[0053] Figure 5 This is a flowchart illustrating the electronic signature module according to an embodiment of the present invention. Detailed Implementation
[0054] The present invention will be further described below with reference to the accompanying drawings, but this is not intended to limit the present invention in any way. Any modifications or substitutions made based on the teachings of the present invention shall fall within the protection scope of the present invention.
[0055] Example 1: A method for generating dynamic keys on a mobile device, such as... Figure 1 As shown, it includes the following steps:
[0056] S1: When a user initiates an electronic signature operation on a mobile device, the system simultaneously activates a multi-sensor data acquisition module to acquire data from various sensors on the mobile device, including an accelerometer, gyroscope, and magnetometer. The system then performs noise filtering and preprocessing on the acquired sensor data to obtain a sensor data matrix, such as... Figure 2 As shown:
[0057] S11: Initialize the signature session and establish the sensor data acquisition channel:
[0058] While the user is authenticating their identity, the system acquires real-time data streams from three hardware sensors on the mobile device: accelerometer, gyroscope, and magnetometer. The main purpose of this data is to generate a dynamic key seed that is highly correlated with the signature system, ensuring that the key incorporates user behavior characteristics, thereby improving the authenticity of the signature and its resistance to attacks. The sensor data acquisition frequency is set to 100Hz to obtain raw sensor information.
[0059] S12: Collect sensor data including the three-axis acceleration values of the accelerometer, the three-axis angular velocity values of the gyroscope, and the three-axis magnetic field strength values of the magnetometer;
[0060] For accelerometer data, collect triaxial acceleration values. , , ,in Indicates that the mobile device is In the axial direction in time acceleration components, Indicates that the mobile device is In the axial direction in time acceleration components, Indicates that the mobile device is In the axial direction in time The acceleration components;
[0061] For gyroscope data, collect three-axis angular velocity values. , , ,in Indicates mobile device wrap Axis in time angular velocity components, Indicates mobile device wrap Axis in time angular velocity components, Indicates mobile device wrap Axis in time Angular velocity components;
[0062] For magnetometer data, triaxial magnetic field strength values are collected. , , ,in This indicates the time of the mobile device along the x-axis. The magnetic field strength component, Indicates that the mobile device is In the axial direction in time The magnetic field strength component, Indicates that the mobile device is In the axial direction in time Magnetic field strength components;
[0063] S13: Perform noise filtering and preprocessing:
[0064] A low-pass filter is used to smooth the data from each sensor, and the cutoff frequency of the filter is set to 20Hz.
[0065] For accelerometer data, the filtered data is represented as follows: , , ,in This indicates that the mobile device is in the process of filtering. In the axial direction in time acceleration components, This indicates that the mobile device is in the process of filtering. In the axial direction in time acceleration components, This indicates that the mobile device is in the process of filtering. In the axial direction in time The acceleration components; the gyroscope and magnetometer data are filtered accordingly to obtain... , , and , , ;in , , These represent the mobile device's bypass after filtering, respectively. axis, shaft and Axis in time angular velocity components , , These represent the mobile device after filtering, respectively. axis, shaft and In the axial direction in time Magnetic field strength components;
[0066] S14: Calculate the comprehensive change intensity index of the sensor data, which includes the comprehensive acceleration intensity, comprehensive angular velocity intensity, and comprehensive magnetic field strength value; the comprehensive acceleration intensity... Specifically:
[0067]
[0068] in Indicates time Total acceleration intensity of mobile devices;
[0069] The combined strength of angular velocity Specifically:
[0070]
[0071] in Indicates time Total angular velocity intensity of mobile devices;
[0072] The comprehensive value of the magnetic field strength Specifically:
[0073]
[0074] in Indicates time The total magnetic field strength around the mobile device;
[0075] The processed multi-sensor data is stored in a buffer according to time series, forming a sensor data matrix. The matrix is A two-dimensional array, where 9 represents the number of dimensions of the sensor data, including 3 acceleration components, 3 angular velocity components, and 3 magnetic field strength components. This indicates the number of time points collected.
[0076] It should be noted that this step achieves high-precision device motion state perception through multi-sensor data fusion technology, providing a reliable physical foundation for subsequent dynamic key generation. Compared with traditional single-sensor acquisition methods, this step simultaneously utilizes three different types of sensors—accelerometers, gyroscopes, and magnetometers—to comprehensively capture the device's motion characteristics in three-dimensional space, including linear motion, rotational motion, and changes in the magnetic field environment, forming a complete motion state description system.
[0077] S2: Detects the network environment and mobile device status of electronic signature operations, analyzes the security level and transmission requirements of the signed document, determines the corresponding security policy based on the document type and signing mode, and generates an environment assessment parameter matrix, such as... Figure 3 As shown:
[0078] S21: Evaluation and Quantification of Network Environment:
[0079] Obtain the current network connection type by calling the mobile device's network interface API. ,in The value is One of them; measures the signal strength of a network connection. ,in Indicates the received signal strength indicator value; simultaneously detects network bandwidth. ,in Indicates the currently available network bandwidth;
[0080] Calculate network latency By sending to the specified server Data packets and round-trip time are measured, where Indicates the current network round-trip latency; network stability metrics The standard deviation of network latency was calculated using five consecutive measurements.
[0081]
[0082] in Indicates the first The network latency value measured this time. This represents the average delay value of 5 measurements, and ∑ represents the summation function;
[0083] S22: Assess the mobility status of the mobile device:
[0084] Based on sensor data matrix The device mobility status indicators are calculated, including the device's mobility speed, attitude change rate, and mobility stability; the device mobility speed... Specifically:
[0085]
[0086] in Indicates time The speed at which mobile devices move. Indicates time -1 The movement speed of the mobile device; The sampling time interval;
[0087] The device attitude change rate Specifically:
[0088]
[0089] in Indicates time Rate of change of mobile device posture Indicates time Total angular velocity intensity of mobile devices;
[0090] The stability of the device's movement In order to be in time Centered time window length Standard deviation of the moving speed of internal mobile devices;
[0091] S23: Analyze the security level of signed documents:
[0092] Based on the document type identifier in the document metadata Classify them, among which The possible values include These correspond to contracts, agreements, approval documents, and certificate documents, respectively; a security level weight is assigned to each document type. ,in The corresponding weight value is 0.9. The corresponding weight value is 0.8. The corresponding weight value is 0.7. The corresponding weight value is 0.95;
[0093] Analyze document page count and document size ,in This indicates the total number of pages in the document awaiting signature. Indicates document file size; based on signature mode. Classify them, among which The possible values include These correspond to single-page signatures, multi-page signatures, and signatures across the seam;
[0094] Calculate document complexity metrics :
[0095]
[0096] S24: Generate the environmental assessment parameter matrix:
[0097] Network environment parameters, device mobility status parameters, and document security parameters are integrated into an environmental assessment parameter matrix. =[ , , , , , , , , , , , , , ];
[0098] in for The parameter vector contains 14 environmental assessment parameters, including network type, signal strength, available network bandwidth, network latency, network stability, device movement speed, attitude change rate, movement stability, document type, security level weight, number of document pages, document size, signature mode, and document complexity.
[0099] It should be noted that this step establishes a comprehensive environment-aware and adaptive security policy mechanism, capable of dynamically adjusting the security level of the signing system based on real-time network conditions, device status, and document characteristics. Compared to traditional fixed security policies, this step achieves intelligent and personalized configuration of signing security policies through comprehensive evaluation of multi-dimensional environmental parameters, significantly improving the system's security and applicability.
[0100] This step, through real-time monitoring and quantitative analysis of the network environment, accurately identifies the current network security risk level, including security differences between network types, the impact of signal strength on transmission stability, and the threats to data integrity posed by network latency and stability. This dynamic assessment mechanism based on the network environment enables the system to take appropriate security measures under different network conditions, avoiding the security risks of performing high-risk signing operations in insecure network environments.
[0101] S3: Based on the sensor data matrix and environmental assessment parameter matrix, a dynamic key is generated using a data fusion algorithm and hash function. The environmental risk level is assessed, and the key update frequency and encryption strength parameters are determined. An encrypted channel for the signing session is then established. Figure 4 As shown:
[0102] S31: Sensor Data Fusion and Feature Extraction
[0103] Sensor data matrix Data fusion processing is performed to extract motion feature vectors, which include time-domain and frequency-domain features. The time-domain features include the mean of acceleration data, the variance of angular velocity data, and the peak value of magnetic field data, specifically:
[0104] Mean characteristics of acceleration data Specifically:
[0105]
[0106] Variance characteristics of angular velocity data Specifically:
[0107]
[0108] in , , These represent the filtered windings respectively. Mean value of axial angular velocity, around The mean and angular velocity of the shaft The mean of the axial angular velocity.
[0109] Peak characteristics of magnetic field data Specifically:
[0110]
[0111] in This represents the maximum value of the total magnetic field strength. This represents the minimum value of the total magnetic field strength;
[0112] The frequency domain features include the dominant frequency features of the accelerometer, specifically:
[0113] Perform a Fast Fourier Transform (FFT) on the accelerometer data to extract the dominant frequency component; dominant frequency characteristics of the acceleration data. Specifically:
[0114]
[0115] in The argmax function returns the frequency value corresponding to the maximum amplitude in the FFT transform result;
[0116] Combining time-domain features and frequency-domain features into a motion feature vector :
[0117]
[0118] in The feature vector is 1×4;
[0119] S32: Assess the environmental risk level:
[0120] Based on environmental assessment parameter matrix The environmental risk level is calculated as follows:
[0121] Define network security risk coefficient Calculated based on signal strength and network stability:
[0122]
[0123] in and The network security risk weighting coefficients are α = 0.6 and β = 0.4.
[0124] Define the mobility risk coefficient Calculated based on the equipment's movement status:
[0125]
[0126] in , , This is the weighting factor for the mobility risk coefficient. Let π be the mathematical constant, γ = 0.3, δ = 0.4, and ε = 0.3.
[0127] Define document security risk coefficient Based on document complexity calculation:
[0128]
[0129] Calculate environmental risk level :
[0130]
[0131] according to The numerical range categorizes environmental risk into three levels: LOW_RISK corresponds to... MEDIUM_RISK corresponds to HIGH_RISK corresponds to ;
[0132] S33: Determine the dynamic key parameters:
[0133] The dynamic key update frequency and encryption strength parameters are determined based on the environmental risk level; the key update interval... Based on environmental risk levels:
[0134] when When the level is LOW_RISK, For 60 seconds; when When the level is MEDIUM_RISK, It is 30; when When the level is HIGH_RISK, It lasts for 10 seconds;
[0135] Key length Determined based on the weighting of environmental risk level and document security level:
[0136]
[0137] in Round down; when When, set ;when When, set when When, set ;
[0138] Hash iteration count Determined based on environmental risk level:
[0139]
[0140] S34: Dynamic Key Generation and Encrypted Channel Establishment
[0141] motion feature vector The current timestamp (TIMESTAMP) and the user identifier (USER_ID) are combined to form the key seed. :
[0142]
[0143] Where || represents a data join operation;
[0144] The key seed is hashed multiple times using the SHA-256 hash function to generate a dynamic key. :
[0145]
[0146] in Indicates to conduct This SHA-256 hash operation The generated dynamic key has a length of [length missing]. Bit;
[0147] Furthermore, to optimize key management, the dynamic key generated in this step... Further, the root key is generated and managed with the server cryptographic device. Use XOR operations for combination to enhance security:
[0148]
[0149] in For the enhanced dynamic key;
[0150] Using enhanced dynamic keys An AES encrypted channel is established to provide encryption protection for subsequent signed data transmission; the encrypted channel adopts the AES-GCM mode, in which... As an encryption key, a 128-bit initialization vector IV is also generated for encryption operations; during communication, the channel further uses a communication key generated and managed by the gateway device. External encryption is applied to ensure secure transmission.
[0151] It should be noted that this step innovatively combines multi-sensor motion characteristics with environmental risk assessment, realizing a dynamic key generation mechanism based on physical behavior characteristics. This fundamentally solves the security risks of traditional static keys being easily cracked and copied. By extracting features from sensor data in both the time and frequency domains, this step can capture the unique motion patterns and behavioral habits of users when holding the device. These biophysical characteristics have strong individual variability and are not easily replicated, providing a natural guarantee of randomness and uniqueness for key generation.
[0152] The environmental risk assessment system established in this step can perceive the security environment of the signing operation in real time. Through comprehensive quantitative analysis of network risk, mobile risk, and document risk, the system can intelligently adjust the security strength and update strategy of the key. This adaptive security mechanism enables the system to automatically increase key strength and update frequency in high-risk environments and optimize performance in low-risk environments, achieving a dynamic balance between security and efficiency. This avoids the problems of traditional systems either over-protection leading to inefficiency or insufficient protection resulting in security vulnerabilities.
[0153] S4: Perform electronic signature operations and implement full-process security monitoring, ensuring the authenticity and integrity of the signature through multiple verification mechanisms, and completing the entire electronic signature process, such as... Figure 5 As shown:
[0154] S41: Pre-verification and authorization confirmation before signing:
[0155] Verify user identity legitimacy by comparing the current user's identifier (USER_ID) with the list of authorized signatory users. Perform a match verification:
[0156]
[0157] in Indicates the user's authorization status; when USER_ID exists in the list of authorized users. The value is TRUE, otherwise FALSE.
[0158] Verify the legitimacy of the signing device by checking its unique identifier DEVICE_ID and digital certificate. Validity:
[0159]
[0160] in Indicates the device verification status. This function is used to verify the validity of the device certificate. As a root certificate authority, This is a list of trusted devices; when the legitimacy of the signing device is verified... The value is TRUE, otherwise FALSE.
[0161] Only when and The system will only allow the signature execution phase if all values are TRUE.
[0162] S42: Dynamic signature data generation and encrypted transmission:
[0163] Generate a signature data block containing spatiotemporal information, specifically as follows:
[0164] Signature timestamp Record the precise signing time in Unix timestamp format;
[0165] Signature Location Location data, including latitude, longitude, and altitude, is obtained via GPS or network positioning.
[0166] Signature Environment Fingerprint Generated from the current sensor data matrix and environmental assessment parameter matrix:
[0167]
[0168] in Indicates the time of signing and execution. This is a matrix of sensor data at the moment of signing. A 64-bit environmental fingerprint hash value;
[0169] Construct complete signature data :
[0170]
[0171] in Digital signature of core information using the user's private key:
[0172]
[0173] in This is an RSA digital signature generation function that uses a private key to perform a signature operation on the input hash value, generating a digital signature that can be verified using a public key. This represents the RSA private key of the signing user; The hash value of the document to be signed;
[0174] Use dynamic keys Encrypt the signed data using AES-GCM:
[0175]
[0176] in The encrypted signature data; This is the Galois / Counter Mode encryption function for the AES algorithm;
[0177] S43: Confirmation of signature completion:
[0178] Verify the integrity and success of the signing operation; confirm the correctness of the signed data by decryption verification:
[0179]
[0180] in This is the Galois / Counter Mode decryption function for the AES algorithm;
[0181] Verify the integrity of the decrypted signature data structure:
[0182]
[0183] in This indicates the completion and confirmation status of the signature, with a value of TRUE or FALSE, used to indicate whether the entire signature operation has been successfully completed; The structure format of the decrypted and recovered signature data includes information on the type, length, and order of the data fields; Represents complete signature data The structural format; The RSA public key representing the signing user is used to verify the validity of the digital signature; This indicates that it was extracted from the decrypted signature data. This field is generated from the user's private key in step S42; This function is an RSA digital signature verification function. It decrypts the digital signature using the public key and compares it with the original signature. The signature validity is verified by comparison. TRUE indicates that the signature verification was successful, and FALSE indicates that the signature verification failed.
[0184] Furthermore, the system transmits the signature result to the server for storage and archiving, completing the entire dynamic electronic signature process based on mobile device sensor data; during the transmission, a communication key generated and managed by the gateway device is used. Encryption is performed to ensure the security of data under a multi-layered key system; after transmission is completed, the system clears the local temporary key and sensitive data to ensure the security and privacy protection of the signing process.
[0185] It should be noted that this step establishes a complete multi-layered security verification system. Through a dual pre-verification mechanism of user identity and device legitimacy, the compliance and credibility of the signing operation are ensured from the source. Compared with traditional single identity verification methods, this step simultaneously verifies user permissions and device trustworthiness, effectively preventing the security risks of unauthorized users using legitimate devices or legitimate users using untrusted devices to sign, thus building a solid security foundation for the entire signing process.
[0186] Example 2: The present invention also discloses an electronic signature system, comprising the following five modules:
[0187] Data acquisition module: When a user initiates an electronic signature operation on a mobile device, the system synchronously activates the multi-sensor data acquisition module to acquire data from various sensors of the mobile device, including accelerometers, gyroscopes, and magnetometers, and performs noise filtering and preprocessing on the acquired sensor data.
[0188] Environment assessment module: Detects the network environment and mobile device status of electronic signature operations, analyzes the security level and transmission requirements of signed documents, and determines the corresponding security strategy based on the document type and signing mode;
[0189] Dynamic key generation module: Based on sensor data matrix and environmental assessment parameter matrix, dynamic keys are generated using data fusion algorithm and hash function. The dynamic key works in conjunction with the root key managed by the server cryptographic machine and the communication key managed by the gateway device. The in conjunction is to combine the dynamic key with the root key using XOR operation, and at the same time, the communication key is used for outer encryption during communication.
[0190] Electronic signature module: Performs electronic signature operations and implements full-process security monitoring. It ensures the authenticity and integrity of the signature through multiple verification mechanisms, and completes the entire electronic signature process.
[0191] It should be noted that the sequence numbers of the above embodiments of the present invention are merely for descriptive purposes and do not represent the superiority or inferiority of the embodiments. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, apparatus, article, or method that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, apparatus, article, or method. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, apparatus, article, or method that includes that element.
[0192] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) as described above, and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, or network device, etc.) to execute the methods described in the various embodiments of the present invention.
[0193] The above are merely preferred embodiments of the present invention and do not limit the scope of the patent. Any equivalent structural or procedural transformations made based on the description and drawings of the present invention, or direct or indirect applications in other related technical fields, are similarly included within the scope of patent protection of the present invention.
Claims
1. A method for generating dynamic keys on a mobile device, characterized in that, Includes the following steps: S1: When a user initiates an electronic signature operation on a mobile device, the system simultaneously activates the multi-sensor data acquisition module to acquire data from various sensors on the mobile device, including accelerometers, gyroscopes, and magnetometers. The system then performs noise filtering and preprocessing on the acquired sensor data to obtain a sensor data matrix. S2: Detect the network environment and mobile device status of electronic signature operations, analyze the security level and transmission requirements of signed documents, determine the corresponding security strategy based on the document type and signing mode, and generate an environment assessment parameter matrix. Step S2 includes: S21: Perform network environment detection and quantification to obtain network connection type, signal strength, network bandwidth, network latency and network stability indicators; S22: Evaluate the movement state of the mobile device, which includes the movement speed, attitude change rate, and movement stability of the mobile device; S23: Analyze the security level of signed documents, assign security level weights according to the document type, and calculate the document complexity index; S24: Based on the assessment parameters of network environment, mobile device mobility status, and signed document security level, generate an environment assessment parameter matrix containing 14 environment assessment parameters; Environment Assessment Parameter Matrix for The parameter vector contains 14 environmental assessment parameters, including network type, signal strength, available network bandwidth, network latency, network stability, device movement speed, attitude change rate, movement stability, document type, security level weight, number of document pages, document size, signature mode, and document complexity. S3: Based on the sensor data matrix and environmental assessment parameter matrix, a dynamic key is generated using a data fusion algorithm and hash function. The environmental risk level is assessed, and the dynamic key update frequency and encryption strength parameters are determined to establish an encrypted channel for the signing session. S4: Perform electronic signature operations and implement full-process security monitoring, ensuring the authenticity and integrity of the signature through multiple verification mechanisms, and completing the entire electronic signature process.
2. The mobile terminal dynamic key generation method according to claim 1, characterized in that, Step S1 includes: S11: Initialize the signature session and establish a sensor data acquisition channel, setting the sensor data acquisition frequency to 100Hz; S12: Collect sensor data including the three-axis acceleration values of the accelerometer, the three-axis angular velocity values of the gyroscope, and the three-axis magnetic field strength values of the magnetometer; S13: Use a low-pass filter to smooth the data from each sensor. The cutoff frequency of the low-pass filter is set to 20Hz. S14: Calculate the comprehensive change intensity index of sensor data, including the comprehensive intensity of acceleration, the comprehensive intensity of angular velocity, and the comprehensive value of magnetic field strength, to form a sensor data matrix.
3. The mobile terminal dynamic key generation method according to claim 2, characterized in that, Step S3 includes: S31: Sensor data matrix fusion and feature extraction, extracting time-domain and frequency-domain features and combining them into a motion feature vector; S32: Based on the environmental assessment parameter matrix, assess the environmental risk level, calculate the network security risk coefficient, mobility risk coefficient and document security risk coefficient, and obtain the environmental risk level; S33: Determine the dynamic key parameters, and set the dynamic key update interval, key length, and hash iteration number according to the environmental risk level; S34: Dynamic key generation and encryption channel establishment. The SHA-256 hash function is used to perform multiple iterative operations on the key seed to generate a dynamic key. The motion feature vector, the current timestamp, and the user identity identifier are combined into the key seed.
4. The mobile terminal dynamic key generation method according to claim 3, characterized in that, Step S4 includes: S41: Pre-verification and authorization confirmation before signing, verifying the legitimacy of the user's identity and the legitimacy of the signing device; S42: Dynamic signature data generation and encrypted transmission, generating signature data blocks containing spatiotemporal information, and using a dynamic key to encrypt the signature data using AES-GCM; S43: Signature completion confirmation. Verify the correctness of the signature data by decryption and verify the integrity of the decrypted signature data structure.
5. The mobile terminal dynamic key generation method according to claim 3, characterized in that, Step S31 includes: The time-domain characteristics include the mean characteristics of the triaxial acceleration values, the variance characteristics of the triaxial angular velocity values, and the peak characteristics of the triaxial magnetic field strength values; The frequency domain features include the main frequency features of the triaxial acceleration values extracted by performing a Fast Fourier Transform (FFT) on the accelerometer data.
6. The mobile terminal dynamic key generation method according to claim 4, characterized in that, Step S42 includes: A signature environment fingerprint is generated by using the SHA256 hash function to generate the sensor data matrix, environmental assessment parameter matrix, and dynamic key at the time of signature. Construct a complete signature data structure that includes user identity, mobile device identity, signature timestamp, signature geolocation, signature environment fingerprint, and digital signature; The signature data is encrypted with AES-GCM using a dynamic key generated based on sensor data, enabling the binding and verification of signature data with the motion status of the mobile device.
7. An electronic signature system, characterized in that, include: Data acquisition module: When a user initiates an electronic signature operation on a mobile device, the system synchronously activates the multi-sensor data acquisition module to acquire data from various sensors of the mobile device, including accelerometers, gyroscopes, and magnetometers, and performs noise filtering and preprocessing on the acquired sensor data. Environment assessment module: Detects the network environment and mobile device status of electronic signature operations, analyzes the security level and transmission requirements of signed documents, and determines the corresponding security strategy based on the document type and signing mode; Dynamic key generation module: Based on sensor data matrix and environmental assessment parameter matrix, dynamic keys are generated using data fusion algorithm and hash function. The dynamic key works in conjunction with the root key managed by the server cryptographic machine and the communication key managed by the gateway device. The in conjunction is to combine the dynamic key with the root key using XOR operation, and at the same time, the communication key is used for outer encryption during communication. Electronic signature module: Performs electronic signature operations and implements full-process security monitoring. It ensures the authenticity and integrity of the signature through multiple verification mechanisms and completes the entire electronic signature process. To achieve the mobile terminal dynamic key generation method as described in any one of claims 1-6.