Digital signature method for trusteeship certificate and scene certificate
By combining managed certificates with scenario-based certificates in digital signatures, the problems of high cost and security in electronic contract signing are solved, enabling efficient management and secure use of certificates, reducing operating costs and ensuring certificate security.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-25
- Publication Date
- 2026-03-13
AI Technical Summary
Existing electronic contract signing methods lead to a linear increase in operating costs, and the security of certificates is difficult to guarantee, especially in high-frequency business scenarios where costs accumulate.
We employ a digital signature method that combines managed certificates with scenario certificates. Managed certificates are valid for many years upon a single application, while scenario certificates are invalidated after a single use. By combining certificate management strategies for branch offices and customers, we ensure certificate security and cost control.
It reduces the operating costs of electronic signatures, improves certificate security, especially in high-frequency business scenarios, reduces the usage costs for branch offices, and ensures the secure use of certificates on the customer side.
Abstract
Description
Technical Field
[0001] This invention relates to the field of electronic contract signing technology, and in particular to a method for digital signature combining escrow certificates and scenario certificates. Background Technology
[0002] With the continuous promotion of digital finance, more and more transactions have shifted from offline to online, greatly improving transaction convenience. Contract signing is a crucial part of financial transactions. Previously, electronic contract signing relied on SaaS services from digital certification authorities (DCAs), where the digital certification authority would provide the electronic contract image, bank information, and customer information to the DCA for signing. However, this method suffers from drawbacks such as fixed fees per signing and cumulative costs in high-frequency business scenarios. As online business expands, this model leads to a linear increase in operating costs, impacting the effectiveness of digital transformation.
[0003] Therefore, it is necessary to provide a method that combines managed certificates with scenario-based digital signatures to reduce the cost of electronic signatures for banks and ensure the security of bank-side digital certificates. Summary of the Invention
[0004] The purpose of this invention is to provide a method for digital signature combining escrow certificates and scenario certificates, so as to reduce the cost of electronic signatures for banks and ensure the security of bank-side digital certificates.
[0005] To address the problems existing in the prior art, this invention provides a method for digital signatures combining managed certificates and scenario certificates, comprising the following steps:
[0006] Step 1: The bank branch pre-applies for the custody certificate by sending the branch's name, certificate number, and a copy of its business license to the digital certification authority through the digital certificate issuance system. After obtaining the custody certificate, the certificate information is stored in the electronic signature system database and linked to the branch's institution number.
[0007] Step 2: When a customer initiates a signature application, the electronic signature system receives the signature request, encapsulates the customer's name and ID number, and applies for a scenario certificate from a digital certification authority through the digital certificate issuance system.
[0008] Step 3: After the scenario certificate application is successful, assemble the certificate information and contract information and send them to the signature verification server for digital signature. After the signature is completed, set the scenario certificate to an invalid state.
[0009] Step 4: After the customer completes all signings on a single electronic contract, the branch office finds the corresponding escrow certificate and certificate information based on the associated institution number, assembles the escrow certificate, certificate information, and contract information after the customer has signed and digitally signed them. After the signing is completed, the escrow certificate remains valid.
[0010] Optionally, in the method of combining the managed certificate with the scenario certificate digital signature, the scenario certificate has the characteristic of being used once and discarded after use.
[0011] Optionally, in the method of combining escrow certificates with scenario-based digital signatures, the escrow certificate has the characteristic of being valid for many years with a single application.
[0012] Compared with the prior art, the present invention has the following advantages:
[0013] (1) This invention combines the characteristics of escrow certificates and scenario certificates. Escrow certificates have the characteristic of "one application, valid for many years". As a branch office with a high frequency of signing, using escrow certificates for digital signatures can greatly reduce the cost of using electronic signatures.
[0014] (2) At the same time, the certificates of branch institutions are uniformly managed and stored within the bank, which can ensure the security of the certificates.
[0015] (3) For customers with low signing frequency, scenario certificates with a cost far lower than managed certificates can be used to maximize the use of the certificates. Scenario certificates have the characteristics of "apply and use immediately, expire after use", which can also ensure that after the customer's certificate is used up, other electronic signatures cannot be used, thus ensuring the security of customer signatures. Detailed Implementation
[0016] The specific embodiments of the present invention will now be described in more detail. The advantages and features of the present invention will become clearer from the following description.
[0017] In the following, if the methods described herein include a series of steps, the order of these steps presented herein is not necessarily the only order in which these steps can be performed, and some of the steps described may be omitted and / or some other steps not described herein may be added to the method.
[0018] With the continuous promotion of digital finance, more and more transactions have shifted from offline to online, greatly improving transaction convenience. Contract signing is a crucial part of financial transactions. Previously, electronic contract signing relied on SaaS services from digital certification authorities (DCAs), where the digital certification authority would provide the electronic contract image, bank information, and customer information to the DCA for signing. However, this method suffers from drawbacks such as fixed fees per signing and cumulative costs in high-frequency business scenarios. As online business expands, this model leads to a linear increase in operating costs, impacting the effectiveness of digital transformation.
[0019] To address the problems existing in the prior art, this invention provides a method for digital signatures combining managed certificates and scenario certificates, comprising the following steps:
[0020] Step 1: Bank branches pre-apply for a custody certificate by sending the branch's name, certificate number, and a copy of its business license to the digital certification authority through the digital certificate issuance system. After obtaining the custody certificate, the certificate information is stored in the electronic signature system database and associated with the branch's institution number. Preferably, the scenario certificate has the characteristic of being used only once and discarded after use.
[0021] In one embodiment, a branch office applies for the activation of a custodial certificate through OA approval. After receiving the approval, the certificate administrator uploads the branch's name, unified social credit code or organization code, business license image, etc., to the electronic signature system's backend management platform. The platform then packages this data and sends it to the digital certificate issuance system. The digital certificate issuance system sends a request to an external digital certification authority. After receiving the response information from the external authority, the digital certificate issuance system returns it to the electronic signature system. The electronic signature system stores the custodial certificate, signature certificate, string data, custodial certificate creation time, future expiration time, etc.
[0022] Step 2: When a customer initiates a signature application, the electronic signature system receives the signature request, encapsulates the customer's name and ID number, and applies for a scenario certificate from a digital certification authority through the digital certificate issuance system; preferably, the managed certificate has the feature of being valid for many years with a single application.
[0023] In one embodiment, when a customer operates a loan transaction on a corporate mobile banking app, and clicks the "Sign" button when the electronic contract is displayed on the page, enters the SMS verification code, and clicks "Confirm," the corporate mobile banking app sends the customer's signature request to the electronic signature system. After receiving the request, the signature system encapsulates the customer's name, ID number, ID image, SMS verification code transaction history, public key, and other information, and then requests an external digital certification authority through the digital certificate issuance system. Subsequently, the digital certificate issuance system receives the response information from the external authority and returns it to the electronic signature system, which stores the scenario certificate signature certificate string data.
[0024] Step 3: After the scenario certificate application is successful, assemble the certificate information and contract information and send them to the signature verification server for digital signature. After the signature is completed, set the scenario certificate to an invalid state.
[0025] In one embodiment, the electronic signature system assembles the electronic contract PDF, private key ciphertext, scenario certificate from step two, signature certificate, and string, and then requests the digital signature interface of the signature verification server. The signature verification server completes the signing operation and then returns the signed contract PDF to the electronic signature system. The electronic signature system sets an invalidation flag for the scenario certificate, which can no longer be used in the future.
[0026] Step 4: After the customer completes all signings on a single electronic contract, the branch office finds the corresponding escrow certificate and certificate information based on the associated institution number, assembles the escrow certificate, certificate information, and contract information after the customer has signed and digitally signed them. After the signing is completed, the escrow certificate remains valid.
[0027] In one embodiment, the electronic signature system identifies that the customer's electronic signature on the contract has been completed. It then determines the branch office number associated with the electronic contract and associates this branch office number with the certificate string data of its escrow certificate. The electronic signature system assembles this certificate string data, the private key ciphertext, and the electronic contract PDF from step three, and requests the digital signature interface of the signature verification server. The signature verification server completes the signing operation and then returns the signed contract PDF to the electronic signature system. The electronic signature system then returns the signing completion status and the fully signed electronic contract PDF to the enterprise's mobile banking app. The escrow certificate used in this instance can still be reused later.
[0028] In summary, compared with the prior art, the present invention has the following advantages:
[0029] (1) This invention combines the characteristics of escrow certificates and scenario certificates. Escrow certificates have the characteristic of "one application, valid for many years". As a branch office with a high frequency of signing, using escrow certificates for digital signatures can greatly reduce the cost of using electronic signatures.
[0030] (2) At the same time, the certificates of branch institutions are uniformly managed and stored within the bank, which can ensure the security of the certificates.
[0031] (3) For customers with low signing frequency, scenario certificates with a cost far lower than managed certificates can be used to maximize the use of the certificates. Scenario certificates have the characteristics of "apply and use immediately, expire after use", which can also ensure that after the customer's certificate is used up, other electronic signatures cannot be used, thus ensuring the security of customer signatures.
[0032] In summary, compared with the prior art, the present invention has the following advantages:
[0033] The above are merely preferred embodiments of the present invention and do not constitute any limitation on the present invention. Any equivalent substitutions or modifications made by those skilled in the art to the technical solutions and content disclosed in the present invention without departing from the scope of the present invention shall be deemed to have remained within the protection scope of the present invention.
Claims
1. A method for digital signatures combining managed certificates and scenario certificates, characterized in that, Includes the following steps: Step 1: The bank branch pre-applies for the custody certificate by sending the branch's name, certificate number, and a copy of its business license to the digital certification authority through the digital certificate issuance system. After obtaining the custody certificate, the certificate information is stored in the electronic signature system database and linked to the branch's institution number. Step 2: When a customer initiates a signature application, the electronic signature system receives the signature request, encapsulates the customer's name and ID number, and applies for a scenario certificate from a digital certification authority through the digital certificate issuance system. Step 3: After the scenario certificate application is successful, assemble the certificate information and contract information and send them to the signature verification server for digital signature. After the signature is completed, set the scenario certificate to an invalid state. Step 4: After the customer completes all signings on a single electronic contract, the branch office finds the corresponding escrow certificate and certificate information based on the associated institution number, assembles the escrow certificate, certificate information, and contract information after the customer has signed and digitally signed them. After the signing is completed, the escrow certificate remains valid.
2. The method of combining a managed certificate with a scenario certificate digital signature as described in claim 1, characterized in that, Scenario certificates are designed for one-time use and are discarded after use.
3. The method of combining a managed certificate with a scenario certificate digital signature as described in claim 1, characterized in that, Hosted certificates offer the advantage of being valid for multiple years with a single application.