An electronic signature management method and related device
Patent Information
- Application Number
- CN202611051620.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-15
- Publication Date
- 2026-09-22
AI Technical Summary
[0003]在移动端环境下,为提升用户操作便捷性,常在收到指令后直接调取签章私钥执行盖章,这就导致私钥暴露、违规调用的风险较高,难以满足高安全等级业务的管控要求
[0031]借由上述技术方案,本申请提供的一种电子签章管控方法及相关装置,包括:响应签章指令,采集多维身份特征、并上传至服务端,以使服务端对多维身份特征进行核验;接收服务端下发的分片私钥,分片私钥是多维身份特征核验通过时所下发的;基于分片私钥生成签章私钥,并使用签章私钥对目标文件执行签章操作。本申请中移动端响应签章指令时,采集多维身份特征上传服务器进行核验,在核验通过后由服务端下发分片私钥,移动端利用该分片私钥在本地重组生成签章私钥并对目标文件执行签章操作。通过引入多维身份特征的核验,能够有效阻断非授权的指令,另外,基于分片私钥的动态下发,可以避免完整私钥在移动端的长期驻留,从而降低私钥暴露、违规调用的风险,显著提升移动端电子签章业务的整体安全性与可靠性。
Smart Images

Figure CN122802908A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of software technology, and in particular to an electronic signature control method and related device. Background Technology
[0002] With the rapid development of mobile internet technology and the popularization of digital office, electronic signatures, as a core means of confirming the legal validity of documents and ensuring the security of business transactions, have been widely used in many scenarios such as financial signing, government approval, and corporate contract management.
[0003] In mobile environments, to improve user convenience, the signature private key is often retrieved directly after receiving an instruction to perform the stamping. This leads to a high risk of private key exposure and unauthorized access, making it difficult to meet the control requirements of high-security businesses. Summary of the Invention
[0004] In view of the above problems, this application provides an electronic signature control method and related device to reduce the risk of private key exposure and unauthorized access. The specific solution is as follows:
[0005] The first aspect of this application provides an electronic signature control method, which is applied to a mobile terminal, and the electronic signature control method includes:
[0006] In response to a signature command, multi-dimensional identity features are collected and uploaded to the server so that the server can verify the multi-dimensional identity features.
[0007] Receive the fragmented private key issued by the server, which is issued when the multidimensional identity feature verification is successful;
[0008] A signing private key is generated based on the fragmented private key, and the signing private key is used to perform a signing operation on the target file.
[0009] In one possible implementation, the response to the signature instruction, collecting multi-dimensional identity features, and uploading them to the server so that the server can verify the multi-dimensional identity features, includes:
[0010] The voice monitoring function is activated to collect the voice signing instructions input by the operator and to extract the audio data of the voice signing instructions.
[0011] The voiceprint features of the operator are extracted from the audio data, and at the same time, the terminal fingerprint of the mobile device is generated based on the hardware information of the mobile device.
[0012] The voiceprint feature and the terminal fingerprint are uploaded to the server so that the server can verify the voiceprint feature based on the voiceprint template and verify the terminal fingerprint based on the fingerprint template.
[0013] In one possible implementation, the step of responding to the signature instruction, collecting multi-dimensional identity features, and uploading them to the server so that the server can verify the multi-dimensional identity features further includes:
[0014] The system detects whether the voice signature command is a valid command based on the audio data, and if the voice signature command is a valid command, it executes the step of uploading the voiceprint feature and the terminal fingerprint to the server.
[0015] In one possible implementation, detecting whether the voice signature instruction is a valid instruction based on the audio data includes:
[0016] Extract the audio temporal and semantic features of the voice signature instruction from the audio data;
[0017] Liveness detection is performed based on the audio temporal features, and intent detection is performed based on the semantic features;
[0018] The validity of the voice signature command is determined based on the results of liveness detection and intent recognition.
[0019] In one possible implementation, the electronic signature control method further includes:
[0020] Upon completion of the signing operation, the signing operation record and the file information of the target file are obtained, and the signing operation record, the file information, and the multidimensional identity features are encrypted and written into the traceability extension field of the target file.
[0021] In one possible implementation, the electronic signature control method further includes:
[0022] Upon completion of the signing operation, a signing operation log of the target text is generated and uploaded to the server.
[0023] A second aspect of this application provides an electronic signature control device, which is applied to a mobile terminal and includes:
[0024] The instruction response module is used to respond to signature instructions, collect multi-dimensional identity features, and upload them to the server so that the server can verify the multi-dimensional identity features.
[0025] The signature control module is used to receive the fragmented private key issued by the server, which is issued when the multi-dimensional identity feature verification is successful; generate a signature private key based on the fragmented private key; and use the signature private key to perform a signature operation on the target file.
[0026] A third aspect of this application provides a computer program product including computer-readable instructions that, when executed on an electronic device, cause the electronic device to implement the electronic signature control method of the first aspect or any implementation thereof.
[0027] A fourth aspect of this application provides an electronic device, including at least one processor and a memory connected to the processor, wherein:
[0028] The memory is used to store computer programs;
[0029] The processor is used to execute the computer program so that the electronic device can implement the electronic signature control method of the first aspect or any implementation thereof.
[0030] The fifth aspect of this application provides a computer storage medium carrying one or more computer programs, which, when executed by an electronic device, enable the electronic device to implement the electronic signature control method of the first aspect or any implementation thereof.
[0031] By employing the above technical solution, this application provides an electronic signature control method and related apparatus, comprising: responding to a signing instruction, collecting multi-dimensional identity features and uploading them to a server for verification by the server; receiving a fragmented private key issued by the server, the fragmented private key being issued upon successful verification of the multi-dimensional identity features; generating a signing private key based on the fragmented private key, and using the signing private key to perform a signing operation on the target file. In this application, when the mobile terminal responds to a signing instruction, it collects multi-dimensional identity features and uploads them to the server for verification. After successful verification, the server issues a fragmented private key, which the mobile terminal uses to reassemble locally to generate a signing private key and performs a signing operation on the target file. By introducing multi-dimensional identity feature verification, unauthorized instructions can be effectively blocked. In addition, the dynamic issuance of fragmented private keys avoids the long-term residence of the complete private key on the mobile terminal, thereby reducing the risk of private key exposure and unauthorized access, and significantly improving the overall security and reliability of mobile electronic signature services. Attached Figure Description
[0032] The above and other features, advantages, and aspects of the embodiments of this disclosure will become more apparent from the accompanying drawings and the following detailed description. Throughout the drawings, the same or similar reference numerals denote the same or similar elements. It should be understood that the drawings are schematic, and the originals and elements are not necessarily drawn to scale.
[0033] Figure 1 A flowchart illustrating an electronic signature control method provided in this application embodiment;
[0034] Figure 2This is a partial flowchart illustrating an electronic signature control method provided in an embodiment of this application.
[0035] Figure 3 This is another part of the flowchart illustrating an electronic signature control method provided in an embodiment of this application;
[0036] Figure 4 A schematic diagram of an electronic signature control device provided in this application embodiment;
[0037] Figure 5 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation
[0038] The embodiments of this application are described below with reference to the accompanying drawings. The terminology used in the implementation section of this application is for explaining specific embodiments only and is not intended to limit the scope of this application.
[0039] As will be known to those skilled in the art, with the development of technology and the emergence of new scenarios, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems.
[0040] The terms "first," "second," etc., used in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such terms are interchangeable where appropriate; this is merely a way of distinguishing objects with the same attributes in the embodiments of this application. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion, so that a process, method, system, product, or apparatus that comprises a series of elements is not necessarily limited to those elements, but may include other elements not explicitly listed or inherent to those processes, methods, products, or apparatuses.
[0041] To address the high risks of private key exposure and unauthorized access in mobile environments, this application provides an electronic signature control method. The electronic signature control method of this application embodiment will be described in detail below with reference to the accompanying drawings.
[0042] See Figure 1 , Figure 1 This is a flowchart illustrating an electronic signature control method provided in an embodiment of this application. Figure 1 As shown in the figure, the electronic signature control method provided in this application embodiment is applied to a mobile terminal and may include steps S101 to S103, which are described in detail below.
[0043] S101 responds to the signature command, collects multi-dimensional identity features, and uploads them to the server so that the server can verify the multi-dimensional identity features.
[0044] In this embodiment, the signature instruction can be captured by listening to user interface interaction events or voice trigger signals. Upon receiving the signature instruction, the mobile device invokes integrated sensor and data interfaces to obtain multi-dimensional identity features. These multi-dimensional identity features may include the user's current biometric state and perceived data of the device environment. For example, these multi-dimensional identity features include one or more biometric features such as voiceprint features, facial features, and fingerprint features, as well as device features such as the mobile device's hardware serial number, operating system version, and network physical address.
[0045] After acquiring multidimensional identity features, the mobile device uploads these features to the server via an encrypted communication link. The server parses the received multidimensional identity features and uses a pre-registered template library to match and verify each feature. If all features in the multidimensional identity features pass the matching verification, the multidimensional identity feature verification is considered successful.
[0046] S102, Receive the fragmented private key issued by the server. The fragmented private key is issued when the multi-dimensional identity feature verification is successful.
[0047] In this embodiment, after the server confirms successful multi-dimensional identity verification, it issues the corresponding fragmented private key to the mobile device according to the permission rules. This fragmented private key is a key fragment split from the complete signing private key using a specific algorithm. It does not possess independent signing functionality and must be combined with other fragments or locally pre-stored information to reconstruct a usable signing private key. The server issues this fragmented private key only within the validity period of a single session after successful multi-dimensional identity verification, and it can be configured to be valid only once, limited to use in the current business process. By strongly binding the private key distribution to the identity verification result, it ensures that only mobile devices with legitimate identities and verified credentials can obtain the critical key fragments required for signing, achieving dynamic authorization and secure isolation of key calls.
[0048] The mobile device receives fragmented private keys via an encrypted communication link and temporarily stores them in a secure area of memory, ensuring that the complete private key information is not retained in persistent storage media. This fragmented private key distribution method avoids storing highly sensitive complete signing private keys locally on the mobile device for extended periods, significantly reducing the risk of private key leakage due to device loss, hacking, or malware attacks.
[0049] S103, Generate a signing private key based on the fragmented private key, and use the signing private key to perform a signing operation on the target file.
[0050] In this embodiment, after receiving the fragmented private key, the mobile terminal combines it with another key fragment securely stored locally, or through specific computational logic, according to a preset key synthesis algorithm, to reconstruct and generate a complete signing private key. It should be noted that the signing private key is a core credential used for digitally signing electronic documents and has legal validity. Its generation process is performed in a secure execution environment on the mobile terminal to prevent the theft of intermediate data during the synthesis process.
[0051] After generating the signature private key, the mobile device calls the electronic signature engine to load the target file to be processed. This target file can be an OFD (Open Fixed-layout Document) file conforming to the document layout specification or an electronic document in other formats. When performing the signature operation on the target file, the generated signature private key can be used to perform asymmetric encryption on the digest value of the target file to generate a digital signature. This digital signature and a visualized seal image are then overlaid and written to a designated location in the target file according to a predetermined format. By dynamically generating a complete private key using fragmented private keys and performing the signature locally, controlled use of signature permissions is ensured, as well as the integrity and compliance of the signature operation.
[0052] In this embodiment, the multi-dimensional identity features collected by the mobile terminal in response to the signing instruction serve as the basis for server verification, ensuring the dual legitimacy of the operator's identity and the terminal environment, and intercepting illegal signing instructions at the source. The server only issues a fragmented private key after successful verification, using a key sharding mechanism to strongly bind identity authentication and key usage, avoiding the risk of static storage of the complete private key on the mobile terminal. The mobile terminal dynamically generates a signing private key based on the fragmented private key and performs the signing operation on the target file, achieving real-time verification of permissions and atomic execution of the signing action. This significantly improves the overall security level of the electronic signature system.
[0053] In one possible implementation, the operator's voiceprint characteristics are extracted through voice monitoring and audio interception. These voiceprint characteristics are then used to defend against attacks involving recording playback and speech synthesis. Additionally, a terminal fingerprint is generated based on the mobile device's hardware information to prevent misuse on unauthorized devices after account theft. This ensures that the electronic signature private key is only accessed by legitimate personnel using legitimate devices, eliminating the risk of impersonation and unauthorized signatures at the source.
[0054] See Figure 2 , Figure 2 This is a partial flowchart illustrating an electronic signature control method provided in an embodiment of this application. Figure 2As shown in the embodiment of this application, an electronic signature control method is provided, wherein step S101, "responding to the signature instruction, collecting multi-dimensional identity features, and uploading them to the server so that the server can verify the multi-dimensional identity features", may include steps S201 to S203, which are described in detail below.
[0055] S201, activate the voice monitoring function to collect the voice signing instructions input by the operator and capture the audio data of the voice signing instructions.
[0056] In this embodiment, the mobile terminal activates the microphone and other audio-to-electric conversion devices by calling the operating system's audio acquisition interface or the software development kit integrated within the application to initiate voice monitoring, converting analog sound wave signals in the environment into digital audio streams in real time. During continuous voice monitoring, real-time semantic analysis is performed on the acquired voice stream to detect whether it contains preset signature trigger keywords (such as "start stamping," "execute stamping," etc.). Once a valid voice signature command is identified, the corresponding audio data stream is immediately locked. To optimize subsequent processing efficiency, audio data containing valid command content is precisely extracted from the locked data stream, removing preceding and following silence segments and irrelevant noise.
[0057] The extracted audio data is usually stored in Pulse Code Modulation (PCM) format or Waveform Audio File Format (WAV) to preserve key parameters such as sampling rate, bit depth, and number of channels, thereby ensuring the characteristic purity of the input source and reducing computational redundancy.
[0058] S202: Extract the operator's voiceprint features from the audio data, and at the same time, generate the mobile terminal fingerprint based on the mobile terminal's hardware information.
[0059] In this embodiment, for the captured audio data, the mobile device first performs preprocessing operations such as pre-emphasis, framing, and windowing. Then, each frame of the speech signal is transformed to the frequency domain, and the energy distribution of the Mel filter bank is calculated. After logarithmic operations and discrete cosine transform, Mel frequency cepstral coefficients are obtained, which are then concatenated to form voiceprint features characterizing the physiological structure and behavioral habits of the operator's vocal organs. Thus, unstructured sound waveforms can be transformed into quantifiable and comparable acoustic fingerprints to distinguish different individuals. In practical applications, voiceprint feature extraction can also be achieved through a voiceprint embedding model based on deep neural networks; this embodiment does not limit this approach.
[0060] While extracting the aforementioned voiceprint features, the mobile device reads the underlying hardware information and performs hash calculations or applies specific string encoding rules to generate a unique and difficult-to-forge device identifier, i.e., a terminal fingerprint. It should be noted that the hardware information may include the International Mobile Equipment Identity (IMEI), Media Access Control Address (MAC address), CPU serial number, screen resolution parameters, and operating system version number, etc.
[0061] This application's embodiments introduce a device-level physical identity identifier to form a two-factor authentication scheme that binds voiceprint to the device, ensuring that even if account credentials are leaked, attackers will be unable to pass verification when operating on an unauthorized device due to the mismatch of terminal fingerprints.
[0062] S203, upload the voiceprint feature and terminal fingerprint to the server so that the server can verify the voiceprint feature based on the voiceprint template and verify the terminal fingerprint based on the fingerprint template.
[0063] In this embodiment, the mobile terminal uploads its voiceprint and fingerprint to the server via an encrypted communication link. Upon receiving the voiceprint and fingerprint, the server performs dual verification.
[0064] Specifically, in the voiceprint feature verification process, the server retrieves the standard voiceprint template registered and filed by the operator during the system initialization phase from the voiceprint database. It then calculates the similarity score between the real-time uploaded voiceprint features and this standard voiceprint template, using metrics such as cosine similarity or Euclidean distance. If the similarity score is greater than or equal to a preset threshold, the voiceprint feature verification is considered successful, confirming the operator as a legitimate authorized person. Conversely, if the similarity score is less than the preset threshold, the voiceprint feature verification is considered unsuccessful.
[0065] In addition, during the terminal fingerprint verification process, the server retrieves the authorized device fingerprint templates pre-stored by the operator during system initialization from the device fingerprint database. It then matches the real-time uploaded terminal fingerprint with these authorized device fingerprint templates to determine if the mobile device is a compliant device authorized by the system. Specifically, it calculates the matching score between the terminal fingerprint and the authorized device fingerprint template. If the matching score is greater than or equal to a preset threshold, the terminal fingerprint verification is considered successful, confirming the mobile device's operating environment is secure. If the matching score is less than the preset threshold, the terminal fingerprint verification is considered unsuccessful, indicating the mobile device is an unauthorized terminal or its hardware information has been tampered with.
[0066] Only after both voiceprint verification and terminal fingerprint verification are passed will the server confirm the successful multi-dimensional identity verification of this signing instruction and then send the fragmented private key to the mobile terminal.
[0067] In one possible implementation, the captured audio data undergoes instruction legality detection. Semantic analysis filters out unexpected voice input or malicious voice forgery attempts, ensuring that subsequent high-security identity verification only targets genuine and valid signature instructions. To this end, an electronic signature control method provided in this application embodiment, wherein step S101, "responding to the signature instruction, collecting multi-dimensional identity features, and uploading them to the server so that the server can verify the multi-dimensional identity features," may further include the following steps:
[0068] The system detects whether the voice signature instruction is a valid instruction based on the audio data, and if the voice signature instruction is a valid instruction, it executes step S203.
[0069] In this embodiment, the audio data is not a simple record of signal waveforms, but a structured temporal sequence representing the operator's vocal behavior in a specific time dimension. It contains acoustic features, prosodic features, and corresponding semantic text information. By parsing this audio data, the user's specific instructions can be extracted and matched with predefined legal instructions to determine whether the current voice signature instruction is valid.
[0070] In practical applications, an Automatic Speech Recognition (ASR) engine deployed on a mobile device can be used to check the legality of audio data commands. The mobile device inputs the collected audio data into the ASR engine. The ASR engine first performs endpoint detection to remove silent segments, then uses an acoustic model to convert the speech signal into a phoneme sequence, and finally decodes it into a corresponding text string using a language model. The mobile device compares the decoded text string with preset legal command content, which stores preset trigger phrases such as "start stamping" and "confirm signature." If the text string matches any phrase in the legal command content, or if the edit distance is less than a preset threshold, the voice signature command is considered a legal command.
[0071] In one possible implementation, liveness detection and intent recognition are performed simultaneously based on audio data. Only when both conditions are met—liveness detection confirming a real person's voice and intent recognition confirming a signing intent—is the voice signing instruction deemed legitimate. See also Figure 3 , Figure 3 This is another schematic flowchart illustrating an electronic signature control method provided in an embodiment of this application. Figure 3As shown in the embodiment of this application, an electronic signature control method is provided. The above step S101, "detecting whether the voice signature instruction is a legal instruction based on the audio data", may include steps S301 to S303. These steps are described in detail below.
[0072] S301, extract audio temporal and semantic features of voice signature instructions from audio data.
[0073] In this embodiment, audio time-domain features are used to characterize the physical properties of speech signals in the time dimension. These features not only include numerical sequences but also reflect multi-dimensional structured information such as the vibration patterns, energy distribution, and phase relationships of the sound waveform. For the extracted audio data, the mobile device first preprocesses the audio data, including pre-emphasis, framing, and windowing operations, to highlight the spectral characteristics of the speech signal and smooth signal noise. Then, it extracts parameters reflecting the essential properties of the audio, such as short-time energy, short-time zero-crossing rate, and fundamental frequency period, from the processed audio data to obtain audio time-domain features, which are used to distinguish real human voices from environmental noise or sound reproduced by recording equipment.
[0074] Meanwhile, the mobile device extracts high-dimensional abstract vectors from the audio data to represent the meaning and logical intent of the voice commands as semantic features. Specifically, the audio data is input into an automatic speech recognition model, which converts the sound wave signals into corresponding text information. Natural language processing techniques are then used to extract keywords, syntactic structures, and semantic relationships from the text that reflect the intent of the command, such as extracting core action words like "please stamp" and "sign," along with their contextual information.
[0075] S302 performs liveness detection based on audio temporal features and intent detection based on semantic features.
[0076] In this embodiment, liveness detection is used to determine whether the current voice command originates from a real biological entity, rather than a pre-recorded audio file or a sound generated by synthesis software. It utilizes subtle physiological information contained in the audio temporal features, such as breathing sounds, lip-teeth fricatives, or minute vibrations of specific rhythms. These features exhibit randomness and continuity in real speech, while recorded playback often suffers from missing high-frequency components or periodic distortion in specific frequency bands. The extracted audio temporal features are input into a pre-trained liveness detection binary classifier. This classifier analyzes the statistical distribution of the feature sequence and outputs a probability determination of whether the voice command belongs to a live or non-live entity. If the determination result is live, it indicates that the command was issued in real time by a person present, thus effectively resisting recorded playback attacks.
[0077] Intent recognition is used to analyze whether the voice commands issued by the operator conform to the preset legal signing operation specifications. The mobile device calculates the similarity or matching degree between semantic features and preset intent template features to determine the user's true intent. An intent classification model is constructed, including positive examples such as performing a signing, starting to stamp, and confirming signing, as well as negative examples such as playing music, making a phone call, and checking the weather. In the inference stage, semantic features are input into the model, and the model outputs the intent category to which the instruction belongs by analyzing sentence structure, keyword matching degree, and contextual logic. If the recognition result falls within the range of legal signing intent categories, it indicates that the instruction content meets the business operation requirements, avoiding erroneous signing operations triggered by accidental wake-up or irrelevant voice.
[0078] S303, determine whether the voice signature command is a valid command based on the liveness detection result and the intent detection result.
[0079] In this embodiment, a logical AND operation is performed on the obtained liveness detection result and intent detection result. That is, the voice signature command is determined to be a legal command only if both conditions are met simultaneously: the liveness detection result confirms that the voice is a real person speaking and the intent detection result confirms that the voice is intended to sign. If either of the detection results is negative, such as the liveness detection result indicating that the voice is playing a recording or the intent detection result indicating that the voice is an irrelevant command, the subsequent process is immediately terminated and the command is marked as an illegal command.
[0080] Through a multi-dimensional cross-validation mechanism, instructions that only have legitimate voice content but are not from the real source, or instructions that are from the real source but whose content is irrelevant to the signing operation, can be effectively filtered out. This ensures that only voice instructions issued by real users with a clear intention to sign can pass the security test, thereby improving the anti-attack capability and operational accuracy of the electronic signature system.
[0081] In one possible implementation, after the signing operation is confirmed to have been completed, the signing operation record and the file information of the target file are automatically obtained. Subsequently, the signing operation record, file information, and multi-dimensional identity features are integrated, and the integrated data is encrypted using a preset encryption algorithm. The generated ciphertext data is then written into the traceability extension domain of the target file. This allows the construction of an audit evidence chain for the signing behavior, achieving precise traceability by strongly binding the operation data to the file itself. In this regard, the electronic signature control method provided in this application embodiment further includes the following steps:
[0082] Upon completion of the signing operation, the signing operation record and the file information of the target file are obtained. The signing operation record, file information, and multi-dimensional identity features are then encrypted and written into the traceability extension field of the target file.
[0083] In this embodiment, the signature operation record is a structured data set representing the execution status of the entire signature process, rather than simple log text. This signature operation record includes at least the signature start timestamp, signature completion timestamp, operation result status code (e.g., the specific reason for success or failure), confirmation receipt information from the server-side verification, and the version identifier of the signature algorithm, which can represent the complete temporal logic and operational status of the underlying physical signature action.
[0084] The target file's information is used to uniquely identify the object being signed. This includes the target file's hash value (such as a SHA-256 digest), the original filename, file size, and file storage path. The file hash value ensures the integrity of the file content, effectively preventing logical vulnerabilities where a signature remains valid even if the file has been replaced.
[0085] Multidimensional identity features can include biometric and device feature data that have been collected and uploaded to the server, including the user's voiceprint features and the mobile terminal fingerprint, which can identify the operator and the physical device used from a physiological and behavioral perspective.
[0086] Once the signing operation based on the fragmented private key is completed, the local log collection interface is immediately invoked to capture the signing operation record; at the same time, the metadata of the target file is read through the file system interface to generate file information; for multi-dimensional identity features, a copy of the feature data generated in this session is extracted from the temporary memory buffer or secure storage area.
[0087] After encapsulating the obtained signature operation records, document information, and multi-dimensional identity features into a data packet to be stored, the data packet is encrypted using a preset encryption algorithm. This encryption process can employ symmetric encryption algorithms such as Advanced Encryption Standard (AES), or a hybrid encryption mode combining asymmetric encryption algorithms, to ensure the confidentiality and tamper-proof nature of the data after it is written to the file. The encrypted ciphertext data is ultimately written to the traceability extension field of the target file.
[0088] It should be noted that the source extension field is a specific storage area reserved within the target file, distinct from the file's visible content area. It is not visible in normal reading mode and can only be read through dedicated parsing tools or authorized interfaces. The data structure in this area uses key-value pairs or a custom binary format for storage, with encrypted data blocks as values and specific identifiers as keys, thereby establishing a permanent mapping between operations and the file itself at the file's underlying level.
[0089] By transforming operational behavior data into hidden data within the file, audit information that was originally scattered in system logs or server-side databases can be transferred and stored along with the target file. This achieves a deep binding between the legal effect of the signature and the physical file, providing a real, complete, and difficult-to-forge data traceability foundation for any subsequent disputes over seal misuse or unauthorized use.
[0090] In one possible implementation, a signing operation log of the target text is generated after the signing operation is completed. To this end, an electronic signature control method provided in this application embodiment further includes the following steps:
[0091] Upon completion of the signing operation, a signing operation log of the target text is generated and uploaded to the server.
[0092] In this embodiment of the application, the signing operation log is a structured record of key node information of the entire electronic signing process, used to form a complete operation audit chain. It can include multi-dimensional data such as timestamp, operator identification, verification pass status, and signing result summary, and can reflect the complete life cycle from receiving the signing instruction to completing the signing.
[0093] During the generation of the signature operation log, the mobile device automatically captures the current system time as the base time for log generation, extracts the hash value of the verified multi-dimensional identity features as the identity verification field, and obtains the file hash value of the target text and the signature status feedback as the business result fields. Subsequently, the above fields are encapsulated and serialized according to a preset log structure template to form a standard signature operation log. Finally, the signature operation log is uploaded to the server via an encrypted communication link.
[0094] After receiving the signature operation logs, the server performs integrity verification and writes them to the central database. This not only avoids the risk of missing audit evidence due to mobile device damage, data loss, or local tampering, but also enables administrators to centrally query and monitor signature activities across regions and multiple devices in real time through the server platform, providing centralized and reliable data support for subsequent compliance audits, abnormal behavior tracing, and security strategy optimization.
[0095] The above describes an electronic signature control method provided by the embodiments of this application. The following will describe the apparatus for implementing the above electronic signature control method.
[0096] See Figure 4 , Figure 4 This is a schematic diagram of an electronic signature control device provided in an embodiment of this application. Figure 4 As shown in the figure, an electronic signature control device provided in this application includes:
[0097] The instruction response module 401 is used to respond to signature instructions, collect multi-dimensional identity features, and upload them to the server so that the server can verify the multi-dimensional identity features;
[0098] The signature control module 402 is used to receive the fragmented private key issued by the server. The fragmented private key is issued when the multi-dimensional identity feature verification is passed. It generates a signature private key based on the fragmented private key and uses the signature private key to perform a signature operation on the target file.
[0099] In one possible implementation, the instruction response module 401 is specifically used for:
[0100] The voice monitoring function is activated to collect the voice signature command input by the operator and to capture the audio data of the voice signature command; the operator's voiceprint features are extracted from the audio data, and at the same time, the terminal fingerprint of the mobile terminal is generated based on the hardware information of the mobile terminal; the voiceprint features and terminal fingerprint are uploaded to the server so that the server can verify the voiceprint features based on the voiceprint template and verify the terminal fingerprint based on the fingerprint template.
[0101] In one possible implementation, the instruction response module 401 is further configured to:
[0102] The system detects whether the voice signature command is valid based on the audio data, and if the voice signature command is valid, it executes the step of uploading the voiceprint feature and the terminal fingerprint to the server.
[0103] In one possible implementation, the instruction response module 401, used to detect whether the voice signature instruction is a valid instruction based on the audio data, is specifically used for:
[0104] Extract audio temporal and semantic features of voice signature instructions from audio data; perform liveness detection based on audio temporal features and intent detection based on semantic features; determine whether the voice signature instruction is a legitimate instruction based on the liveness detection results and intent detection results.
[0105] In one possible implementation, the signature control module 402 is also used for:
[0106] Upon completion of the signing operation, the signing operation record and the file information of the target file are obtained. The signing operation record, file information, and multi-dimensional identity features are then encrypted and written into the traceability extension field of the target file.
[0107] In one possible implementation, the signature control module 402 is also used for:
[0108] Upon completion of the signing operation, a signing operation log of the target text is generated and uploaded to the server.
[0109] It should be noted that the detailed functions of each module in the embodiments of this application can be found in the corresponding disclosure of the above-mentioned electronic signature control method embodiments, and will not be repeated here.
[0110] This application also provides an electronic device in its embodiments. See also... Figure 5 , Figure 5 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. The electronic device in this embodiment may include, but is not limited to, fixed terminals such as mobile phones, laptops, PDAs (personal digital assistants), PADs (tablet computers), desktop computers, etc. Figure 5 The electronic device shown is merely an example and should not impose any limitation on the functionality and scope of use of the embodiments of this application.
[0111] like Figure 5 As shown, the electronic device may include a processing unit (e.g., a central processing unit, a graphics processing unit, etc.) 501, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 502 or a program loaded from a storage device 508 into a random access memory (RAM) 503. When the electronic device is powered on, the RAM 503 also stores various programs and data required for the operation of the electronic device. The processing unit 501, ROM 502, and RAM 503 are interconnected via a bus 504. An input / output (I / O) interface 505 is also connected to the bus 504.
[0112] Typically, the following devices can be connected to I / O interface 505: input devices 506 including, for example, touchscreens, touchpads, keyboards, mice, cameras, microphones, accelerometers, gyroscopes, etc.; output devices 507 including, for example, liquid crystal displays (LCDs), speakers, vibrators, etc.; storage devices 508 including, for example, memory cards, hard drives, etc.; and communication devices 509. Communication device 509 allows electronic devices to communicate wirelessly or wiredly with other devices to exchange data. Although Figure 5 Electronic devices with various devices are shown, but it should be understood that it is not required to implement or have all of the devices shown. More or fewer devices may be implemented or have alternatively.
[0113] This application also provides a computer program product, including computer-readable instructions, which, when executed on an electronic device, cause the electronic device to implement any of the electronic signature control methods provided in this application.
[0114] This application also provides a computer-readable storage medium that carries one or more computer programs. When the one or more computer programs are executed by an electronic device, the electronic device can implement any of the electronic signature control methods provided in this application.
[0115] It should also be noted that the device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. In addition, in the device embodiment drawings provided in this application, the connection relationship between modules indicates that they have a communication connection, which can be implemented as one or more communication buses or signal lines.
[0116] Through the above description of the embodiments, those skilled in the art can clearly understand that this application can be implemented by means of software plus necessary general-purpose hardware, or it can be implemented by special-purpose hardware including application-specific integrated circuits, special-purpose CPUs, special-purpose memory, special-purpose components, etc. Generally, any function performed by a computer program can be easily implemented by corresponding hardware, and the specific hardware structure used to implement the same function can also be diverse, such as analog circuits, digital circuits, or special-purpose circuits. However, for this application, software program implementation is more often the preferred implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a readable storage medium, such as a computer floppy disk, USB flash drive, mobile hard disk, ROM, RAM, magnetic disk, or optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, training equipment, or network device, etc.) to execute the methods described in the various embodiments of this application.
[0117] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented in software, it can be implemented, in whole or in part, as a computer program product.
[0118] The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions may be transmitted from one website, computer, training device, or data center to another website, computer, training device, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium may be any available medium that a computer can store or a data storage device such as a training device or data center that integrates one or more available media. The available media may be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., DVDs), or semiconductor media (e.g., solid-state drives (SSDs)).
Claims
1. A method for controlling electronic signatures, characterized in that, The electronic signature control method is applied to mobile devices, and the electronic signature control method includes: In response to a signature command, multi-dimensional identity features are collected and uploaded to the server so that the server can verify the multi-dimensional identity features. Receive the fragmented private key issued by the server, which is issued when the multidimensional identity feature verification is successful; A signing private key is generated based on the fragmented private key, and the signing private key is used to perform a signing operation on the target file.
2. The electronic signature control method according to claim 1, characterized in that, The response signature command collects multi-dimensional identity features and uploads them to the server so that the server can verify the multi-dimensional identity features, including: The voice monitoring function is activated to collect the voice signing instructions input by the operator and to extract the audio data of the voice signing instructions. The voiceprint features of the operator are extracted from the audio data, and at the same time, the terminal fingerprint of the mobile device is generated based on the hardware information of the mobile device. The voiceprint feature and the terminal fingerprint are uploaded to the server so that the server can verify the voiceprint feature based on the voiceprint template and verify the terminal fingerprint based on the fingerprint template.
3. The electronic signature control method according to claim 2, characterized in that, The process of responding to a signature instruction, collecting multi-dimensional identity features, and uploading them to the server so that the server can verify the multi-dimensional identity features, also includes: The system detects whether the voice signature command is a valid command based on the audio data, and if the voice signature command is a valid command, it executes the step of uploading the voiceprint feature and the terminal fingerprint to the server.
4. The electronic signature control method according to claim 3, characterized in that, The step of detecting whether the voice signature instruction is a valid instruction based on the audio data includes: Extract the audio temporal and semantic features of the voice signature instruction from the audio data; Liveness detection is performed based on the audio temporal features, and intent detection is performed based on the semantic features; The validity of the voice signature command is determined based on the results of liveness detection and intent recognition.
5. The electronic signature control method according to claim 1, characterized in that, The electronic signature control method also includes: Upon completion of the signing operation, the signing operation record and the file information of the target file are obtained, and the signing operation record, the file information, and the multidimensional identity features are encrypted and written into the traceability extension field of the target file.
6. The electronic signature control method according to claim 1, characterized in that, The electronic signature control method also includes: Upon completion of the signing operation, a signing operation log of the target text is generated and uploaded to the server.
7. An electronic signature control device, characterized in that, The electronic signature control device is applied to a mobile terminal, and the electronic signature control device includes: The instruction response module is used to respond to signature instructions, collect multi-dimensional identity features, and upload them to the server so that the server can verify the multi-dimensional identity features. The signature control module is used to receive the fragmented private key issued by the server, which is issued when the multi-dimensional identity feature verification is successful; generate a signature private key based on the fragmented private key; and use the signature private key to perform a signature operation on the target file.
8. A computer program product, characterized in that, It includes computer-readable instructions that, when executed on an electronic device, cause the electronic device to implement the electronic signature control method as described in any one of claims 1 to 6.
9. An electronic device, characterized in that, It includes at least one processor and a memory connected to the processor, wherein: The memory is used to store computer programs; The processor is used to execute the computer program to enable the electronic device to implement the electronic signature control method as described in any one of claims 1 to 6.
10. A computer storage medium, characterized in that, The storage medium carries one or more computer programs, which, when executed by an electronic device, enable the electronic device to implement the electronic signature control method as described in any one of claims 1 to 6.