CN101763677A - System for authenticating endorsement signature on information medium - Google Patents

System for authenticating endorsement signature on information medium Download PDF

Info

Publication number
CN101763677A
CN101763677A CN200910235825A CN200910235825A CN101763677A CN 101763677 A CN101763677 A CN 101763677A CN 200910235825 A CN200910235825 A CN 200910235825A CN 200910235825 A CN200910235825 A CN 200910235825A CN 101763677 A CN101763677 A CN 101763677A
Authority
CN
China
Prior art keywords
information
cipher
safety feature
signing messages
text information
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
CN200910235825A
Other languages
Chinese (zh)
Other versions
CN101763677B (en
Inventor
须清
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Beijing Paragon Technology Co Ltd
Original Assignee
Beijing Paragon Technology Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Beijing Paragon Technology Co Ltd filed Critical Beijing Paragon Technology Co Ltd
Priority to CN2009102358250A priority Critical patent/CN101763677B/en
Publication of CN101763677A publication Critical patent/CN101763677A/en
Application granted granted Critical
Publication of CN101763677B publication Critical patent/CN101763677B/en
Expired - Fee Related legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Abstract

The invention provides a system for authenticating an endorsement signature on an information medium, comprising an authentication server, the information medium and a safety device. The authentication server comprises an information collection component, a data storage stack and a safety device interface component. The safety device comprises a secrete key of an endorsee and a decryption algorithm implementation module. Authorized signature information is stored in the data storage stack. The information collection component collects ciphertext information and converts the ciphertext information into ciphertext information data processed by the authentication server. The authentication server transfers the ciphertext information data to the safety device, and the safety device decrypts plaintext of obtained signature information and transfers the plaintext of the signature information to the authentication server. The authentication server realizes authentication of the information medium by judging whether the plaintext of the signature information is consistent with the authorized signature information by comparison. By adopting the technology of the invention, the uniqueness and the non-imitability of the signature information are improved, thus ensuring the electronic bill to be used more safely. The system can obviously reduce the risks in using the electronic bill and promote the development of the modern financial industry.

Description

To the system of endorsing and signing and authenticate on the information medium
Technical field
The present invention relates to system that endorsement signature on the information medium is authenticated, particularly relate to and be printed on the information medium after the endorsement signing messages encrypted and pass to the system that the endorsement signature that is used for bill identification of the electronic unit that is embedded in the medium authenticates.
Background technology
Along with the development of modern economy, the health of financial circles, orderly, safe development are significant for current economic development.In the financial circles development, popularize to the comprehensive of various financial documents gradually from money transaction, become the main means of payment that miscellaneous service is carried out in the modern economy as the letter of credit, cashier's cheque, check etc.But because the value of financial document itself and circulation are subjected to very big challenge for the security of financial document.Report is arranged when forging case that the letter of credit, cashier's cheque, check carry out financial swindling all over the world.And owing to the circulation of the letter of credit, cashier's cheque, check can repeatedly be transferred the possession of, and wherein any once transfer appearance forgery all may bring massive losses to the related side.
With regard to the antifalsification of the present employed letter of credit, cashier's cheque, check normally based on some anti-false signs on concession manufacturing and the ticket; The validation of the letter of credit, cashier's cheque, check is based on the person's that provides the bill signature or endorsement.And based on the reason of cost and technology, the anti-false sign of the letter of credit, cashier's cheque, check is also uncomplicated, is easy to be copied by the fake producer.And there are two problems in the signature or the endorsement that are used for the validation of the letter of credit, cashier's cheque, check: be that signature or the endorsement that same individual carries out in decentraction situation attitude, different time points can not guarantee in full accord on the one hand, cause effective signature or endorsement to be rejected acceptance, be because signature that requires to carry out or endorsement must be basic identical at every turn on the other hand, for the fake producer provides the chance of faking.Signer or endorsement person's signature or endorsement information is no matter how unique, in case seen signature or endorsement information by illegal person, the exercise by certain hour can realize the imitation for signature or endorsement information fully.And be to compare by human eye to judge for the validation of the letter of credit, cashier's cheque, check now.The safety technique that obvious existing ticket adopted can not provide safeguard for the Secure Transaction function that realizes bill.
Use the replacement that carves a seal for many years to sign in China, though guaranteed the consistance of each signature, owing to carve a seal too easily by imitated, so and dangerous.Even by the administrative intervention of government, take the administrative authorization mode to specify and have only professional could carry out the business of carving a seal, but can not stop illegal person's imitated behavior owing to the technical not high of itself through authorizing.Though extensively popularizing of the development of modern network technology and internet is for the development of financial circles brings new opportunity.As Internet-based banking services and for the electronic key authentication techniques that guarantee Internet-based banking services safety are just becoming the important directions that modern finance already develops, but the safety that also greatly threatening Web bank such as network hacker, virus, fishing program simultaneously.Be still the major transaction instrument of modern finance industry based on the business transaction of financial document.
Summary of the invention
Technical matters to be solved by this invention is how to strengthen the safety of electronic bill and how to guarantee the signing messages of electronic bill and/or the security and the validity of endorsement information, and realize effective circulation of electronic bill in the mode of a kind of easy identification and use, to reduce the risk in the electronic bill use, promote the development of modern finance industry.
Term explanation: during technical solution of the present invention is described, " Electronic Paper " be meant comprise have that bistable state or multistable electronic material constitute can display message equipment or parts or flexible display material, can change its displaying contents by electronization.The electrodeless Electronic Paper of Beijing Pai Ruigen scientific and technological invention, the electric wetting Electronic Paper of Beijing Pai Ruigen scientific and technological invention, the electric ink of E-ink company, the electrophoresis cartridge of SIPIX company etc. are typically arranged.
The term explanation: during technical solution of the present invention was described, financial document was to be used to carry out the voucher relevant with financial business in the financial business field.Write down at least one information relevant on the bill with financial business.
The term explanation: during technical solution of the present invention was described, electronic bill was to be applied to every field and professional relevant voucher.Write down at least one information relevant on the bill with business.Comprise passenger ticket in financial document, the communications and transportation and shipping ticket, film ticket, food and drink ticket, coupons, lottery ticket etc.
Term explanation: among the present invention, endorsement is meant that the owner of bill transfers other people with bill and the behavior confirmed.Show as and on bill, stay at least one and prove information or the sign of bill owner in order to confirm.
The term explanation: during technical solution of the present invention was described, radio electronic label, RFID, RF Tag, RFID tag, electronic tag etc. had identical implication.
The term explanation: during technical solution of the present invention was described, the implication of " endorsement " was meant in industries such as financial field, and electronic bill is expressed the proof information that realizes relevant proprietorial transfer of electronic bill or payment respective value fund by information specific.The implication of " remote holder endorsement " is to show that the bill that the electronic bill holder is obtained is that its bill supplier transfers the bill holder by " endorsement ", and the information of " remote holder endorsement " is that the validity of this transfer proves.
For addressing the above problem, the technical solution that proposes is at first to design a kind of Electronic Signature, employing presents the information of Electronic Signature in a kind of visible mode, even be that the information of Electronic Signature is not easy imitated or has imitated the thinking of dealing with problems that can not effectively use simultaneously.At first, the electronic bill that technical solution of the present invention adopted and the electronic bill of prior art have difference, and the present invention is adopted as the special technology scheme of the present invention that realizes.
1, a kind of electronic bill is characterized in that comprising information medium, sets a particular signature zone at the front and/or the reverse side of described information medium, signing messages is encrypted the cipher-text information that obtains be printed on described particular signature zone usefulness.
2, a kind of electronic bill, it is characterized in that comprising information medium, in described information medium, embedded electronic unit and in the front of described information medium and/or reverse side set a particular signature zone, signing messages is encrypted the cipher-text information that obtains is printed on described particular signature zone and/or signing messages is encrypted the cipher-text information that obtains and write in the described electronic unit; Perhaps with signing messages with encrypt the cipher-text information that obtains from the data message that described electronic unit reads and be printed on described particular signature zone and/or will comprise signing messages and encrypt the cipher-text information that obtains and write the described electronic unit from the data message that described electronic unit reads.
3, a kind of electronic bill, it is characterized in that comprising information medium, in described information medium, embedded electronic unit and in the front of described information medium and/or reverse side set a particular signature zone, with signing messages encrypt the cipher-text information that obtains all or first's whole or second portion of being printed on described particular signature zone and/or signing messages being encrypted the cipher-text information that obtains write in the described electronic unit; Perhaps be printed on described particular signature zone and/or write the described electronic unit with signing messages with from the whole or second portion that the data message that described electronic unit reads is encrypted the cipher-text information that obtains with signing messages with from the whole or first that the data message that described electronic unit reads is encrypted the cipher-text information that obtains.
4, a kind of mixed electronic bill, it is characterized in that comprising information medium, at least one zone of described information medium comprises Electronic Paper, in the front of described information medium and/or reverse side set first particular signature zone and set the second particular signature zone at described electronics recto and/or reverse side, signing messages is encrypted the cipher-text information that obtains is printed on described first particular signature zone and/or signing messages is encrypted the cipher-text information that obtains and be presented on the described second particular signature zone by electronization.
5, a kind of mixed electronic bill, it is characterized in that comprising information medium, at least one zone of described information medium comprises Electronic Paper, in the front of described information medium and/or reverse side set first particular signature zone and set the second particular signature zone at described electronics recto and/or reverse side, it is regional and/or be presented on the described second particular signature zone by the whole or second portion that electronization is encrypted signing messages the cipher-text information that obtains that the whole or first of signing messages being encrypted the cipher-text information that obtains is printed on described first particular signature.
6, a kind of mixed electronic bill, it is characterized in that comprising information medium, at least one zone of described information medium comprises Electronic Paper, in described information medium, embedded electronic unit, in the front of described information medium and/or reverse side set first particular signature zone and set the second particular signature zone at described electronics recto and/or reverse side, signing messages is encrypted the cipher-text information that obtains is printed on described first particular signature zone and/or signing messages is encrypted the cipher-text information that obtains and be presented on described second particular signature zone and/or signing messages is encrypted the cipher-text information that obtains and write in the described electronic unit by electronization.
7, a kind of mixed electronic bill, it is characterized in that comprising information medium, at least one zone of described information medium comprises Electronic Paper, in described information medium, embedded electronic unit, in the front of described information medium and/or reverse side set first particular signature zone and set the second particular signature zone at described electronics recto and/or reverse side, the whole or first of signing messages being encrypted the cipher-text information that obtains is printed on described first particular signature zone and/or is presented on described second particular signature whole or third part regional and/or that signing messages is encrypted the cipher-text information that obtains by the whole or second portion that electronization is encrypted signing messages the cipher-text information that obtains and writes in the described electronic unit.
8, a kind of mixed electronic bill, it is characterized in that comprising information medium, at least one zone of described information medium comprises Electronic Paper, in described information medium, embedded electronic unit, in the front of described information medium and/or reverse side set first particular signature zone and set the second particular signature zone at described electronics recto and/or reverse side, with signing messages with encrypt the cipher-text information that obtains from the data message that described electronic unit reads and be printed on described first particular signature zone and/or encrypt that the cipher-text information that obtains is presented on described second particular signature zone and/or with signing messages with encrypt the cipher-text information that obtains from the data message that described electronic unit reads and write the described electronic unit with signing messages with from the data message that described electronic unit reads by electronization.
9, a kind of mixed electronic bill, it is characterized in that comprising information medium, at least one zone of described information medium comprises Electronic Paper, in described information medium, embedded electronic unit, in the front of described information medium and/or reverse side set first particular signature zone and set the second particular signature zone at described electronics recto and/or reverse side, with signing messages and from the whole or first that the data message that described electronic unit reads is encrypted the cipher-text information that obtains be printed on described first particular signature zone and/or by electronization with signing messages with to be presented on described second particular signature from the whole or second portion that the data message that described electronic unit reads is encrypted the cipher-text information that obtains regional and/or write the described electronic unit with signing messages with from the whole or third part that the data message that described electronic unit reads is encrypted the cipher-text information that obtains.
Electronic Signature of the present invention has multiple scheme, is respectively:
1, a kind of Electronic Signature of dorsal support bookmark name, it is characterized in that on medium, signing, comprise as lower member: information processing apparatus, described information processing apparatus comprise enciphering algorithm module and have stored signing messages, endorsement person's private key information and by endorsement person's public key information;
Print module, described print module is connected with described information processing apparatus, and described print module can print information on medium;
To be password carry out cryptographic calculation to described signing messages handles and obtain cipher-text information with described endorsement person's private key information with by endorsement person's public key information by described enciphering algorithm module, by described information processing apparatus described cipher-text information is converted to the signed data that described print module prints.
2, a kind of Electronic Signature of dorsal support bookmark name is characterized in that signing comprising on the medium of electronic unit, comprises as lower member:
Information processing apparatus, described information processing apparatus comprise enciphering algorithm module and have stored signing messages, endorsement person's private key information and by endorsement person's public key information;
Print module, described print module is connected with described information processing apparatus, and described print module can print information on medium;
Module for reading and writing, described module for reading and writing is connected with described information processing apparatus, and described module for reading and writing writes data in electronic unit;
To be password carry out cryptographic calculation to described signing messages handles and obtain cipher-text information with described endorsement person's private key information with by endorsement person's public key information by described enciphering algorithm module, by described information processing apparatus described cipher-text information is converted to the signed data that described module for reading and writing writes in electronic unit; And/or described cipher-text information is converted to the signed data that described print module prints by described information processing apparatus.
3, a kind of Electronic Signature of dorsal support bookmark name is characterized in that signing comprising on the medium of electronic unit, comprises as lower member:
Information processing apparatus, described information processing apparatus comprise enciphering algorithm module and have stored signing messages, endorsement person's private key information and by endorsement person's public key information;
Print module, described print module is connected with described information processing apparatus, and described print module can print information on medium;
Module for reading and writing, described module for reading and writing is connected with described information processing apparatus, and described module for reading and writing writes data in electronic unit;
To be password carry out cryptographic calculation to described signing messages handles and obtain cipher-text information with described endorsement person's private key information with by endorsement person's public key information by described enciphering algorithm module, by described information processing apparatus the whole or first of described cipher-text information is converted to the signed data that described module for reading and writing writes in electronic unit; And/or the whole or second portion of described cipher-text information is converted to the signed data that described print module prints by described information processing apparatus.
4, a kind of Electronic Signature of dorsal support bookmark name is characterized in that signing comprising on the medium of electronic unit, comprises as lower member:
Information processing apparatus, described information processing apparatus comprise enciphering algorithm module and have stored signing messages, endorsement person's private key information and by endorsement person's public key information;
Print module, described print module is connected with described information processing apparatus, and described print module can print information on medium;
Module for reading and writing, described module for reading and writing is connected with described information processing apparatus, and described module for reading and writing writes data and/or reading of data from electronic unit in electronic unit;
To be password carry out cryptographic calculation to the data that read, described signing messages from electronic unit handle and obtain cipher-text information with described endorsement person's private key information with by endorsement person's public key information by described enciphering algorithm module, by described information processing apparatus described cipher-text information is converted to the signed data that described module for reading and writing writes in electronic unit; And/or described cipher-text information is converted to the signed data that described print module prints by described information processing apparatus.
5, a kind of Electronic Signature of dorsal support bookmark name is characterized in that signing comprising on the medium of electronic unit, comprises as lower member:
Information processing apparatus, described information processing apparatus comprise enciphering algorithm module and have stored signing messages, endorsement person's private key information and by endorsement person's public key information;
Print module, described print module is connected with described information processing apparatus, and described print module can print information on medium;
Module for reading and writing, described module for reading and writing is connected with described information processing apparatus, and described module for reading and writing writes data and/or reading of data from electronic unit in electronic unit;
To be password carry out cryptographic calculation to the data that read, described signing messages from electronic unit handle and obtain cipher-text information with described endorsement person's private key information with by endorsement person's public key information by described enciphering algorithm module, by described information processing apparatus the whole or first of described cipher-text information is converted to the signed data that described module for reading and writing writes in electronic unit; And/or the whole or second portion of described cipher-text information is converted to the signed data that described print module prints by described information processing apparatus.
6, a kind of multifunction electronic signature of dorsal support bookmark name is characterized in that signing at least one regional area has embedded the medium of Electronic Paper, comprises:
Information processing apparatus, described information processing apparatus comprise enciphering algorithm module and have stored signing messages, endorsement person's private key information and by endorsement person's public key information;
Print module, described print module is connected with described information processing apparatus, and described print module can print information on medium;
Electronic Paper electronization module, described Electronic Paper electronization module is connected with described information processing apparatus, and described Electronic Paper electronization module can be carried out electronization at least one regional area or the whole zone of Electronic Paper;
To be password carry out cryptographic calculation to described signing messages handles and obtain cipher-text information with described endorsement person's private key information with by endorsement person's public key information by described enciphering algorithm module, by described information processing apparatus described cipher-text information is converted to the graphical signed data that described Electronic Paper electronization module is carried out electronization; And/or described cipher-text information is converted to the printed signature information that described print module prints by described information processing apparatus.
10, a kind of multifunction electronic signature of dorsal support bookmark name is characterized in that signing at least one regional area has embedded the medium of Electronic Paper, comprises:
Information processing apparatus, described information processing apparatus comprise enciphering algorithm module and have stored signing messages, endorsement person's private key information and by endorsement person's public key information;
Print module, described print module is connected with described information processing apparatus, and described print module can print information on medium;
Electronic Paper electronization module, described Electronic Paper electronization module is connected with described information processing apparatus, and described Electronic Paper electronization module can be carried out electronization at least one regional area or the whole zone of Electronic Paper;
To be password carry out cryptographic calculation to described signing messages handles and obtain cipher-text information with described endorsement person's private key information with by endorsement person's public key information by described enciphering algorithm module, by described information processing apparatus described cipher-text information is converted to the graphical signed data that described Electronic Paper electronization module is carried out electronization; And/or described cipher-text information is converted to the printed signature information that described print module prints by described information processing apparatus.
Adopt the endorse method of signature of the Electronic Signature of above-mentioned dorsal support bookmark name as follows:
1, a kind of method that endorsement is signed on information medium is characterized in that comprising following steps:
Is that password adopts first computing module of rivest, shamir, adelman to carry out calculation process to obtain first operation result with signing messages with endorsement person's private key, is that password adopts second computing module of rivest, shamir, adelman to carry out calculation process to obtain encrypt data to described first operation result with quilt endorsement person's PKI; Perhaps
Is that password adopts first computing module of rivest, shamir, adelman to carry out calculation process to obtain first operation result with signing messages with quilt endorsement person's PKI, is that password adopts second computing module of rivest, shamir, adelman to carry out calculation process to obtain encrypt data to described first operation result with endorsement person's private key; Perhaps
With signing messages is that password adopts first computing module of rivest, shamir, adelman to carry out calculation process to obtain first operation result with the private key of signer partly or entirely, with signing messages is that password adopts second computing module of rivest, shamir, adelman to carry out calculation process to obtain second operation result, described first operation result and described second operation result are combined in certain sequence as encrypt data with quilt endorsement person's PKI partly or entirely;
Described encrypt data is converted to printed signature information;
Described printed signature information is printed on the information medium.
2, a kind of method that endorsement is signed on information medium is characterized in that described information medium has embedded electronic unit, and signature comprises following steps:
Is that password adopts first computing module of rivest, shamir, adelman to carry out calculation process to obtain first operation result with signing messages with endorsement person's private key, is that password adopts second computing module of rivest, shamir, adelman to carry out calculation process to obtain encrypt data to described first operation result with quilt endorsement person's PKI; Perhaps
Is that password adopts first computing module of rivest, shamir, adelman to carry out calculation process to obtain first operation result with signing messages with quilt endorsement person's PKI, is that password adopts second computing module of rivest, shamir, adelman to carry out calculation process to obtain encrypt data to described first operation result with endorsement person's private key; Perhaps
With signing messages is that password adopts first computing module of rivest, shamir, adelman to carry out calculation process to obtain first operation result with the private key of signer partly or entirely, with signing messages is that password adopts second computing module of rivest, shamir, adelman to carry out calculation process to obtain second operation result, described first operation result and described second operation result are combined in certain sequence as encrypt data with quilt endorsement person's PKI partly or entirely;
Described encrypt data is converted to the signed data that writes to described electronic unit, and described encrypt data is converted to printed signature information;
Described signed data is write described electronic unit, and described printed signature information is printed on the information medium.
3, a kind of method that endorsement is signed on information medium is characterized in that described information medium has embedded electronic unit, and signature comprises following steps:
Read data information from electronic unit;
Is that password adopts first computing module of rivest, shamir, adelman to carry out calculation process to obtain first operation result with signing messages and described data message with endorsement person's private key, is that password adopts second computing module of rivest, shamir, adelman to carry out calculation process to obtain encrypt data to described first operation result with quilt endorsement person's PKI; Perhaps
Is that password adopts first computing module of rivest, shamir, adelman to carry out calculation process to obtain first operation result with signing messages and described data message with quilt endorsement person's PKI, is that password adopts second computing module of rivest, shamir, adelman to carry out calculation process to obtain encrypt data to described first operation result with endorsement person's private key; Perhaps
With signing messages and described data message is that password adopts first computing module of rivest, shamir, adelman to carry out calculation process to obtain first operation result with the private key of signer partly or entirely, with signing messages and described data message is that password adopts second computing module of rivest, shamir, adelman to carry out calculation process to obtain second operation result, described first operation result and described second operation result are combined in certain sequence as encrypt data with quilt endorsement person's PKI partly or entirely;
Described encrypt data is converted to the signed data that writes to described electronic unit, and described encrypt data is converted to printed signature information;
Described signed data is write described electronic unit, and described printed signature information is printed on the information medium.
4, a kind of method that endorsement is signed on information medium is characterized in that described information medium has embedded electronic unit, and signature comprises following steps:
Is that password adopts first computing module of rivest, shamir, adelman to carry out calculation process to obtain first operation result with signing messages with endorsement person's private key, is that password adopts second computing module of rivest, shamir, adelman to carry out calculation process to obtain encrypt data to described first operation result with quilt endorsement person's PKI; Perhaps
Is that password adopts first computing module of rivest, shamir, adelman to carry out calculation process to obtain first operation result with signing messages with quilt endorsement person's PKI, is that password adopts second computing module of rivest, shamir, adelman to carry out calculation process to obtain encrypt data to described first operation result with endorsement person's private key; Perhaps
With signing messages is that password adopts first computing module of rivest, shamir, adelman to carry out calculation process to obtain first operation result with the private key of signer partly or entirely, with signing messages is that password adopts second computing module of rivest, shamir, adelman to carry out calculation process to obtain second operation result, described first operation result and described second operation result are combined in certain sequence as encrypt data with quilt endorsement person's PKI partly or entirely;
With the first of described encrypt data or all be converted to the signed data that writes to described electronic unit, and with the second portion of described encrypt data or all be converted to printed signature information;
Described signed data is write described electronic unit, and described printed signature information is printed on the information medium.
5, a kind of method that endorsement is signed on information medium is characterized in that described information medium has embedded electronic unit, and signature comprises following steps:
Read data information from electronic unit;
Is that password adopts first computing module of rivest, shamir, adelman to carry out calculation process to obtain first operation result with signing messages and described data message with endorsement person's private key, is that password adopts second computing module of rivest, shamir, adelman to carry out calculation process to obtain encrypt data to described first operation result with quilt endorsement person's PKI; Perhaps
Is that password adopts first computing module of rivest, shamir, adelman to carry out calculation process to obtain first operation result with signing messages and described data message with quilt endorsement person's PKI, is that password adopts second computing module of rivest, shamir, adelman to carry out calculation process to obtain encrypt data to described first operation result with endorsement person's private key; Perhaps
With signing messages and described data message is that password adopts first computing module of rivest, shamir, adelman to carry out calculation process to obtain first operation result with the private key of signer partly or entirely, with signing messages and described data message is that password adopts second computing module of rivest, shamir, adelman to carry out calculation process to obtain second operation result, described first operation result and described second operation result are combined in certain sequence as encrypt data with quilt endorsement person's PKI partly or entirely;
With the first of described encrypt data or all be converted to the signed data that writes to described electronic unit, and with the second portion of described encrypt data or all be converted to printed signature information;
Described signed data is write described electronic unit, and described printed signature information is printed on the information medium.
6, preferably before described each step, safety component is carried out the information communication of information connection and foundation and electronic signature body by the interface unit of electronic signature body.
As follows to the system schema that the endorsement signing messages authenticates:
1, a kind of system that endorsement signature on the information medium is authenticated is characterized in that comprising:
Certificate server, described certificate server comprise information acquisition parts, data back, safety feature interface unit;
Information medium, described information medium surface has pair signing messages to encrypt the cipher-text information that obtains;
Safety feature, described safety feature comprise by endorsement person's key and decipherment algorithm realizes module;
Described certificate server is undertaken by described safety feature interface unit and described safety feature that wire signal is connected or wireless signal connects;
Stored described information medium owner's approval signing messages in the described data back;
Described information acquisition parts are gathered described cipher-text information and described cipher-text information are converted to the cipher-text information data of being handled by described certificate server;
Described certificate server is given described safety feature with the cipher-text information data transfer, by described safety feature described cipher-text information data is decrypted the plaintext that obtains signing messages and the plaintext of signing messages is passed to described certificate server;
The whether consistent authentication that realizes information medium of the approval signing messages of storage in advance in the plaintext of described certificate server by more described signing messages and the described data back.
2, a kind of system that endorsement signature on the information medium is authenticated is characterized in that comprising:
Certificate server, described certificate server comprise information acquisition parts, data back, safety feature interface unit;
Information medium has embedded electronic unit in the described information medium, has write in described electronic unit signing messages is encrypted the cipher-text information that obtains;
Safety feature, described safety feature comprise by endorsement person's key and decipherment algorithm realizes module;
Described certificate server is undertaken by described safety feature interface unit and described safety feature that wire signal is connected or wireless signal connects;
Stored described information medium owner's approval signing messages in the described data back;
Described information acquisition parts are gathered described cipher-text information and described cipher-text information are converted to the cipher-text information data of being handled by described certificate server;
Described certificate server is given described safety feature with the cipher-text information data transfer, by described safety feature described cipher-text information data is decrypted the plaintext that obtains signing messages and the plaintext of signing messages is passed to described certificate server;
The whether consistent authentication that realizes information medium of the approval signing messages of storage in advance in the plaintext of described certificate server by more described signing messages and the described data back.
3, a kind of system that endorsement signature on the information medium is authenticated is characterized in that comprising:
Certificate server, described certificate server comprise information acquisition parts, data back, safety feature interface unit;
Information medium, described information medium comprises Electronic Paper, has in the described Electronic Paper signing messages is encrypted the cipher-text information that obtains;
Safety feature, described safety feature comprise by endorsement person's key and decipherment algorithm realizes module;
Described certificate server is undertaken by described safety feature interface unit and described safety feature that wire signal is connected or wireless signal connects;
Stored described information medium owner's approval signing messages in the described data back;
Described information acquisition parts are gathered described cipher-text information and described cipher-text information are converted to the cipher-text information data of being handled by described certificate server;
Described certificate server is given described safety feature with the cipher-text information data transfer, by described safety feature described cipher-text information data is decrypted the plaintext that obtains signing messages and the plaintext of signing messages is passed to described certificate server;
The whether consistent authentication that realizes information medium of the approval signing messages of storage in advance in the plaintext of described certificate server by more described signing messages and the described data back.
4, a kind of system that endorsement signature on the information medium is authenticated is characterized in that comprising:
Certificate server, described certificate server comprise information acquisition parts, data back, safety feature interface unit;
Information medium, embedded electronic unit in the described information medium, write the first of signing messages being encrypted the cipher-text information that obtains in described electronic unit, described information medium surface has pair signing messages to encrypt the second portion of the cipher-text information that obtains;
Safety feature, described safety feature comprise by endorsement person's key and decipherment algorithm realizes module;
Described certificate server is undertaken by described safety feature interface unit and described safety feature that wire signal is connected or wireless signal connects;
Stored described information medium owner's approval signing messages in the described data back;
Described information acquisition parts are gathered the second portion of the first of described cipher-text information and cipher-text information and the first of described cipher-text information and the second portion of cipher-text information are converted to the cipher-text information data of being handled by described certificate server;
Described certificate server is given described safety feature with the cipher-text information data transfer, by described safety feature described cipher-text information data is decrypted the plaintext that obtains signing messages and the plaintext of signing messages is passed to described certificate server;
The whether consistent authentication that realizes information medium of the approval signing messages of storage in advance in the plaintext of described certificate server by more described signing messages and the described data back.
5, a kind of system that endorsement signature on the information medium is authenticated is characterized in that comprising:
Certificate server, described certificate server comprise information acquisition parts, data back, safety feature interface unit;
Information medium, embedded electronic unit in the described information medium, in described electronic unit, write the first of signing messages being encrypted the cipher-text information that obtains, described information medium comprises Electronic Paper, has the second portion of signing messages being encrypted the cipher-text information that obtains in the described Electronic Paper;
Safety feature, described safety feature comprise by endorsement person's key and decipherment algorithm realizes module;
Described certificate server is undertaken by described safety feature interface unit and described safety feature that wire signal is connected or wireless signal connects;
Stored described information medium owner's approval signing messages in the described data back;
Described information acquisition parts are gathered the second portion of the first of described cipher-text information and cipher-text information and the first of described cipher-text information and the second portion of cipher-text information are converted to the cipher-text information data of being handled by described certificate server;
Described certificate server is given described safety feature with the cipher-text information data transfer, by described safety feature described cipher-text information data is decrypted the plaintext that obtains signing messages and the plaintext of signing messages is passed to described certificate server;
The whether consistent authentication that realizes information medium of the approval signing messages of storage in advance in the plaintext of described certificate server by more described signing messages and the described data back.
6, a kind of system that endorsement signature on the information medium is authenticated is characterized in that comprising:
Certificate server, described certificate server comprise information acquisition parts, data back, safety feature interface unit;
Information medium, embedded electronic unit in the described information medium, in described electronic unit, write the first of signing messages being encrypted the cipher-text information that obtains, described information medium comprises Electronic Paper, have the second portion of signing messages being encrypted the cipher-text information that obtains in the described Electronic Paper, described information medium surface has pair signing messages to encrypt the third part of the cipher-text information that obtains;
Safety feature, described safety feature comprise by endorsement person's key and decipherment algorithm realizes module;
Described certificate server is undertaken by described safety feature interface unit and described safety feature that wire signal is connected or wireless signal connects;
Stored described information medium owner's approval signing messages in the described data back;
Described information acquisition parts are gathered the third part of the second portion of first, cipher-text information of described cipher-text information and cipher-text information and the first of described cipher-text information, the second portion of cipher-text information and the third part of cipher-text information are converted to the cipher-text information data of being handled by described certificate server;
Described certificate server is given described safety feature with the cipher-text information data transfer, by described safety feature described cipher-text information data is decrypted the plaintext that obtains signing messages and the plaintext of signing messages is passed to described certificate server;
The whether consistent authentication that realizes information medium of the approval signing messages of storage in advance in the plaintext of described certificate server by more described signing messages and the described data back.
7, preferably described data back stores endorsement person's public key information or the public key information that described secure device stores has endorsement person.
8, preferably described secure device stores has endorsement person's public key information and by endorsement person's private key information.
9, preferably:
Described safety feature is a contact intelligent card, and described safety feature interface unit is supported intelligent card interface; Or
Described safety feature is the usb key card, and described safety feature interface unit is supported USB (universal serial bus); Or
Described safety feature is the Wireless USB key card, and described safety feature interface unit is supported the radio universal serial line interface; Or
Described safety feature is a contact type intelligent card, and described safety feature interface unit is supported wireless radio interface; Or
Described safety feature is the contact safe memory card, and described safety feature interface unit is supported pcmcia interface or Micro SD interface or SF interface or memory stick (Memory Stick) interface.
The method that endorsement signature on the information medium is authenticated is as follows:
1, a kind of method that endorsement signature on the information medium is authenticated comprises following steps:
The cipher-text information of the conduct signature on the Information Monitoring medium;
Certificate server passes to safety feature with described cipher-text information by wire communication mode and/or wireless communication mode, by described safety feature described cipher-text information data is decrypted the plaintext that obtains signing messages and the plaintext of signing messages is passed to described authentification of message system;
Whether the plaintext of judging described signing messages mates with the approval signing messages of described authentication server stores;
If mate then authentication success;
If do not match then authentification failure.
2, a kind of method that endorsement signature on the information medium is authenticated comprises following steps:
Collection is presented on the cipher-text information of the conduct signature on the Electronic Paper of information medium;
Certificate server passes to safety feature with described cipher-text information by wire communication mode and/or wireless communication mode, by described safety feature described cipher-text information data is decrypted the plaintext that obtains signing messages and the plaintext of signing messages is passed to described authentification of message system;
Whether the plaintext of judging described signing messages mates with the approval signing messages of described authentication server stores;
If mate then authentication success;
If do not match then authentification failure.
3, a kind of method that endorsement signature on the information medium is authenticated comprises following steps:
Collection is embedded in the cipher-text information of the conduct signature that the electronic unit in the information medium stores;
Certificate server passes to safety feature with described cipher-text information by wire communication mode and/or wireless communication mode, by described safety feature described cipher-text information data is decrypted the plaintext that obtains signing messages and the plaintext of signing messages is passed to described authentification of message system;
Whether the plaintext of judging described signing messages mates with the approval signing messages of described authentication server stores;
If mate then authentication success;
If do not match then authentification failure.
4, a kind of method that endorsement signature on the information medium is authenticated comprises following steps:
Collection be embedded in the conduct signature that the electronic unit in the information medium stores cipher-text information first and gather the second portion of the cipher-text information of the conduct signature that is printed on the information medium;
Certificate server passes to safety feature with the first of described cipher-text information and the second portion of cipher-text information by wire communication mode and/or wireless communication mode, by described safety feature the second portion of the first of described cipher-text information and cipher-text information is decrypted the plaintext that obtains signing messages and the plaintext of signing messages is passed to described authentification of message system;
Whether the plaintext of judging described signing messages mates with the approval signing messages of described authentication server stores;
If mate then authentication success;
If do not match then authentification failure.
5, a kind of method that endorsement signature on the information medium is authenticated comprises following steps:
Collection be embedded in the conduct signature that the electronic unit in the information medium stores cipher-text information first and gather the second portion of the cipher-text information of the conduct signature on the Electronic Paper that is presented on information medium;
Certificate server passes to safety feature with the first of described cipher-text information and the second portion of cipher-text information by wire communication mode and/or wireless communication mode, by described safety feature the second portion of the first of described cipher-text information and cipher-text information is decrypted the plaintext that obtains signing messages and the plaintext of signing messages is passed to described authentification of message system;
Whether the plaintext of judging described signing messages mates with the approval signing messages of described authentication server stores;
If mate then authentication success;
If do not match then authentification failure.
6, a kind of method that endorsement signature on the information medium is authenticated comprises following steps:
Collection is embedded in the first of the cipher-text information of the conduct signature that the electronic unit in the information medium stores, gather the conduct signature on the Electronic Paper that is presented on information medium cipher-text information second portion and gather the third part of the cipher-text information of the conduct signature that is printed on the information medium;
Certificate server passes to safety feature with the first of described cipher-text information, the second portion of cipher-text information and the third part of cipher-text information by wire communication mode and/or wireless communication mode, by described safety feature the third part of the second portion of the first of described cipher-text information, cipher-text information and cipher-text information is decrypted the plaintext that obtains signing messages and the plaintext of signing messages is passed to described authentification of message system;
Whether the plaintext of judging described signing messages mates with the approval signing messages of described authentication server stores;
If mate then authentication success;
If do not match then authentification failure.
7, preferably carry out importing the key information that described cipher-text information is decrypted before described each step.
8, preferably carry out before described each step safety feature being connected with certificate server by the safety feature interface unit, described secure device stores has the key information that described cipher-text information is decrypted.
9, preferably safety feature could be started the key functions of components by the safety feature interface unit with the identification code that needs to import the key parts after certificate server is connected.
Beneficial effect of the present invention: the present invention improved signing messages uniqueness, can not copying property, make the use of electronic bill safer.Owing to adopt the mode of a kind of easy identification and use to realize effective signature of electronic bill, can significantly reduce the risk in the electronic bill use, promote the development of modern finance industry.
Description of drawings:
Fig. 1 is that Electronic Signature of the present invention is realized synoptic diagram for first kind.
Fig. 2 is that Electronic Signature of the present invention is realized synoptic diagram for second kind.
Fig. 3 is first kind of implementation principle of work of Electronic Signature of the present invention synoptic diagram.
Fig. 4 is second kind of implementation principle of work of Electronic Signature of the present invention synoptic diagram.
Fig. 5 is the third implementation principle of work synoptic diagram of Electronic Signature of the present invention.
Fig. 6 is the third realization synoptic diagram of Electronic Signature of the present invention.
Fig. 7 is that Electronic Signature of the present invention is realized synoptic diagram for the 4th kind.
Fig. 8 is the 4th kind of implementation principle of work synoptic diagram of Electronic Signature of the present invention.
Fig. 9 is the 5th kind of implementation principle of work synoptic diagram of Electronic Signature of the present invention.
Figure 10 is the 6th kind of implementation principle of work synoptic diagram of Electronic Signature of the present invention.
Figure 11 is authentification of message system of the present invention first kind of realization synoptic diagram.
Figure 12 is authentification of message system of the present invention second kind of realization synoptic diagram.
Figure 13 is the first method synoptic diagram that signs electronically.
Figure 14 is the second method synoptic diagram that signs electronically.
Figure 15 is the third method synoptic diagram that signs electronically.
Figure 16 is the 4th kind of method synoptic diagram that signs electronically.
Figure 17 is the first method synoptic diagram that carries out electronics endorsement signature.
Figure 18 is the second method synoptic diagram that carries out electronics endorsement signature.
Figure 19 is the first method synoptic diagram that carries out electronics reendorse signature.
Figure 20 is the second method synoptic diagram that carries out electronics reendorse signature.
Figure 21 is the first method synoptic diagram that carries out electron underwriting authentication.
Figure 22 is the second method synoptic diagram that carries out electron underwriting authentication.
Figure 23 is an electronic bill synoptic diagram of the present invention.
Embodiment:
Further describe specific embodiments of the present invention below in conjunction with accompanying drawing.
Fig. 1 is that Electronic Signature of the present invention is realized synoptic diagram for first kind.Electronic Signature 100 comprises information processing apparatus 101 and print module 102, and print module 102 is connected with described information processing apparatus 101, and print module 102 can print information on medium.Print module 102 has a printing surface of contact 110 to contact with medium or is close.Medium described herein refers generally to electronic bill, referring to Figure 23.Figure 23 is an electronic bill synoptic diagram of the present invention, sets a specific region 2302 at the information medium 2301 of electronic bill 2300 and is used for electronic signature.When signing electronically, the printing surface of contact 110 of print module 102 contacts with specific region 2302, and signing messages is printed on specific region 2302.Described information processing apparatus 101 comprises the rivest, shamir, adelman module and has stored the private key information of signing messages, signature owner; By described rivest, shamir, adelman module described signing messages, described private key information are carried out calculation process and obtain output information, described output information is converted to the signed data that described print module 102 prints by described information processing apparatus 101.The signed data of printing can be rendered as a string data usually and be convenient to the human eye perception.But the automatic identification of the inconvenient machine of a string data, therefore the signed data of printing preferably is in modes such as bar code or two-dimensional bar codes and can adopts now corresponding bar code scanner or two-dimensional bar code reader to carry out automatic reading easily, can realize the automatic identification of signing messages.In this scheme, the public key information of signer is a public information, and can decipher this information with the public key information of signer and obtain raw information.Therefore can differentiate the true and false of the signing messages that Electronic Signature signs automatically by machinery and equipment.
Fig. 2 is that Electronic Signature of the present invention is realized synoptic diagram for second kind.Implementation than Fig. 1, in the implementation of Fig. 2, Electronic Signature 200 has increased by first fixed support 202 and second fixed support 203, and the Electronic Signature main body that comprises information processing apparatus 101 and print module 102 can be slided on first fixed support 202 and second fixed support 203.When not only printing the Electronic Signature main body, described first fixed support 202 and second fixed support 203, but also be convenient to aiming at and the location of print module 102 and specific region 2302 as the supporting ﹠ stablizing effect.Such as, on electronic bill, set a position reference point, by determining the relative position of reference point and first fixed support 202 and/or second fixed support 203, signing messages can both be printed to specific region 2302 in the time of just can guaranteeing to sign at every turn.
With the multiple implementation of being combined with of signing messages and electronic bill, Fig. 3, Fig. 4, Fig. 5 have provided the principle of work of three kinds of implementations respectively.Fig. 3 is first kind of implementation principle of work of Electronic Signature of the present invention synoptic diagram.Electronic Signature comprises information processing apparatus 302 and print module 303, and print module 303 is connected with described information processing apparatus 302, and it is the module signal of the principle of work of Fig. 1.
Fig. 4 is second kind of implementation principle of work of Electronic Signature of the present invention synoptic diagram.Electronic Signature comprises information processing apparatus 402 and radio frequency module for reading and writing 403, and radio frequency module for reading and writing 403 and described information processing apparatus 402 are connected by radiofrequency signal.This scheme requires to embed radio electronic label in electronic bill, signing messages is encrypted the back write radio electronic label by radio frequency module for reading and writing 403.After adopting radio electronic label, though its information human eye is invisible, the characteristics of its contactless identification more help the use of Electronic Signature.If people wish to have the effect that seeing is believing simultaneously or carry out double authentication, the scheme of Fig. 3 and Fig. 4 can be carried out combination, referring to Fig. 5.
Fig. 5 is the third implementation principle of work synoptic diagram of Electronic Signature of the present invention.Electronic Signature comprises information processing apparatus 502, radio frequency module for reading and writing 503, MIM message input module 505 and print module 501.In order to comprise more information in the information that makes electronic signature, as information such as the date of signing, the bill term of validity, payer, beneficiary, increased MIM message input module 505 in this programme, these information can be input to information processing apparatus 502 by MIM message input module 505, as the part of signing messages.And will both write in the radio electronic label of electronic bill by radio frequency module for reading and writing 503 after the signing messages encryption, again signing messages is encrypted the back is printed on electronic bill by print module 501 specific region.
Fig. 6 is the third realization synoptic diagram of Electronic Signature of the present invention.Electronic Signature 600 comprise information processing apparatus 601, interface unit 603 and print module 602 and with external safety component (not drawing in the drawings), print module 602 is connected with described information processing apparatus 601, and print module 102 can print information on medium; Interface unit 603 is connected with described information processing apparatus 601, simultaneously interface unit 603 comprises connector and is connected with external safety component, to carry out encrypted secret key information and cryptographic algorithm focuses on external safety component, and can make the use of Electronic Signature more flexible.Print module 602 has a printing surface of contact 610 to contact with medium or is close.Compare with the realization of Fig. 1, the realization of Fig. 6 is that the security-related part of Electronic Signature is realized by external safety component.Described safety component comprises security information processing module, rivest, shamir, adelman module and has stored the private key information of signing messages, signature owner.
Fig. 7 is that Electronic Signature of the present invention is realized synoptic diagram for the 4th kind.This programme is at the situation that comprises Electronic Paper in the electronic bill.Realize because the information of Electronic Paper presents by Electronic Paper being carried out electronization, thus its realization and Fig. 1 some is different.Electronic Signature 700 comprises first electrode surface 710 and second electrode surface 703 of information processing apparatus 701 and Electronic Paper electronization module 702 and Electronic Paper electronization, Electronic Paper electronization module 702 is connected with described information processing apparatus 701, and Electronic Paper electronization module 702 can present information in the Electronic Paper on medium by first electrode surface 710 and second electrode surface 703.First electrode surface 710 and second electrode surface 703 by one slidably web member 705 be connected; Place electronic bill between first electrode surface 710 and second electrode surface 703, and the Electronic Paper part of electronic bill is just in time placed the surface of contact of first electrode surface 710 and second electrode surface 703.Described information processing apparatus 701 comprises the rivest, shamir, adelman module and has stored the private key information of signing messages, signature owner; By described rivest, shamir, adelman module described signing messages, described private key information are carried out calculation process and obtain output information, described output information is converted to the signed data that described Electronic Paper electronization module 702 is carried out electronization by described information processing apparatus 701.The signed data of electronization can be rendered as a string data usually and be convenient to the human eye perception.But the automatic identification of the inconvenient machine of a string data, therefore the signed data of printing preferably is in modes such as bar code or two-dimensional bar codes and can adopts now corresponding bar code scanner or two-dimensional bar code reader to carry out automatic reading easily, can realize the automatic identification of signing messages.In this scheme, the public key information of signer is a public information, and can decipher this information with the public key information of signer and obtain raw information.Therefore can differentiate the true and false of the signing messages that Electronic Signature signs automatically by machinery and equipment.
Fig. 8 is the 4th kind of implementation principle of work synoptic diagram of Electronic Signature of the present invention.The smart card 804 that Electronic Signature comprises information processing apparatus 802 and print module 803 and is connected by intelligent card interface 801, it is the module signal of the principle of work of Fig. 6.Described safety component adopts intelligent card interface 801 with smart card 804, interface unit.Because smart card is popularized very wide, easy to carry, wieldy characteristics now, therefore also adopt the mode of smart card in the preferred implementation of the present invention.
Fig. 9 is the 5th kind of implementation principle of work synoptic diagram of Electronic Signature of the present invention.The smart card 904 that Electronic Signature comprises information processing apparatus 902 and radio frequency module for reading and writing 903 and is connected by intelligent card interface 901.Described safety component adopts intelligent card interface 901 with smart card 904, interface unit.Because smart card is popularized very wide, easy to carry, wieldy characteristics now, therefore also adopt the mode of smart card in the preferred implementation of the present invention.Radio frequency module for reading and writing 903 and described information processing apparatus 902 are connected by radiofrequency signal.This scheme requires to embed radio electronic label in electronic bill, signing messages is encrypted the back write radio electronic label by radio frequency module for reading and writing 903.After adopting radio electronic label, though its information human eye is invisible, the characteristics of its contactless identification more help the use of Electronic Signature.If people wish to have the effect that seeing is believing simultaneously or carry out double authentication, the scheme of Fig. 8 and Fig. 9 can be carried out combination.
Figure 10 is the 6th kind of implementation principle of work synoptic diagram of Electronic Signature of the present invention.Than Fig. 9, this specific implementation has also increased MIM message input module 1005 except that the smart card 904 that comprises information processing apparatus 902 and radio frequency module for reading and writing 903 and be connected by intelligent card interface 901.These information can be input to information processing apparatus 902 by MIM message input module 1005, as the part of signing messages.
Figure 11 is authentification of message system of the present invention first kind of realization synoptic diagram.The authentification of message system comprises certificate server 1101, information medium 1103, and described certificate server comprises information acquisition parts 1102, enciphering and deciphering algorithm calculating unit, data back.Described information medium 1103 refers generally to electronic bill, also can be other media that need sign, and the surface comprises the cipher-text information of visible signing messages; Described enciphering and deciphering algorithm calculating unit comprises the computing module of enciphering and deciphering algorithm; Stored described information medium owner's approval signing messages in the described data back; Described information acquisition parts 1102 are gathered the cipher-text information on described information medium 1103 surfaces and described cipher-text information are converted to by the cipher-text information data of described certificate server 1101 processing; Described asymmetric enciphering and deciphering algorithm calculating unit is decrypted described cipher-text information data and obtains signing messages; Described certificate server 1101 is by the whether consistent authentication that realizes information medium of the approval signing messages of storage in advance in more described signing messages and the described data back.
Figure 12 is authentification of message system of the present invention second kind of realization synoptic diagram.The authentification of message system comprises certificate server 1201, information medium 1203, safety feature 1204.Described certificate server 1201 comprises information acquisition parts 1202, data back, safety feature interface unit; Described information medium surface comprises the cipher-text information of visible signing messages; Described safety feature 1204 comprise endorsement person PKI, realized module by endorsement person's private key and decipherment algorithm; Described certificate server 1201 is undertaken by described safety feature interface unit and described safety feature 1204 that wire signal is connected or wireless signal connects; Stored described information medium 1203 owners' approval signing messages in the described data back; Described information acquisition parts 1202 are gathered the cipher-text information on described information medium surface and described cipher-text information are converted to the cipher-text information data of being handled by described certificate server; Described certificate server 1201 is given described safety feature 1204 with the cipher-text information data transfer, is decrypted by 1204 pairs of described cipher-text information data of described safety feature to obtain signing messages and signing messages is passed to described certificate server 1201; Described certificate server 1201 is by the whether consistent authentication that realizes information medium of the approval signing messages of storage in advance in more described signing messages and the described data back.
Figure 13 is the first method synoptic diagram that signs electronically.In step 1301, be that password adopts the algoritic module of rivest, shamir, adelman to carry out calculation process to obtain encrypt data with the private key of signer at first with signing messages, in step 1302, described encrypt data is converted to printed signature information then, when step 1303, described printed signature information is printed on the information medium at last.The method of this electronic signature is that the implementation with Fig. 1 is the description that Electronic Signature carries out electric endorsement method.
Figure 14 is the second method synoptic diagram that signs electronically.For electronic signature and the electronic bill that has embedded radio electronic label are bound, can be when signing electronically with the identifying information of the information of radio electronic label such as electronic tag part as signing messages.Therefore the endorsement method step is as follows: at first in step 1400 from radio electronic label read data information, entering step 1401 is that password adopts the algoritic module of rivest, shamir, adelman to carry out calculation process to obtain encrypt data with described signing messages and described data message with the private key of signer, in step 1402, described encrypt data is converted to printed signature information then, when step 1403, described printed signature information is printed on the information medium at last.
Figure 15 is the third method synoptic diagram that signs electronically.Corresponding with the Electronic Signature implementation of Fig. 6, because Electronic Signature is divided into separable safety component and electronic signature body, therefore its electric endorsement method step is as follows: the information communication of at first safety component being carried out information connection and foundation and electronic signature body in step 1500 by the interface unit of electronic signature body, entering in the step 1301 signing messages is that password adopts the algoritic module of rivest, shamir, adelman to carry out calculation process to obtain encrypt data with the private key of signer, in step 1302, described encrypt data is converted to printed signature information then, when step 1303, described printed signature information is printed on the information medium at last.
Figure 16 is the 4th kind of method synoptic diagram that signs electronically.For electronic signature and the electronic bill that has embedded radio electronic label are bound, can be when signing electronically with the identifying information of the information of radio electronic label such as electronic tag part as signing messages.Therefore the endorsement method step is as follows: the information communication of at first safety component being carried out information connection and foundation and electronic signature body in step 1600 by the interface unit of electronic signature body, and in step 1400 from radio electronic label read data information, entering step 1401 is that password adopts the algoritic module of rivest, shamir, adelman to carry out calculation process to obtain encrypt data with described signing messages and described data message with the private key of signer, in step 1402, described encrypt data is converted to printed signature information then, when step 1403, described printed signature information is printed on the information medium at last.
Figure 17 is the first method synoptic diagram that carries out electronics endorsement signature.In step 1701, be that password adopts first computing module of rivest, shamir, adelman to carry out calculation process to obtain first operation result with endorsement person's private key at first with signing messages, in step 1702, be that password adopts second computing module of rivest, shamir, adelman to carry out calculation process to obtain encrypt data with quilt endorsement person's PKI then to described first operation result, enter step 1703 described encrypt data is converted to printed signature information, in step 1704, described printed signature information is printed on the information medium at last.The signing messages in when signature of generally endorsing comprises endorsement person's information, by endorsement person's information, disburser's information, the person's of honouring information, signature date, the term of validity etc., a plurality of endorsements signatures can be coupled together the continuity that forms the endorsement signature by signing messages.
Figure 18 is the second method synoptic diagram that carries out electronics endorsement signature.For electronic signature and the electronic bill that has embedded radio electronic label are bound, can be when signing electronically with the identifying information of the information of radio electronic label such as electronic tag part as signing messages.Therefore the endorsement method step of endorsing is as follows: at first in step 1800 from radio electronic label read data information, and in step 1801, be that password adopts first computing module of rivest, shamir, adelman to carry out calculation process to obtain first operation result with endorsement person's private key with described signing messages and described data message; In step 1802, be that password adopts second computing module of rivest, shamir, adelman to carry out calculation process to obtain encrypt data with quilt endorsement person's PKI then to described first operation result, enter step 1803 described encrypt data is converted to printed signature information, in step 1804, described printed signature information is printed on the information medium at last.The signing messages in when signature of generally endorsing comprises endorsement person's information, by endorsement person's information, disburser's information, the person's of honouring information, signature date, the term of validity etc., a plurality of endorsements signatures can be coupled together the continuity that forms the endorsement signature by signing messages.
Figure 19 is the first method synoptic diagram that carries out electronics reendorse signature.Carrying out reendorse when signature, needing to obtain the information of remote holder signature, with the consistance that guarantees signing messages and prevent that the unauthorized person from carrying out the interests loss of the electronic bill that reendorse causes.Concrete grammar is described below: at first in step 1901 described remote holder signed data being decrypted and obtaining the remote holder signing messages, is that password adopts first computing module of rivest, shamir, adelman to carry out calculation process to obtain first operation result with described remote holder signing messages, reendorse signing messages with quilt endorsement person's PKI in step 1902; In step 1903, be that password adopts second computing module of rivest, shamir, adelman to carry out calculation process to obtain encrypt data with the private key of signer then to described first operation result; Enter step 1904 described encrypt data is converted to printed signature information, in step 1905, described printed signature information is printed on the information medium at last.
Figure 20 is the second method synoptic diagram that carries out electronics reendorse signature.When being divided into safety component and electronic signature body in the realization of Electronic Signature, when it carries out the reendorse signature, need earlier safety component and electronic body to be set up being connected of information.Concrete grammar is described below: the information communication of at first safety component being carried out information connection and foundation and electronic signature body in step 2000 by the interface unit of electronic signature body, and in step 1901, described remote holder signed data is decrypted and obtains the remote holder signing messages, in step 1902, be that password adopts first computing module of rivest, shamir, adelman to carry out calculation process to obtain first operation result with quilt endorsement person's PKI with described remote holder signing messages, reendorse signing messages; In step 1903, be that password adopts second computing module of rivest, shamir, adelman to carry out calculation process to obtain encrypt data with the private key of signer then to described first operation result; Enter step 1904 described encrypt data is converted to printed signature information, in step 1905, described printed signature information is printed on the information medium at last.
Figure 21 is the first method synoptic diagram that carries out electron underwriting authentication.Electronic Signature of the present invention is after signing on the electronic bill, when the authentification of message system among employing the present invention authenticates signing messages, its implementation is as follows: at first gather the cipher-text information of the conduct signature that is printed on the electronic bill in step 2101, in step 2102 described cipher-text information deciphering is obtained signing messages then; Then judge in step 2103 whether the approval signing messages that described signing messages and described authentification of message system store mates; If coupling enters step 2104 and shows authentication success; Enter step 2105 if do not match and show authentification failure.
Figure 22 is the second method synoptic diagram that carries out electron underwriting authentication.The public key information that the invention allows for employing signer when signing messages is carried out asymmetric encryption need use by endorsement person's private key information when therefore deciphering, and private key information belongs to endorsement person's security information as key.Proposed in the present invention and will have been made independently safety feature by endorsement person's private key information and decipherment algorithm, when carrying out authentification of message, safety feature is connected with the authentification of message system, and the deciphering of information is finished by safety feature, can guarantee can not leaked by endorsement person's security information.Concrete authentication method is: the cipher-text information of at first gathering the conduct signature that is printed on the electronic bill in step 2201, in the system of authentification of message described in the step 2202 cipher-text information is passed to safety feature by wire communication mode and/or wireless communication mode then, by described safety feature described cipher-text information data are decrypted and obtain signing messages and signing messages is passed to described authentification of message system; Then judge in step 2203 whether the approval signing messages that described signing messages and described authentification of message system store mates; If coupling enters step 2204 and shows authentication success; Enter step 2205 if do not match and show authentification failure.

Claims (10)

1. system that endorsement signature on the information medium is authenticated is characterized in that comprising:
Certificate server, described certificate server comprise information acquisition parts, data back, safety feature interface unit;
Information medium, described information medium surface has pair signing messages to encrypt the cipher-text information that obtains;
Safety feature, described safety feature comprise by endorsement person's key and decipherment algorithm realizes module;
Described certificate server is undertaken by described safety feature interface unit and described safety feature that wire signal is connected or wireless signal connects;
Stored described information medium owner's approval signing messages in the described data back;
Described information acquisition parts are gathered described cipher-text information and described cipher-text information are converted to the cipher-text information data of being handled by described certificate server;
Described certificate server is given described safety feature with the cipher-text information data transfer, by described safety feature described cipher-text information data is decrypted the plaintext that obtains signing messages and the plaintext of signing messages is passed to described certificate server;
The whether consistent authentication that realizes information medium of the approval signing messages of storage in advance in the plaintext of described certificate server by more described signing messages and the described data back.
2. system that endorsement signature on the information medium is authenticated is characterized in that comprising:
Certificate server, described certificate server comprise information acquisition parts, data back, safety feature interface unit;
Information medium has embedded electronic unit in the described information medium, has write in described electronic unit signing messages is encrypted the cipher-text information that obtains;
Safety feature, described safety feature comprise by endorsement person's key and decipherment algorithm realizes module;
Described certificate server is undertaken by described safety feature interface unit and described safety feature that wire signal is connected or wireless signal connects;
Stored described information medium owner's approval signing messages in the described data back;
Described information acquisition parts are gathered described cipher-text information and described cipher-text information are converted to the cipher-text information data of being handled by described certificate server;
Described certificate server is given described safety feature with the cipher-text information data transfer, by described safety feature described cipher-text information data is decrypted the plaintext that obtains signing messages and the plaintext of signing messages is passed to described certificate server;
The whether consistent authentication that realizes information medium of the approval signing messages of storage in advance in the plaintext of described certificate server by more described signing messages and the described data back.
3. system that endorsement signature on the information medium is authenticated is characterized in that comprising:
Certificate server, described certificate server comprise information acquisition parts, data back, safety feature interface unit;
Information medium, described information medium comprises Electronic Paper, has in the described Electronic Paper signing messages is encrypted the cipher-text information that obtains;
Safety feature, described safety feature comprise by endorsement person's key and decipherment algorithm realizes module;
Described certificate server is undertaken by described safety feature interface unit and described safety feature that wire signal is connected or wireless signal connects;
Stored described information medium owner's approval signing messages in the described data back;
Described information acquisition parts are gathered described cipher-text information and described cipher-text information are converted to the cipher-text information data of being handled by described certificate server;
Described certificate server is given described safety feature with the cipher-text information data transfer, by described safety feature described cipher-text information data is decrypted the plaintext that obtains signing messages and the plaintext of signing messages is passed to described certificate server;
The whether consistent authentication that realizes information medium of the approval signing messages of storage in advance in the plaintext of described certificate server by more described signing messages and the described data back.
4. system that endorsement signature on the information medium is authenticated is characterized in that comprising:
Certificate server, described certificate server comprise information acquisition parts, data back, safety feature interface unit;
Information medium, embedded electronic unit in the described information medium, write the first of signing messages being encrypted the cipher-text information that obtains in described electronic unit, described information medium surface has pair signing messages to encrypt the second portion of the cipher-text information that obtains;
Safety feature, described safety feature comprise by endorsement person's key and decipherment algorithm realizes module;
Described certificate server is undertaken by described safety feature interface unit and described safety feature that wire signal is connected or wireless signal connects;
Stored described information medium owner's approval signing messages in the described data back;
Described information acquisition parts are gathered the second portion of the first of described cipher-text information and cipher-text information and the first of described cipher-text information and the second portion of cipher-text information are converted to the cipher-text information data of being handled by described certificate server;
Described certificate server is given described safety feature with the cipher-text information data transfer, by described safety feature described cipher-text information data is decrypted the plaintext that obtains signing messages and the plaintext of signing messages is passed to described certificate server;
The whether consistent authentication that realizes information medium of the approval signing messages of storage in advance in the plaintext of described certificate server by more described signing messages and the described data back.
5. system that endorsement signature on the information medium is authenticated is characterized in that comprising:
Certificate server, described certificate server comprise information acquisition parts, data back, safety feature interface unit;
Information medium, embedded electronic unit in the described information medium, in described electronic unit, write the first of signing messages being encrypted the cipher-text information that obtains, described information medium comprises Electronic Paper, has the second portion of signing messages being encrypted the cipher-text information that obtains in the described Electronic Paper;
Safety feature, described safety feature comprise by endorsement person's key and decipherment algorithm realizes module;
Described certificate server is undertaken by described safety feature interface unit and described safety feature that wire signal is connected or wireless signal connects;
Stored described information medium owner's approval signing messages in the described data back;
Described information acquisition parts are gathered the second portion of the first of described cipher-text information and cipher-text information and the first of described cipher-text information and the second portion of cipher-text information are converted to the cipher-text information data of being handled by described certificate server;
Described certificate server is given described safety feature with the cipher-text information data transfer, by described safety feature described cipher-text information data is decrypted the plaintext that obtains signing messages and the plaintext of signing messages is passed to described certificate server;
The whether consistent authentication that realizes information medium of the approval signing messages of storage in advance in the plaintext of described certificate server by more described signing messages and the described data back.
6. system that endorsement signature on the information medium is authenticated is characterized in that comprising:
Certificate server, described certificate server comprise information acquisition parts, data back, safety feature interface unit;
Information medium, embedded electronic unit in the described information medium, in described electronic unit, write the first of signing messages being encrypted the cipher-text information that obtains, described information medium comprises Electronic Paper, have the second portion of signing messages being encrypted the cipher-text information that obtains in the described Electronic Paper, described information medium surface has pair signing messages to encrypt the third part of the cipher-text information that obtains;
Safety feature, described safety feature comprise by endorsement person's key and decipherment algorithm realizes module;
Described certificate server is undertaken by described safety feature interface unit and described safety feature that wire signal is connected or wireless signal connects;
Stored described information medium owner's approval signing messages in the described data back;
Described information acquisition parts are gathered the third part of the second portion of first, cipher-text information of described cipher-text information and cipher-text information and the first of described cipher-text information, the second portion of cipher-text information and the third part of cipher-text information are converted to the cipher-text information data of being handled by described certificate server;
Described certificate server is given described safety feature with the cipher-text information data transfer, by described safety feature described cipher-text information data is decrypted the plaintext that obtains signing messages and the plaintext of signing messages is passed to described certificate server;
The whether consistent authentication that realizes information medium of the approval signing messages of storage in advance in the plaintext of described certificate server by more described signing messages and the described data back.
7. according to each described system in the claim 1 to 6, it is characterized in that described data back stores endorsement person's public key information or the public key information that described secure device stores has endorsement person.
8. according to each described system in the claim 1 to 6, it is characterized in that described secure device stores has endorsement person's public key information and by endorsement person's private key information.
9. according to each described system in the claim 1 to 6, it is characterized in that:
Described safety feature is a contact intelligent card, and described safety feature interface unit is supported intelligent card interface; Or
Described safety feature is the usb key card, and described safety feature interface unit is supported USB (universal serial bus); Or
Described safety feature is the Wireless USB key card, and described safety feature interface unit is supported the radio universal serial line interface; Or
Described safety feature is a contact type intelligent card, and described safety feature interface unit is supported wireless radio interface; Or
Described safety feature is the contact safe memory card, and described safety feature interface unit is supported pcmcia interface or Micro SD interface or SF interface or memory stick (Memory Stick) interface.
10. system according to claim 8 is characterized in that:
Described safety feature is a contact intelligent card, and described safety feature interface unit is supported intelligent card interface; Or
Described safety feature is the usb key card, and described safety feature interface unit is supported USB (universal serial bus); Or
Described safety feature is the Wireless USB key card, and described safety feature interface unit is supported the radio universal serial line interface; Or
Described safety feature is a contact type intelligent card, and described safety feature interface unit is supported wireless radio interface; Or
Described safety feature is the contact safe memory card, and described safety feature interface unit is supported pcmcia interface or Micro SD interface or SF interface or memory stick (Memory Stick) interface.
CN2009102358250A 2009-10-23 2009-10-23 System for authenticating endorsement signature on information medium Expired - Fee Related CN101763677B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN2009102358250A CN101763677B (en) 2009-10-23 2009-10-23 System for authenticating endorsement signature on information medium

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN2009102358250A CN101763677B (en) 2009-10-23 2009-10-23 System for authenticating endorsement signature on information medium

Publications (2)

Publication Number Publication Date
CN101763677A true CN101763677A (en) 2010-06-30
CN101763677B CN101763677B (en) 2012-03-07

Family

ID=42494827

Family Applications (1)

Application Number Title Priority Date Filing Date
CN2009102358250A Expired - Fee Related CN101763677B (en) 2009-10-23 2009-10-23 System for authenticating endorsement signature on information medium

Country Status (1)

Country Link
CN (1) CN101763677B (en)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN111488570A (en) * 2020-04-14 2020-08-04 威盛电子股份有限公司 Authentication method and authentication system

Family Cites Families (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1350258A (en) * 2001-12-03 2002-05-22 上海电子商务安全证书管理中心有限公司 Electronic signature verifying method and device
DE10217632A1 (en) * 2002-04-19 2003-11-06 Giesecke & Devrient Gmbh The security document
CN1790390A (en) * 2005-12-28 2006-06-21 胡祥义 Safety electronic passport system
CN100586065C (en) * 2006-04-24 2010-01-27 北京易恒信认证科技有限公司 CPK credibility authorization system
CN1873703A (en) * 2006-05-29 2006-12-06 吴建明 New method for drawing a bill for cheque
CN101051907B (en) * 2007-05-14 2012-08-22 北京握奇数据系统有限公司 Safety certifying method and its system for facing signature data

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN111488570A (en) * 2020-04-14 2020-08-04 威盛电子股份有限公司 Authentication method and authentication system
CN111488570B (en) * 2020-04-14 2023-10-31 威盛电子股份有限公司 Authentication method and authentication system

Also Published As

Publication number Publication date
CN101763677B (en) 2012-03-07

Similar Documents

Publication Publication Date Title
CN101763676B (en) Method for authenticating endorsement signature on information medium
CN101763677B (en) System for authenticating endorsement signature on information medium
CN101763678B (en) System for authenticating signature on information medium
CN101699472B (en) Electronic signature supporting continuous endorsement
CN101699468B (en) Electronic signature for continuously endorsing electronic paper through support of external security part
CN101758694B (en) Electronic bill containing electronic part
CN101697190A (en) Electronic signature for signing on electronic paper
CN201946057U (en) Equipment for authenticating signature on information medium
CN201616129U (en) Equipment for authenticating endorsement signature on information medium
CN101763679B (en) Method for authenticating signature on information medium
CN101697207B (en) Multifunctional electronic signature supporting continuous endorsement of external safety component
CN101697203B (en) Electronic signature supporting continuous endorsement of external safety component
CN101763615B (en) Method for endorsing electronic paper
CN101763614B (en) Method for endorsing and signing on mixed electronic bill
CN101699471B (en) Electronic signature supporting endorsement
CN201522708U (en) Signature device for signing information medium endorsement containing electronic component
CN201583979U (en) Multifunctional signature device of external safety component supporting continuous endorsing and signing
CN201583962U (en) Signature device of external safety component supporting continuous endorsing and signing on electronic paper
CN201604388U (en) Financial instrument including electronic paper
CN101699466B (en) Electronic signature for endorsing electronic paper through external security part
CN201583973U (en) Signature device of external safety component supporting continuous endorsing and signing
CN201592575U (en) Financial bill
CN101699464B (en) Electronic signature supporting continuous endorsement on media including electronic components
CN201594269U (en) Signature device for signing electronic paper
CN101758693A (en) Mixed electronic bill

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C14 Grant of patent or utility model
GR01 Patent grant
CF01 Termination of patent right due to non-payment of annual fee

Granted publication date: 20120307

Termination date: 20141023

EXPY Termination of patent right or utility model