TWI831523B - Operation method of digital file verification system - Google Patents

Operation method of digital file verification system Download PDF

Info

Publication number
TWI831523B
TWI831523B TW111148321A TW111148321A TWI831523B TW I831523 B TWI831523 B TW I831523B TW 111148321 A TW111148321 A TW 111148321A TW 111148321 A TW111148321 A TW 111148321A TW I831523 B TWI831523 B TW I831523B
Authority
TW
Taiwan
Prior art keywords
signature
user
issuing unit
digital
digital signature
Prior art date
Application number
TW111148321A
Other languages
Chinese (zh)
Other versions
TW202427989A (en
Inventor
張傳旺
許楹怡
黃譯興
Original Assignee
國立勤益科技大學
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 國立勤益科技大學 filed Critical 國立勤益科技大學
Priority to TW111148321A priority Critical patent/TWI831523B/en
Application granted granted Critical
Publication of TWI831523B publication Critical patent/TWI831523B/en
Publication of TW202427989A publication Critical patent/TW202427989A/en

Links

Landscapes

  • Editing Of Facsimile Originals (AREA)

Abstract

An operation method of a digital file verification system is disclosed. The operation method comprises the steps of performing a download request step, performing a signature request step, performing a signature embedding step, and performing a post-signature calculation step. The present invention saves the files digitally, and combines the digital signature and watermark technology to propose a simple, safe and reliable verification system. It not only allows the digital file to be legal and non-modifiable, to ensure the integrity and anti-counterfeiting of digital files, no longer worry about the loss or damage of files in transit, but also to avoid tampering or damage during network transmission. In this way, the security that the file will not be tampered is achieved.

Description

電子文件驗證系統之運作方法 How the electronic document verification system operates

本發明是有關於一種文件運作方法,特別是有關於一種基於數位簽章技術的電子文件浮水印驗證系統之運作方法。 The present invention relates to a document operation method, and in particular to an operation method of an electronic document watermark verification system based on digital signature technology.

當今文件的保存大多仍仰賴紙本實體為主,但隨著經年累月的累積,文件的數量日益龐大。紙本文件的保存不僅佔用實體建築空間,更要擔心文件是否會因為儲存環境的安全因素而受到水災、火災或蟲蝕腐鏽等文件損毀的問題,因此在保存文件上就要付出相當高的維護成本。 Today, most documents still rely on physical paper for preservation, but as time passes, the number of documents becomes increasingly larger. The preservation of paper documents not only takes up physical building space, but also worries about whether the documents will be damaged by floods, fires, insect corrosion, corrosion, etc. due to the safety of the storage environment. Therefore, a considerable amount of money must be paid to preserve documents. Maintenance costs.

現在全球受武漢肺炎(COVID-19)疫情嚴峻的影響,人員的移動受到嚴格的限制。然而,許多重要文件的申請都需要驗證其申請人的身分,倘若申請人不在國內則需要回國跑申請流程,這一來一往中將會耗費相當大的時間與成本。 Nowadays, the world is severely affected by the Wuhan pneumonia (COVID-19) epidemic, and the movement of people is subject to strict restrictions. However, applications for many important documents require verification of the identity of the applicant. If the applicant is not in the country, he or she needs to return to the country to run the application process, which will consume considerable time and cost.

雖然台灣推動自然人憑證(citizen digital certificate)已經很長一段時間了,但是要擁有並使用自然人憑證功能時必須先花費時間與金錢進行註冊與申請的動作,且申請完成後還必須搭配晶片讀卡機的操作與使用。由於多數 民眾對於線上進行身分認證仍存在許多不確定的因素與疑慮因此仍有眾多民眾還是會選擇臨櫃辦理業務。 Although Taiwan has been promoting citizen digital certificates for a long time, in order to own and use the natural person certificate function, you must first spend time and money to register and apply, and after the application is completed, you must also use a chip card reader. operation and use. due to majority People still have many uncertain factors and doubts about identity authentication online, so many people still choose to handle business at the counter.

此外,在疫情影響之下,政府大力宣導要民眾減少外出,避免人員流動造成疫情擴散,甚至縮短公部門的上班時間或暫停臨櫃作業等,間接導致民眾無法申辦相關文件或辦理業務,造成許多不便及業務延宕的情形。 In addition, under the influence of the epidemic, the government has vigorously advocated for people to reduce going out to avoid the spread of the epidemic caused by the movement of people. It has even shortened the working hours of public departments or suspended counter operations, etc., which has indirectly caused people to be unable to apply for relevant documents or handle business, resulting in Many inconveniences and business delays.

有鑑於此,本發明將文件以數位化的方式保存,並結合數位簽章(digital signature)與浮水印(watermark)的技術,提出了一套簡易、安全、可靠的驗證系統。不僅讓數位文件擁有合法性與其不可竄改性,以確保數位文件的完整性並且防偽確實,不用再擔心文件在運送途中遺失或是損壞,也避免在網路傳輸的過程中遭竄改或損毀,達到本發明強調的安全且不會被竄改的特性與其方便的效果。 In view of this, the present invention saves files in a digital manner and combines digital signature and watermark technologies to propose a simple, safe and reliable verification system. It not only makes digital files legal and non-tamperable, but also ensures the integrity of digital files and ensures anti-counterfeiting. You no longer have to worry about files being lost or damaged during transportation, and it also avoids being tampered with or damaged during network transmission. This achieves The present invention emphasizes the characteristics of safety and inability to be tampered with and its convenient effect.

為達前述目的,本發明提出一種電子文件驗證系統之運作方法,包含下列步驟:進行一下載請求步驟,其係由一使用者針對對應於該使用者之一數位資料提出一下載請求;進行一簽章請求步驟,其係由該使用者所屬之一發證單位(Si)依據該下載請求將具有該數位資料之一電子檔案、該發證單位之一代理碼(Sac)及該使用者之一帳號(UIDi)傳輸至一公證中心(CA);進行一簽章嵌入步驟,其係由該公證中心將對應於該使用者之該帳號之一金鑰(Pn)作為一簽章,藉以使得具有該數位資料之該電子檔案,成為具有該簽章及該數位資料之一數位簽章文件,且使用一隱寫式浮水印技術將該簽章之內容嵌入至該數位簽章文件中,再將該數位簽章文件回傳給該發證單位;以及進行一簽章後運算步驟, 其係由該發證單位依據該數位簽章文件中之該數位資料進行一雜湊函數運算而產生一雜湊(hash)值,且將該雜湊值儲存於一資料庫中,再將該數位簽章文件發送給該使用者,藉以使得該使用者獲得具有該簽章及該數位資料之該數位簽章文件且使得該發證單位之該資料庫儲存有該雜湊值。 In order to achieve the aforementioned objectives, the present invention proposes an operating method of an electronic document verification system, which includes the following steps: performing a download request step, in which a user submits a download request for digital data corresponding to the user; performing a download request step; In the signature request step, the issuing unit (Si) to which the user belongs will transfer an electronic file with the digital data, the agency code (Sac) of the issuing unit and the user's personal information based on the download request. An account (UIDi) is transmitted to a notary center (CA); a signature embedding step is performed, in which the notary center uses the key (Pn) corresponding to the account of the user as a signature, thereby making The electronic file with the digital data becomes a digital signature document with the signature and the digital data, and a steganographic watermark technology is used to embed the content of the signature into the digital signature document, and then Send the digital signature document back to the issuing unit; and perform a post-signing operation step, The issuing unit performs a hash function operation on the digital data in the digital signature document to generate a hash value, stores the hash value in a database, and then adds the digital signature to the hash value. The file is sent to the user, thereby enabling the user to obtain the digital signature document with the signature and the digital data and causing the database of the issuing unit to store the hash value.

其中,在進行該下載請求步驟之前,更包含進行一系統設定與使用者註冊階段流程,其包含下列步驟:該發證單位提出一設定請求;該公證中心接收並依據該設定請求配發該代理碼給該發證單位;該使用者輸入該帳號與一密碼以提出一註冊請求;以及該發證單位依據該註冊請求,將該代理碼與對應於該使用者之該帳號發送至該公證中心,使得該公證中心依據該代理碼與該帳號產生對應於該代理碼及該帳號之該金鑰,並通知該發證單位與該使用者該註冊請求已成功。 Among them, before performing the download request step, a system setting and user registration phase process is further included, which includes the following steps: the certification unit submits a setting request; the notary center receives and allocates the agent according to the setting request code to the issuing unit; the user inputs the account number and a password to submit a registration request; and the issuing unit sends the agent code and the account number corresponding to the user to the notary center based on the registration request , causing the notary center to generate the key corresponding to the agent code and the account based on the agent code and the account, and notify the issuing unit and the user that the registration request has been successful.

其中,在進行該下載請求步驟之前,更包含由該公證中心配發該代理碼給該發證單位以及依據該代理碼與該帳號產生對應於該代理碼及該帳號之該金鑰。 Before performing the download request step, the notary center allocates the proxy code to the issuing unit and generates the key corresponding to the proxy code and the account based on the proxy code and the account.

其中,該數位資料為成績單、畢業證書或在職證明。 Among them, the digital data is transcripts, graduation certificates or employment certificates.

其中,該使用者為一學生,該發證單位為一學校單位。 Among them, the user is a student, and the issuing unit is a school unit.

其中,該使用者為一求職者,該發證單位為一公司單位。 Among them, the user is a job seeker, and the certification unit is a company unit.

承上所述,本發明之電子文件驗證系統之運作方法,主要是在數位簽章的基礎下,將數位簽章的內容擷取出來,將此內容以浮水印的形式鑲嵌在電子文件之中,如此不僅可以確保浮水印彼此不相同,同時也有數位簽章不可竄改之特性,更是用另一形式作數位簽章的雙重認證,在作驗證時有更高的安全性。 Based on the above, the operation method of the electronic document verification system of the present invention is mainly to extract the content of the digital signature based on the digital signature, and embed the content in the electronic document in the form of a watermark. , this not only ensures that the watermarks are different from each other, but also ensures that the digital signature cannot be tampered with. It also uses another form of two-factor authentication for the digital signature, providing higher security during verification.

茲為使鈞審對本發明的技術特徵及所能達到的技術功效有更進一步的瞭解與認識,謹佐以較佳的實施例及配合詳細的說明如後。 In order to enable Jun Shen to have a further understanding of the technical features and technical effects of the present invention, preferred embodiments and accompanying detailed descriptions are provided below.

S10、S20、S30:步驟 S10, S20, S30: steps

S110、S120、S130、S140:步驟 S110, S120, S130, S140: steps

S210、S220、S230、S240:步驟 S210, S220, S230, S240: steps

S310、S320、S330、S340:步驟 S310, S320, S330, S340: steps

CA:公證中心 CA: Notary Center

Si:發證單位 Si: Issuing unit

Ui:使用者 Ui:User

Pi:公鑰 Pi: public key

Pri:私鑰 Pri:private key

UIDi:帳號 UIDi:Account

Sac:代理碼 Sac:Agent code

PWi:密碼 PWi:Password

SDi:數位簽章文件 SDi: digital signature document

Di:數位資料 Di: digital data

H(SDi):雜湊值 H(SDi): Hash value

圖1為本發明之電子文件驗證系統之運作流程示意圖。 Figure 1 is a schematic diagram of the operation flow of the electronic document verification system of the present invention.

圖2為本發明之系統設定與使用者註冊階段流程之示意圖。 Figure 2 is a schematic diagram of the system setting and user registration phase process of the present invention.

圖3為本發明之使用者欲產生數位簽章文件流程之示意圖。 FIG. 3 is a schematic diagram of the process of a user intending to generate a digital signature document according to the present invention.

圖4為本發明之數位簽章文件完整性驗證流程之示意圖。 Figure 4 is a schematic diagram of the digital signature file integrity verification process of the present invention.

圖5為本發明之系統設定與使用者註冊階段流程之方塊示意圖。 Figure 5 is a block diagram of the system setting and user registration phase process of the present invention.

圖6為本發明之使用者欲產生數位簽章文件流程之方塊示意圖。 FIG. 6 is a block diagram illustrating the process of a user intending to generate a digital signature document according to the present invention.

圖7為本發明之數位簽章文件完整性驗證流程之方塊示意圖。 Figure 7 is a block diagram of the digital signature file integrity verification process of the present invention.

圖8為本發明之數位簽章文件完整性驗證流程之一種結果圖。 Figure 8 is a result diagram of the digital signature file integrity verification process of the present invention.

圖9為本發明之數位簽章文件完整性驗證流程之另一種結果圖。 Figure 9 is another result diagram of the digital signature file integrity verification process of the present invention.

為利瞭解本創作之技術特徵、內容與優點及其所能達成之功效,茲將本創作配合圖式,並以實施例之表達形式詳細說明如下,而其中所使用之圖式,其主旨僅為示意及輔助說明書之用,未必為本創作實施後之真實比例與精準配置,故不應就所附之圖式的比例與配置關係解讀、侷限本創作於實際實施上的權利範圍。此外,為使便於理解,下述實施例中的相同元件係以相同的符號標示來說明。 In order to facilitate understanding of the technical features, content and advantages of this invention and the effects it can achieve, this invention is described in detail below with diagrams and in the form of expressions of embodiments. The purpose of the diagrams used is only They are for illustration and auxiliary instructions, and may not represent the true proportions and precise configurations of the creation after its implementation. Therefore, the proportions and configurations of the attached drawings should not be interpreted to limit the scope of rights in the actual implementation of this creation. In addition, to facilitate understanding, the same elements in the following embodiments are labeled with the same symbols for explanation.

另外,在全篇說明書與申請專利範圍所使用的用詞,除有特別註明外,通常具有每個用詞使用在此領域中、在此揭露的內容中與特殊內容中的平常意義。某些用以描述本創作的用詞將於下或在此說明書的別處討論,以提供本領域技術人員在有關本創作的描述上額外的引導。 In addition, unless otherwise noted, the terms used throughout the specification and patent application generally have the ordinary meanings of each term used in the field, the content disclosed herein, and the specific content. Certain terms used to describe the invention are discussed below or elsewhere in this specification to provide those skilled in the art with additional guidance in describing the invention.

關於本文中如使用“第一”、“第二”、“第三”等,並非特別指稱次序或順位的意思,亦非用以限定本創作,其僅僅是為了區別以相同技術用語描述的組件或操作而已。 The use of "first", "second", "third", etc. in this article does not specifically refer to the order or sequence, nor is it used to limit the present invention. It is only used to distinguish components described by the same technical terms. Or just an operation.

其次,在本文中如使用用詞“包含”、“包括”、“具有”、“含有”等,其均為開放性的用語,即意指包含但不限於。 Secondly, if the words "include", "includes", "have", "contains", etc. are used in this article, they are all open terms, which means including but not limited to.

本發明之電子文件驗證系統係一種基於數位簽章技術的電子文件浮水印驗證系統,其運作主要包含三大流程,包含系統設定與使用者註冊階段流程(S10);使用者欲產生數位簽章文件的流程(S20);以及數位簽章文件完整性驗證流程(S30)。本發明係以使用者為學生申請成績單,發證單位為學生所屬之學校單位,查詢者為任何單位例如求職公司或另間學校單位作為示範,用以表示文件運作原理與結果,並驗證其安全性與可靠性。然而,本發明不侷限於上述舉例,本發明亦可適用於各種需要驗證文件真偽之狀況,舉例而言,使用者可為任何人士,例如求職者,而發證單位可例如為此求職者之原公司單位,而查詢者則為任何單位,例如為該求職者所欲求職之求職公司等。 The electronic document verification system of the present invention is an electronic document watermark verification system based on digital signature technology. Its operation mainly includes three major processes, including system setting and user registration stage process (S10); the user wants to generate a digital signature The file process (S20); and the digital signature file integrity verification process (S30). This invention uses the user as a student to apply for a transcript, the issuing unit as the school unit to which the student belongs, and the queryer as any unit such as a job search company or another school unit as a demonstration to show the operating principles and results of the file, and to verify it. Safety and reliability. However, the present invention is not limited to the above examples. The present invention can also be applied to various situations where the authenticity of documents needs to be verified. For example, the user can be any person, such as a job seeker, and the issuing unit can be, for example, a job seeker. The original company unit, and the queryer is any unit, such as the job search company where the job seeker wants to apply for a job, etc.

就系統設定與使用者註冊階段流程(S10)而言,如圖2所示,其係由發證單位(Si)提出設定請求以及由使用者(Ui)提出註冊請求,再由公證中心(Certificate Authority,CA)產生代理碼(Sac)及金鑰(Pn)[例如,一組非對稱式公(Pi)私(Pri)鑰]給使用者(Ui),其中上述之i僅代表第幾個或某一個的意思。 As far as the system setting and user registration stage process (S10) is concerned, as shown in Figure 2, the setting request is made by the certification unit (Si) and the registration request is made by the user (Ui), and then the notary center (Certificate) Authority, CA) generates a proxy code (Sac) and a key (Pn) [for example, a set of asymmetric public (Pi) private (Pri) keys] to the user (Ui), where the above i only represents the number of or a certain meaning.

如圖1、圖2及圖5所示,此系統設定與使用者註冊階段流程(S10)之詳細步驟如下:如步驟S110,由發證單位(Si)提出設定請求至公證中心(CA);如步驟S120,公證中心(CA)接收並依據上述之設定請求配發代理碼(Sac,School agent code)給發證單位(Si);如步驟S130,使用者(Ui)輸入帳號(UIDi)與密碼(PWi)以提出註冊請求;如步驟S140,待此使用者(Ui)註冊成功後,發證單位(Si)依據此註冊請求將發證單位(Si)之代理碼(Sac)與此使用者之帳號(UIDi)發送至公證中心(CA),使得公證中心(CA)依據代理碼(Sac)與帳號(UIDi)產生對應於代理碼(Sac)及該帳號(UIDi)之金鑰(Pn)(例如,一組非對稱式公(Pi)私(Pri)鑰),並通知發證單位(Si)與使用者(Ui)上述之註冊請求已成功。其中,圖5所示之虛線上半部為公證中心(CA)與發證單位(Si)的系統設定部分,虛線下半部為使用者(Ui)向發證單位(Si)註冊一個帳號(UIDi),註冊完畢後,發證單位(Si)將使用者相關資訊發送至公證中心(CA),並且產生一對公私鑰給使用者(Ui)使用。 As shown in Figure 1, Figure 2 and Figure 5, the detailed steps of this system setting and user registration stage process (S10) are as follows: In step S110, the issuing unit (Si) submits a setting request to the notary center (CA); In step S120, the notary center (CA) receives and allocates an agent code (Sac, School agent code) to the issuing unit (Si) based on the above setting request; in step S130, the user (Ui) enters the account number (UIDi) and password (PWi) to make a registration request; in step S140, after the user (Ui) is successfully registered, the issuing unit (Si) uses the agent code (Sac) of the issuing unit (Si) based on this registration request. The account number (UIDi) of the user is sent to the notary center (CA), so that the notary center (CA) generates a key (Pn) corresponding to the agent code (Sac) and the account number (UIDi) based on the agent code (Sac) and the account number (UIDi). ) (for example, a set of asymmetric public (Pi) private (Pri) keys), and notify the issuing unit (Si) and the user (Ui) that the above-mentioned registration request has been successful. Among them, the upper half of the dotted line shown in Figure 5 is the system setting part of the notary center (CA) and the issuing unit (Si), and the lower half of the dotted line is the user (Ui) registering an account with the issuing unit (Si) ( UIDi), after the registration is completed, the issuing unit (Si) sends the user-related information to the notary center (CA), and generates a pair of public and private keys for the user (Ui) to use.

就使用者,例如學生,欲產生數位簽章文件的流程(S20)而言,如圖1、圖3及圖6所示,使用者(Ui)係先登入發證單位(Si)之事務系統,例如學校單位之校務系統,並且找到此使用者(Ui)的原始數位資料,例如學生之成績單,接著將此成績單送給公證中心(CA)做處理,公證中心(CA)將原始成績加入簽章,並擷取簽章內容以浮水印形式嵌入至成績單發送給發證單位(Si)後,發證單位(Si)將有簽章的成績單作雜湊函數運算並存在資料庫中,然後再將此數位簽章文件交給使用者(Ui)。 As for the process (S20) of a user, such as a student, who wants to generate a digital signature document, as shown in Figure 1, Figure 3 and Figure 6, the user (Ui) first logs in to the transaction system of the issuing unit (Si) , such as the school administration system of a school unit, and find the original digital data of this user (Ui), such as a student's transcript, and then send this transcript to the notary center (CA) for processing, and the notary center (CA) will send the original Add a signature to the scores, and extract the signature content and embed it into the transcript in the form of a watermark. After sending it to the issuing unit (Si), the issuing unit (Si) will perform a hash function operation on the signed transcript and store it in the database. , and then hand the digital signature document to the user (Ui).

請參閱圖3,在本發明之電子文件驗證系統中,上述之使用者,例如學生,欲產生數位簽章文件的流程(S20)包含下列步驟: 進行一下載請求步驟(S210),其係由上述之使用者(Ui)輸入其註冊之帳號(UIDi)與密碼(PWi)登入事務系統,例如學校單位之校務系統,並且由事務系統之資料庫中找到此使用者(Ui)的數位資料(Di),例如學生之成績單,並針對此數位資料提出一下載請求,其中上述之數位資料例如為成績單、畢業證書或在職證明。 Please refer to Figure 3. In the electronic document verification system of the present invention, the process (S20) for the above-mentioned user, such as a student, to generate a digital signature document includes the following steps: A download request step (S210) is performed, in which the above-mentioned user (Ui) enters its registered account (UIDi) and password (PWi) to log in to the business system, such as the school administration system of a school unit, and uses the data of the business system Find the digital data (Di) of this user (Ui) in the library, such as a student's transcript, and make a download request for this digital data, where the above-mentioned digital data is, for example, a transcript, graduation certificate, or employment certificate.

進行一簽章請求步驟(S220),其係由此使用者(Ui)所屬之發證單位(Si)依據上述之下載請求將具有數位資料(Di)之電子檔案、發證單位(Si)之代理碼(Sac)及使用者(Ui)之帳號(UIDi)等三項參數傳輸至公證中心(CA)進行處理。 A signature request step (S220) is performed, in which the issuing unit (Si) to which the user (Ui) belongs transfers the electronic file with the digital data (Di) to the issuing unit (Si) based on the above download request. Three parameters, including the agent code (Sac) and the user's (Ui) account number (UIDi), are transmitted to the Notary Center (CA) for processing.

進行一簽章嵌入步驟(S230),其係由公證中心(CA)透過上述之使用者(Ui)找到對應之金鑰(Pn),並以此對應於發證單位(Si)之代理碼(Sac)及使用者(Ui)之帳號(UIDi)之金鑰(Pn)作為數位資料(Di)之簽章,藉以使得具有數位資料(Di)之電子檔案成為具有簽章及數位資料之數位簽章文件(SDi),且使用隱寫式浮水印技術將簽章之內容嵌入至上述之數位簽章文件(SDi)中,再將此數位簽章文件回傳給發證單位(Si)。 A signature embedding step (S230) is performed, in which the notary center (CA) finds the corresponding key (Pn) through the above-mentioned user (Ui), and corresponds to the agent code (Pn) of the issuing unit (Si). Sac) and the key (Pn) of the user's (UIDi) account (UIDi) serve as the signature of the digital data (Di), thereby making the electronic file with the digital data (Di) become a digital signature with the signature and digital data. seal file (SDi), and use steganographic watermark technology to embed the content of the signature into the above-mentioned digital signature file (SDi), and then send this digital signature file back to the issuing unit (Si).

進行一簽章後運算步驟(S240),其係由發證單位(Si)依據上述之數位簽章文件(SDi)中之數位資料(Di)進行雜湊函數運算而產生一雜湊值[H(SDi)],且將此雜湊值[H(SDi)]儲存於資料庫中,再將上述之數位簽章文件(SDi)發送給使用者(Ui),藉以使得使用者(Ui)獲得具有該簽章及數位資料(Di)之數位簽章文件(SDi)且使得發證單位(Si)之資料庫儲存有獨特且唯一的雜湊值[H(SDi)]。 A post-signature operation step (S240) is performed, in which the issuing unit (Si) performs a hash function operation based on the digital data (Di) in the above-mentioned digital signature file (SDi) to generate a hash value [H(SDi) )], and store this hash value [H(SDi)] in the database, and then send the above-mentioned digital signature file (SDi) to the user (Ui), so that the user (Ui) obtains the signature The digital signature document (SDi) of the stamp and digital data (Di) enables the database of the issuing unit (Si) to store a unique and unique hash value [H(SDi)].

就實際運作而言,當使用者(Ui)進行求職或申請發證深造時,可將上述具有數位資料(Di)之數位簽章文件(SDi)(例如具有簽章的畢業證書或成績 單)送交求職公司人事部門或學校註冊組等業務單位時,此業務單位可作為一查詢者並透過本發明的驗證流程來確認畢業證書或成績單的正確性。換言之,業務單位可將上述數位簽章文件(SDi)上傳到本發明之電子文件驗證系統中,並且經過簽章的確認與比對資料庫中的雜湊值,來確認業務單位所獲得的數位簽章文件(SDi)的來源是否正確且成績單之內容有無被竄改。 In terms of actual operation, when the user (Ui) is applying for a job or applying for a certificate for further study, the above-mentioned digital signature document (SDi) with digital data (Di) (such as a signed graduation certificate or transcript When the document is submitted to a business unit such as the human resources department of the job search company or the school registration group, the business unit can serve as a queryer and confirm the correctness of the graduation certificate or transcript through the verification process of the present invention. In other words, the business unit can upload the above-mentioned digital signature file (SDi) to the electronic document verification system of the present invention, and confirm the digital signature obtained by the business unit by confirming the signature and comparing it with the hash value in the database. Whether the source of the Chapter Document (SDi) is correct and whether the content of the transcript has been tampered with.

請參閱圖1、圖4及圖7,在本發明之電子文件驗證系統中,針對數位簽章文件(SDi)之驗證方法,亦即數位簽章文件完整性驗證流程(S30)包含下列步驟:進行一第一傳輸步驟(S310),其係由查詢者(如上述之業務單位)上傳具有一簽章及一數位資料之一數位簽章文件(SDi)至電子文件驗證系統,其中上述之數位資料係對應於使用者(Ui)之成績或學籍等資料。其中,上述之數位簽章文件(SDi)係具有隱寫式浮水印,且隱寫式浮水印之內容係數位簽章文件之內容。 Please refer to Figure 1, Figure 4 and Figure 7. In the electronic document verification system of the present invention, the verification method for a digital signature document (SDi), that is, the digital signature document integrity verification process (S30) includes the following steps: A first transmission step (S310) is performed, in which the inquirer (such as the above-mentioned business unit) uploads a digital signature document (SDi) with a signature and a digital data to the electronic document verification system, in which the above-mentioned digital signature The data corresponds to the user's (Ui) grades or student status. Among them, the above-mentioned digital signature document (SDi) has a steganographic watermark, and the content of the steganographic watermark is the content of the signature document.

進行一第二傳輸步驟(S320),其中在發證單位(Si)收到上述查詢者所傳輸之數位簽章文件之後,由發證單位(Si)將數位簽章文件傳輸至公證中心(CA)。 A second transmission step (S320) is performed, in which after the issuing unit (Si) receives the digital signature file transmitted by the above-mentioned inquirer, the issuing unit (Si) transmits the digital signature file to the notary center (CA) ).

進行一簽章查驗步驟(S330),其係由公證中心(CA)取得上述之數位簽章文件(SDi)其對應之金鑰(Pn)比對此數位簽章文件(SDi)之簽章是否對應於此使用者(Ui)先前註冊時所產生之金鑰(Pn),藉以判斷並通知發證單位(Si)上述之簽章是否正確,其中此金鑰(Pn)係由公證中心(CA)依據發證單位(Si)之代理碼(Sac)與對應於此使用者之一帳號(UIDi)所預先產生。其中,在本發明中,公證中 心(CA)更選擇性例如進一步比對並判斷數位簽章文件(SDi)之簽章、浮水印、簽章之發行單位是否正確(若正確則為合法,如圖8所示)。 A signature verification step (S330) is performed, in which the notary center (CA) obtains the above-mentioned digital signature document (SDi) and compares the corresponding key (Pn) of the digital signature document (SDi) with the signature of the digital signature document (SDi). Corresponding to the key (Pn) generated when the user (Ui) previously registered, it is used to determine and notify the issuing unit (Si) whether the above signature is correct. The key (Pn) is obtained by the notary center (CA). ) is pre-generated based on the agent code (Sac) of the issuing unit (Si) and an account number (UIDi) corresponding to this user. Among them, in the present invention, during notarization The CA is more selective. For example, it further compares and determines whether the signature, watermark, and issuing unit of the signature of the digital signature document (SDi) are correct (if correct, it is legal, as shown in Figure 8).

進行一雜湊值查驗步驟(S340),發證單位(Si)收到簽章確認訊息(簽章正確)後,由發證單位(Si)將數位簽章文件(SDi)之內容進行雜湊函數運算而產生查驗雜湊值,並比對此查驗雜湊值與發證單位(Si)所預先儲存之雜湊值是否相同,藉以判斷並通知上述之查詢者其所獲得之數位簽章文件(SDi)之內容是否有遭到竄改或是破壞(若遭到竄改或是破壞,則為不合法,如圖9所示)。 A hash value checking step (S340) is performed. After the issuing unit (Si) receives the signature confirmation message (the signature is correct), the issuing unit (Si) performs a hash function operation on the contents of the digital signature document (SDi). Generate a check hash value, and compare whether the check hash value is the same as the hash value pre-stored by the issuing unit (Si), so as to determine and notify the above-mentioned inquirer of the content of the digital signature document (SDi) obtained. Whether it has been tampered with or destroyed (if it has been tampered with or destroyed, it is illegal, as shown in Figure 9).

由此可知,有別於傳統數位簽章的驗證流程,本發明提出的方法主要是在數位簽章的基礎下,將數位簽章的內容擷取出來,將此內容以浮水印的形式鑲嵌在電子文件之中,如此不僅可以確保每個簽章發行人[即,使用者(Ui)]的浮水印不同,同時也有數位簽章不可竄改之特性,更是用另一形式作數位簽章的雙重認證,在作驗證時有更高的安全性。 It can be seen that, different from the traditional digital signature verification process, the method proposed by the present invention mainly extracts the content of the digital signature based on the digital signature, and embeds this content in the form of a watermark. In electronic documents, this not only ensures that the watermark of each signature issuer [i.e., user (Ui)] is different, but also ensures that the digital signature cannot be tampered with. It also uses another form of digital signature. Two-factor authentication provides higher security when performing verification.

而且,就目前技術而言,數位浮水印可大致分兩種,浮現式與隱寫式,本發明所使用的方式為隱寫式,亦即本發明將數位簽章中的簽章內文擷取並嵌入至具有數位簽章的文件中,在文件的驗證部分中將數位簽章用兩種方式作驗證,但因本發明的浮水印是隱藏在文件中,若有心人士想要仿造成績單,就算此人獲取到該發行單位的數位簽章,但在本發明的電子文件驗證系統中,若沒有檢驗到浮水印,此文件依然是不合法的。 Moreover, as far as current technology is concerned, digital watermarks can be roughly divided into two types, the floating type and the steganographic type. The method used in the present invention is the steganographic type, that is, the present invention extracts the text of the signature in the digital signature. Take and embed it into a document with a digital signature. In the verification part of the document, the digital signature is verified in two ways. However, because the watermark of the present invention is hidden in the document, if an interested person wants to forge the transcript , even if this person obtains the digital signature of the issuing unit, if the watermark is not detected in the electronic document verification system of the present invention, the document is still illegal.

由於,透過本發明提出的方法,將數位成績單透過數位簽章與浮水印的不可竄改性,可以確保數位資料的唯一且正確的數值。透過數位簽章的驗證不僅可以確保減少人力、行政及紙張成本,也可以實現資料安全存放的特性。未來可以整合電子畢業證書,讓驗證文憑不再只有單一方法且申請方式複 雜,也確保資料在運輸途中不會弄丟或損壞。不僅是電子文件將來可以透過此系統做驗證與資料管理,之後有身分驗證特性的文件,也可以一併整合在內如身分證、駕照或建保卡等不管是金融業、醫療業各式領域上都能有貢獻,甚至是食衣住行上也有一定的便利性。 Because, through the method proposed by the present invention, the digital transcript can be tamper-proofed through digital signatures and watermarks, thereby ensuring the unique and correct value of the digital data. Verification through digital signatures not only ensures the reduction of manpower, administrative and paper costs, but also enables the secure storage of data. In the future, electronic graduation certificates can be integrated, so that there is no longer a single method for verifying diplomas and multiple application methods. It also ensures that the data will not be lost or damaged during transportation. Not only can electronic documents be verified and managed through this system in the future, but documents with identity verification features can also be integrated in the future, such as ID cards, driver's licenses, or insurance cards, whether in various fields such as the financial industry or the medical industry. It can contribute to everything, and even provide certain conveniences in terms of food, clothing, housing and transportation.

以上所述僅為舉例性,而非為限制性者。任何未脫離本發明之精神與範疇,而對其進行之等效修改或變更,均應包含於後附之申請專利範圍中。 The above is only illustrative and not restrictive. Any equivalent modifications or changes that do not depart from the spirit and scope of the present invention shall be included in the appended patent scope.

S10、S20、S30:步驟 S10, S20, S30: steps

Claims (4)

一種電子文件驗證系統之運作方法,至少包含下列步驟:進行一下載請求步驟,其係由一使用者針對對應於該使用者之一數位資料提出一下載請求;進行一簽章請求步驟,其係由該使用者所屬之一發證單位(Si)依據該下載請求將具有該數位資料之一電子檔案、該發證單位之一代理碼(Sac)及該使用者之一帳號(UIDi)傳輸至一公證中心(CA);進行一簽章嵌入步驟,其係由該公證中心將對應於該發證單位之該代理碼及該使用者之該帳號之一金鑰(Pn)作為一簽章,藉以使得具有該數位資料之該電子檔案,成為具有該簽章及該數位資料之一數位簽章文件,且使用一隱寫式浮水印技術將該簽章之內容嵌入至該數位簽章文件中,再將該數位簽章文件回傳給該發證單位;以及進行一簽章後運算步驟,其係由該發證單位依據該數位簽章文件中之該數位資料進行一雜湊函數運算而產生一雜湊值,且將該雜湊值儲存於一資料庫中,再將該數位簽章文件發送給該使用者,藉以使得該使用者獲得具有該簽章及該數位資料之該數位簽章文件且使得該發證單位之該資料庫儲存有該雜湊值,其中在進行該下載請求步驟之前,更包含由該公證中心配發該代理碼給該發證單位以及依據該代理碼與該帳號產生對應於該代理碼及該帳號之該金鑰。 An operating method of an electronic document verification system, at least including the following steps: performing a download request step, in which a user submits a download request for digital data corresponding to the user; performing a signature request step, in which An electronic file containing the digital data, an agent code (Sac) of the issuing unit and an account number (UIDi) of the user are transmitted to A notary center (CA); performs a signature embedding step, in which the notary center uses the agent code corresponding to the issuing unit and the key (Pn) of the user's account as a signature, Thereby, the electronic file with the digital data becomes a digital signature document with the signature and the digital data, and a steganographic watermark technology is used to embed the content of the signature into the digital signature document. , and then transmit the digital signature document back to the issuing unit; and perform a post-signing operation step, which is generated by the issuing unit performing a hash function operation based on the digital data in the digital signature file A hash value, and the hash value is stored in a database, and then the digital signature file is sent to the user, so that the user obtains the digital signature file with the signature and the digital data, and The database of the issuing unit is caused to store the hash value, which before performing the download request step further includes the notary center allocating the agent code to the issuing unit and generating a correspondence with the account based on the agent code. The proxy code and the key for the account. 如請求項1所述之電子文件驗證系統之運作方法,其中該數位資料為成績單、畢業證書或在職證明。 The operation method of the electronic document verification system as described in request item 1, wherein the digital data is a transcript, graduation certificate or employment certificate. 如請求項1所述之電子文件驗證系統之運作方法,其中該使用者為一學生,該發證單位為一學校單位。 The operation method of the electronic document verification system as described in request item 1, wherein the user is a student and the issuing unit is a school unit. 如請求項1所述之電子文件驗證系統之運作方法,其中該使用者為一求職者,該發證單位為一公司單位。 The operation method of the electronic document verification system as described in request item 1, wherein the user is a job seeker and the issuing unit is a company unit.
TW111148321A 2022-12-15 2022-12-15 Operation method of digital file verification system TWI831523B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
TW111148321A TWI831523B (en) 2022-12-15 2022-12-15 Operation method of digital file verification system

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
TW111148321A TWI831523B (en) 2022-12-15 2022-12-15 Operation method of digital file verification system

Publications (2)

Publication Number Publication Date
TWI831523B true TWI831523B (en) 2024-02-01
TW202427989A TW202427989A (en) 2024-07-01

Family

ID=90824717

Family Applications (1)

Application Number Title Priority Date Filing Date
TW111148321A TWI831523B (en) 2022-12-15 2022-12-15 Operation method of digital file verification system

Country Status (1)

Country Link
TW (1) TWI831523B (en)

Citations (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20010051996A1 (en) * 2000-02-18 2001-12-13 Cooper Robin Ross Network-based content distribution system
CN1579065A (en) * 2001-11-06 2005-02-09 国际商业机器公司 Method and system for the supply of data, transactions and electronic voting
US20150067882A1 (en) * 1999-06-08 2015-03-05 Intertrust Technologies Corporation Methods and systems for encoding and protecting data using digital signature and watermarking techniques
CN105450669A (en) * 2015-12-30 2016-03-30 成都大学 Safety system method and system for data
US20170161439A1 (en) * 2007-07-03 2017-06-08 Eingot Llc Records access and management
CN111178819A (en) * 2019-09-16 2020-05-19 腾讯科技(深圳)有限公司 Electronic document processing method, system and device
US20220058764A1 (en) * 2017-09-20 2022-02-24 Mx Technologies, Inc. Watermark security

Patent Citations (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20150067882A1 (en) * 1999-06-08 2015-03-05 Intertrust Technologies Corporation Methods and systems for encoding and protecting data using digital signature and watermarking techniques
US20010051996A1 (en) * 2000-02-18 2001-12-13 Cooper Robin Ross Network-based content distribution system
CN1579065A (en) * 2001-11-06 2005-02-09 国际商业机器公司 Method and system for the supply of data, transactions and electronic voting
US20170161439A1 (en) * 2007-07-03 2017-06-08 Eingot Llc Records access and management
CN105450669A (en) * 2015-12-30 2016-03-30 成都大学 Safety system method and system for data
US20220058764A1 (en) * 2017-09-20 2022-02-24 Mx Technologies, Inc. Watermark security
CN111178819A (en) * 2019-09-16 2020-05-19 腾讯科技(深圳)有限公司 Electronic document processing method, system and device

Similar Documents

Publication Publication Date Title
US11186111B1 (en) Digitally encoded seal for document verification
CN111213139B (en) Blockchain-based paperless document processing
CN111226249B (en) Trusted platform based on blockchain
CN111108522B (en) Block chain based citation delivery
CN111133734B (en) Block chain based decision execution
US9268969B2 (en) System and method for field-verifiable record authentication
US20080091954A1 (en) Method and system for facilitating printed page authentication, unique code generation and content integrity verification of documents
US11120517B2 (en) Blockchain-based dispute resolution
US20020143711A1 (en) Method and system for performing and providing notary services and verifying an electronic signature via a global computer network
US20060177094A1 (en) A system for embedding, extracting, and executing self-governing behavior and use controls within digital medium content
Yahya et al. A new academic certificate authentication using leading edge technology
US20060123228A1 (en) Document data identity verifying apparatus
TWM520159U (en) Device for generating and identifying electronic document containing electronic authentication and paper authentication
TWI831523B (en) Operation method of digital file verification system
US11971929B2 (en) Secure signing method, device and system
CN115396117A (en) Block chain based tamper-proof electronic document signing and verifying method and system
TWI595380B (en) Device for generating or verifying authenticate electronic document with electronic and paper certification and method thereof
US20240078306A1 (en) Secure, self authenticating document verification system and methods
Kustov et al. DVCS Oracle and the Task of Copyright Preservation in Blockchain-Based Technology
TWI388184B (en) System and method for simulating signatures online
CN116842579A (en) Handwriting electronic signature method
JP2010134850A (en) Official document issuance application device, official document management system, official document issuance application method, and official document management method
KR20120094810A (en) Qr code certificate and verification methods using the internet