WO2017026924A2 - Procédé pour produire une signature analogique et numérique dans un environnement de confiance et un dispositif de sa mise en oeuvre - Google Patents

Procédé pour produire une signature analogique et numérique dans un environnement de confiance et un dispositif de sa mise en oeuvre Download PDF

Info

Publication number
WO2017026924A2
WO2017026924A2 PCT/RU2016/000577 RU2016000577W WO2017026924A2 WO 2017026924 A2 WO2017026924 A2 WO 2017026924A2 RU 2016000577 W RU2016000577 W RU 2016000577W WO 2017026924 A2 WO2017026924 A2 WO 2017026924A2
Authority
WO
WIPO (PCT)
Prior art keywords
microcontroller
signature
trusted environment
digital signature
stylus
Prior art date
Application number
PCT/RU2016/000577
Other languages
English (en)
Russian (ru)
Other versions
WO2017026924A3 (fr
Inventor
Дмитрий Александрович ГЕРТНЕР
Original Assignee
Общество С Ограниченной Ответственностью "Лаборатория Эландис"
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Общество С Ограниченной Ответственностью "Лаборатория Эландис" filed Critical Общество С Ограниченной Ответственностью "Лаборатория Эландис"
Publication of WO2017026924A2 publication Critical patent/WO2017026924A2/fr
Publication of WO2017026924A3 publication Critical patent/WO2017026924A3/fr

Links

Classifications

    • AHUMAN NECESSITIES
    • A61MEDICAL OR VETERINARY SCIENCE; HYGIENE
    • A61BDIAGNOSIS; SURGERY; IDENTIFICATION
    • A61B5/00Measuring for diagnostic purposes; Identification of persons
    • A61B5/103Detecting, measuring or recording devices for testing the shape, pattern, colour, size or movement of the body or parts thereof, for diagnostic purposes
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/64Protecting data integrity, e.g. using checksums, certificates or signatures
    • GPHYSICS
    • G10MUSICAL INSTRUMENTS; ACOUSTICS
    • G10LSPEECH ANALYSIS OR SYNTHESIS; SPEECH RECOGNITION; SPEECH OR VOICE PROCESSING; SPEECH OR AUDIO CODING OR DECODING
    • G10L13/00Speech synthesis; Text to speech systems
    • G10L13/06Elementary speech units used in speech synthesisers; Concatenation rules
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials

Definitions

  • the invention relates to the electronic industry, namely to paperless technologies for document management and can be used to translate the primary documentation of enterprises in electronic form.
  • Known algorithms for electronic digital signature EDS
  • EDS electronic digital signature
  • the ownership of the public key to a specific user is verified by digitally signing the trust center in the form of a digital certificate.
  • a pair of unique keys is generated - secret and public keys of electronic digital signature. The user must keep his secret key secret and use it when signing an electronic document.
  • the disadvantage of electronic digital signature is the difficulty of creating a trusted environment when signing electronic documents, especially when it comes to information containing legal facts.
  • a trusted environment should ensure that the creation of an electronic digital signature on an electronic document is carried out in a trusted system, including hardware and software. For this, it is necessary to use certified computer and software, with the help of which it is supposed to carry out the procedures for creating an electronic digital signature. At the same time, do not allow the computer to connect to non-certified resources on the public network, do not run non-certified software on the computer, or transfer the computer to the wrong hands.
  • the closest analogue is the invention “a method of signing documents with an electronic analogue-digital signature and a device for its implementation” - RF patent N ° 3398334, which allows you to sign documents with an electronic analogue-digital signature, without first generating personal electronic digital signatures of users.
  • the identification of the user who has signed such an electronic document is carried out according to the biometric data of the user, which become an integral part of only this electronic document and which cannot be inserted into another electronic document of a similar format.
  • the objective of the present invention is to provide a method for performing analog-to-digital signature in a trusted environment and a signature device that implements it, which will eliminate this vulnerability and will allow you to safely enter electronic documents directly from any computer into the signature device.
  • the device for signing documents with an electronic analog-to-digital signature in the form of a stylus 1 (Fig. 1) for inputting a handwritten signature consists of a secure compartment 2, in which are located: a microcontroller 3 and an associated memory 4.
  • a microcontroller 3 there is a program code for data processing and cryptographic operations, in particular algorithms for calculating the checksum and electronic digital signature.
  • Memory 4 contains a secret digital signature key.
  • the public key and, if necessary, a digital signature certificate can be located on external media.
  • the stylus 1 includes a transmitter-receiver 5 for wireless communication with an external computer. The transmitter-receiver 5 is connected to the microcontroller 3.
  • the protected compartment 2 contains tamper-evident sensors 6 connected to the microcontroller 3 and the memory 4. In case of violation of the integrity of the protected compartment 2, the secret key is erased in memory 4.
  • the microcontroller 3 associated with the transmitter-receiver 5 for wireless communication with an external computer, it processes data and outputs the processed information through the transmitter-receiver 5 to the computer 7
  • a trusted environment is formed inside the device for signing. The main task is to guarantee to the user that the electronic document signed by him has really moved to the trusted environment without changes, and that the handwritten signature of the user also falls into the trusted environment without changes.
  • the device is characterized in that inertial sensors 8 are additionally placed inside the protected compartment 2 to record the inertial characteristics of the stylus, and therefore the handwritten signature.
  • Inertial sensors 8 are connected with the microcontroller 3.
  • inertial sensors you can use the accelerometer, gyroscope and magnetometer, made by micromechanical technology. These miniature sensors are able to provide the necessary information about the movement of the stylus - acceleration, speed, direction of movement and tilt angles.
  • a sound speaker 9 is placed in the protected compartment 2 and connected to the microcontroller 3.
  • the speech synthesis program is pre-flashed into the microcontroller 3.
  • the method of performing analog-to-digital signature in a trusted environment works as follows.
  • the user sees an electronic document on the monitor screen of the external computer 7. It is verified that a signature device, stylus 1, is connected to computer 7 via a wireless communication channel.
  • the user sets a command to prepare the document for signing through the program interface.
  • the electronic document is sent from the computer 7 to the device for Signatures - stylus 1 over a wireless communication channel.
  • An electronic document is loaded into the memory of the device for signature and transmitted to the microcontroller 3, where, using a speech synthesis program, the text of the electronic document is converted into speech in the form of an audio signal.
  • the audio signal is transmitted to the sound speaker 9 and the user can listen to the text of the electronic document directly from the device for signing, that is, from a trusted environment.
  • the user is guaranteed that the electronic document located in the trusted environment is not modified and corresponds to the original in text form.
  • this method of familiarization with electronic documents before signing them is convenient if you use devices with a small screen as a computer, such as smartphones.
  • the user can sign it using the stylus 1 on the computer screen 7. It is assumed that a screen with the pen input function is used. It can be a tablet computer or a smartphone with a touch screen screen. At the same time, an option is not ruled out in which the user enters his handwritten signature on some external device intended for this purpose.
  • the handwritten signature input device should receive the digitized handwritten signature roller and send it to the transmitter-receiver 5 of the stylus 1 via the wireless transmitter-receiver, from where it will be placed the trusted medium in the protective compartment 2, namely in the microcontroller 3.
  • inertial sensors 8 also supply their microcontroller 3 with their data on the movement of the stylus during the input of a handwritten signature.
  • These data are supplied by such sensors as an accelerometer, gyroscope and magnetometer, made by micromechanical technology.
  • the data from inertial sensors and the handwritten signature roller correlate with each other.
  • This relationship, with a predetermined error, using the program code in the microcontroller 3 is used to determine the ownership of the downloaded digitized signature roller data from inertial sensors.
  • Inertial data acquisition time sensors and the time of receiving points of the trajectory of the handwritten signature roller is fixed, therefore, a common timeline is used for their comparison, which simplifies the analysis of the comparison.
  • the user receives a guarantee that the handwritten signature roller created by him is unchanged placed in a trusted environment.
  • the trusted environment After completion of the scoring of the text and in case of a positive result of the comparison of the video clip, the trusted environment is considered secured and cryptographic operations are performed in the microcontroller 3 of digitally overwriting the digitized handwritten signature roller and the digitized electronic document using the secret digital signature key from memory 4.
  • the invention can be implemented using an additional external audio device 10 (Fig. 2), which is physically separated from the stylus 1.
  • an external audio device can be headphones or speakers.
  • the synthesized audio signal from the stylus 1 is relayed to the external audio device 10.
  • the audio signal can be relayed either via a cable or via a wireless interface, in particular, from the transmitter-receiver 5 to the transmitter-receiver 11.
  • the transmitted audio signal is reproduced on the sound speaker 12.
  • you must use a trusted channel, in order to prevent the potential threat of relaying to an external audio speaker audio signal.
  • a cryptographic module 13 is placed in it.
  • a similar cryptographic module 14 is also included in the signing device, in the main secure compartment 2, the keys are pre-distributed in both cryptographic modules 13 and 14 encryption. It can be either identical symmetric encryption keys or unique asymmetric secret and public keys to provide a common trust environment between both devices through interaction using the specified cryptographic modules and keys.
  • indicators 15 and 16 are placed on both devices from the outside to visually display the current parameters of the audio signal.
  • multi-colored LEDs or liquid crystal indicators can be configured to display parameters such as the amplitude of the sound on several frequency channels. If multi-colored LEDs are used as indicators, then when pronouncing various sounds generated by the speech synthesizer, different LEDs should be lit in different combinations and with different brightness. If the audio signal is relayed unchanged, then on both devices — stylus 1 (signature device) and external audio device 10, the LEDs should light up synchronously and equally, since they visualize the same audio signal and almost at the same time.
  • oscillograms corresponding to the sound parameters of the relayed and outputted audio signal should be displayed synchronously and equally on them.
  • the user will be able by ear and by eye to verify that the audio signal is transmitted from device to device without changes.
  • the speech synthesizer in the signature device can also be used to voice the results of data processing or the need for the user to perform certain critical actions.

Abstract

Un procédé pour former un environnement de confiance afin de produire une signature analogique et numérique et un dispositif de sa mise en oeuvre sont destinés à améliorer la transformation d'une documentation primaire en un format électronique. A la différence des solutions analogues, ce procédé et le dispositif ne nécessitent pas la mise en place d'une procédure de signature des documents électroniques sur des ordinateurs spécialisés certifiés qui assure l'existence d'un environnement de confiance. L'environnement de confiance doit permettre d'assurer que la création d'une signature numérique s'effectue dans un système sécurisé et vérifié qui comprend des équipements et un logiciel appropriés. La non-observation de ce principe crée des menaces potentielles, par exemple, sous la forme d'un remplacement frauduleux d'un document électronique lorsque l'utilisateur voit à l'écran un document et le système violé signe à sa place un autre document. Dans la présente invention l'environnement de confiance est formé dans le dispositif sous la forme d'un stylo électronique, et on peut utiliser à cet effet n'importe quel ordinateur non certifié. L'environnement de confiance de l'invention est réalisé grâce à un ensemble de solutions techniques. Le dispositif pour signer les documents au moyen d'un stylo électronique comprend un compartiment de protection dans lequel se trouve un microcontrôleur avec un code programme, une mémoire avec une clé secrète de signature numérique et, accessoirement, des capteurs inertiels reliés au microcontrôleur et un haut-parleur qui est aussi relié au microcontrôleur et dans lequel est chargé un programme de synthèse vocale. Pour la liaison avec l'ordinateur on utilise une interface sans fil. Les capteurs inertiels servent à vérifier la signature manuscrite de l'utilisateur. Le haut-parleur et le programme de synthèse vocale servent à articuler le texte du document électronique directement depuis l'environnement de confiance. De cette manière, on empêche les données de confiance de s'échapper vers l'extérieur.
PCT/RU2016/000577 2015-08-07 2016-08-26 Procédé pour produire une signature analogique et numérique dans un environnement de confiance et un dispositif de sa mise en oeuvre WO2017026924A2 (fr)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
RU2015133100A RU2616888C2 (ru) 2015-08-07 2015-08-07 Способ выполнения аналого-цифровой подписи в доверенной среде и устройство его реализующее
RU2015133100 2015-08-07

Publications (2)

Publication Number Publication Date
WO2017026924A2 true WO2017026924A2 (fr) 2017-02-16
WO2017026924A3 WO2017026924A3 (fr) 2017-04-13

Family

ID=57983427

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/RU2016/000577 WO2017026924A2 (fr) 2015-08-07 2016-08-26 Procédé pour produire une signature analogique et numérique dans un environnement de confiance et un dispositif de sa mise en oeuvre

Country Status (2)

Country Link
RU (1) RU2616888C2 (fr)
WO (1) WO2017026924A2 (fr)

Cited By (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2019235962A1 (fr) * 2018-06-06 2019-12-12 Dagirov Vitalij Borisovich Système d'enregistrement à distance des utilisateurs de réseau mobile
RU2716221C1 (ru) * 2019-08-07 2020-03-06 Виталий Борисович Дагиров Способ удалённой регистрации пользователя мобильной связи посредством устройства мобильной связи, снабжённого модулем съёмки и сенсорным экраном
RU2721412C1 (ru) * 2019-10-10 2020-05-19 Виталий Борисович Дагиров Способ удалённой регистрации пользователя мобильной связи посредством устройства мобильной связи, снабжённого модулем съёмки и сенсорным экраном
RU2736576C1 (ru) * 2019-10-10 2020-11-18 Виталий Борисович Дагиров Способ удалённой регистрации пользователя мобильной связи посредством устройства мобильной связи, снабжённого модулем съёмки и сенсорным экраном
RU2747039C1 (ru) * 2020-08-03 2021-04-23 Публичное Акционерное Общество "Вымпел-Коммуникации" Способ идентификации абонента в сети оператора связи и его подключения к оператору связи

Family Cites Families (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP3287281B2 (ja) * 1997-07-31 2002-06-04 トヨタ自動車株式会社 メッセージ処理装置
US6935951B2 (en) * 2001-09-04 2005-08-30 Igt Electronic signature capability in a gaming machine
RU2287223C2 (ru) * 2003-08-20 2006-11-10 Ооо "Крейф" Способ подписания документов электронной аналого-цифровой подписью и устройство для его реализации
US8234494B1 (en) * 2005-12-21 2012-07-31 At&T Intellectual Property Ii, L.P. Speaker-verification digital signatures
US10130298B2 (en) * 2012-04-03 2018-11-20 Carnegie Mellon University Musculoskeletal activity recognition system and method
RU2522024C2 (ru) * 2012-10-15 2014-07-10 Общество С Ограниченной Ответственностью "Лаборатория Эландис" Способ подписания электронных документов аналого-цифровой подписью с дополнительной верификацией

Cited By (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2019235962A1 (fr) * 2018-06-06 2019-12-12 Dagirov Vitalij Borisovich Système d'enregistrement à distance des utilisateurs de réseau mobile
RU2709649C2 (ru) * 2018-06-06 2019-12-19 Виталий Борисович Дагиров Система удалённой регистрации пользователей мобильной связи
RU2716221C1 (ru) * 2019-08-07 2020-03-06 Виталий Борисович Дагиров Способ удалённой регистрации пользователя мобильной связи посредством устройства мобильной связи, снабжённого модулем съёмки и сенсорным экраном
RU2721412C1 (ru) * 2019-10-10 2020-05-19 Виталий Борисович Дагиров Способ удалённой регистрации пользователя мобильной связи посредством устройства мобильной связи, снабжённого модулем съёмки и сенсорным экраном
RU2736576C1 (ru) * 2019-10-10 2020-11-18 Виталий Борисович Дагиров Способ удалённой регистрации пользователя мобильной связи посредством устройства мобильной связи, снабжённого модулем съёмки и сенсорным экраном
RU2747039C1 (ru) * 2020-08-03 2021-04-23 Публичное Акционерное Общество "Вымпел-Коммуникации" Способ идентификации абонента в сети оператора связи и его подключения к оператору связи

Also Published As

Publication number Publication date
WO2017026924A3 (fr) 2017-04-13
RU2015133100A (ru) 2017-02-09
RU2616888C2 (ru) 2017-04-18

Similar Documents

Publication Publication Date Title
WO2017026924A2 (fr) Procédé pour produire une signature analogique et numérique dans un environnement de confiance et un dispositif de sa mise en oeuvre
ES2836114T3 (es) Método de envío de información, método de recepción de información, aparato y sistema
CN108964903B (zh) 密码存储方法及装置
EP3333742B1 (fr) Système et procédé de présentation d'informations de confiance sur des dispositifs d'utilisateur non sécurisés
KR102135856B1 (ko) 퍼블릭 블록체인의 노드 인증 방법과 이를 수행하기 위한 장치 및 시스템
US20100086131A1 (en) System and method for remote signature acquisition
CA3058242C (fr) Gestion de cles cryptographiques a partir d'informations d'identite
US20160020908A1 (en) Document signing via mobile device gesture
JP2002258745A (ja) 電子署名装置
JP2017530636A (ja) 認証スティック
US20200117835A1 (en) Method for handwritten electronic signature
WO2018211475A1 (fr) Procédé de création d'un document pourvu d'une signature numérique de haute sécurité
EP2373117A1 (fr) Dispositif de gestion des connexions, terminal de communication, procédé de gestion des connexions, procédé de connexion, programme de gestion des connexions, programme de connexion, et support d'enregistrement
CN112243000A (zh) 应用数据的处理方法,装置、计算机设备及存储介质
CN109426462A (zh) 一种用于网络打印的用户权限管理方法
US9760696B2 (en) Secure physical authentication input with personal display or sound device
KR20090073042A (ko) 디바이스들 사이의 안전한 제휴
KR101466742B1 (ko) 보안 인터페이스를 제공하는 모바일 기기 및 모바일 기기의 보안 강화 방법
US11159320B2 (en) Method for secure connection
KR101679183B1 (ko) 전자 서명 서버 및 방법
GB2540138A (en) Method of exchanging digital content
EP4080391A1 (fr) Dispositif à clé numérique et procédé pour activer un service de clé numérique
JP2001175795A (ja) 診療録作成者認証システム、診療録記憶装置、作成者認証装置および診療録作成者認証方法
KR102124181B1 (ko) 피아노 건반 사용자 인터페이스를 이용한 암호 설정 장치 및 그 방법
EP3737033B1 (fr) Appareil et procédé de partage de données

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 16835534

Country of ref document: EP

Kind code of ref document: A2

NENP Non-entry into the national phase in:

Ref country code: DE

32PN Ep: public notification in the ep bulletin as address of the adressee cannot be established

Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205A DATED 11/07/2018)

122 Ep: pct application non-entry in european phase

Ref document number: 16835534

Country of ref document: EP

Kind code of ref document: A2