EP3300545A1 - Verfahren zur elektronischen unterzeichnung eines dokuments mittels eines smartphones - Google Patents

Verfahren zur elektronischen unterzeichnung eines dokuments mittels eines smartphones

Info

Publication number
EP3300545A1
EP3300545A1 EP17735171.5A EP17735171A EP3300545A1 EP 3300545 A1 EP3300545 A1 EP 3300545A1 EP 17735171 A EP17735171 A EP 17735171A EP 3300545 A1 EP3300545 A1 EP 3300545A1
Authority
EP
European Patent Office
Prior art keywords
document
terminal
server
signatory
signature
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Withdrawn
Application number
EP17735171.5A
Other languages
English (en)
French (fr)
Inventor
Claude RAPOPORT
Christophe CLOESEN
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Portima Scrl
Original Assignee
Portima Scrl
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Portima Scrl filed Critical Portima Scrl
Publication of EP3300545A1 publication Critical patent/EP3300545A1/de
Withdrawn legal-status Critical Current

Links

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/31User authentication
    • G06F21/33User authentication using certificates
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/64Protecting data integrity, e.g. using checksums, certificates or signatures
    • G06F21/645Protecting data integrity, e.g. using checksums, certificates or signatures using a third party
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3215Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using a plurality of channels
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3226Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using a predetermined code, e.g. password, passphrase or PIN
    • H04L9/3228One-time or temporary data, i.e. information which is sent for every authentication or authorization, e.g. one-time-password, one-time-token or one-time-key
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3234Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving additional secure or trusted devices, e.g. TPM, smartcard, USB or software token
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3247Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving digital signatures
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3263Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving certificates, e.g. public key certificate [PKC] or attribute certificate [AC]; Public key infrastructure [PKI] arrangements
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/31User authentication
    • G06F21/313User authentication using a call-back technique via a telephone network

Definitions

  • the present application relates to the electronic signature of documents, such as, for example, insurance contracts, but, more generally, all documents of a service provider or a product supplier.
  • the document to be signed is accompanied by a certificate of characterization of the signatory and his signature.
  • the certificate contains the surname, first name, date of birth of the signatory and an identification number.
  • the signed document contains a quick reference QR code (Quick Reference) that represents an internet link to the signed document.
  • a signature software irreversibly transforms the PDF document to be signed into a string of characters (HASH) that the signatory must sign.
  • the signature is made using a Public Key Infrastructure (PKI).
  • PKI Public Key Infrastructure
  • the smart ID card contains this public key and a private key.
  • the public key is associated with a PKI certificate issued by the PKI server, which is an electronic file that defines the owner of the public key.
  • the identity card of the signatory having been introduced in his reader, and the document to sign transformed into HASH, it is with the signature of the HASH that one proceeds.
  • the signature software the number of personal identification (PIN code) is requested to the signer to have access to the private key stored and recorded in the chip.
  • the HASH is encrypted by means of the private key and the resulting signed HASH, as well as the certificate are sent to the signature server that the PDF document assistants, together with the exact date and time.
  • the recipient can, by means of the public key of the PKI certificate, verify the integrity of the document and the authenticity of the signer. Note that the pairing of both public and private keys is impossible, unless you have exorbitant means.
  • the invention relates to a method of electronically signing a document of a recipient, by a signatory having a smart telephone mobile terminal and to a camera, via the Internet and to the using a signature server and an application store, connected to the Internet and having a signature application, with a secure cryptography library, a method in which
  • the recipient sends the server the document to sign and the telephone number of the signatory
  • the signer downloads the application on his terminal and connects to it,
  • the server sends a service message (MS) to the terminal with a user code for the continuation of the application, code that the terminal returns to it for security,
  • MS service message
  • the signatory using his terminal, takes at least one picture of his identity document which is sent to the server by the Internet,
  • the terminal creates, from the secure library, a private key and a public key that is sent to the server,
  • the server creates the HASH of the document to be signed and a certificate of signature and sends them to the terminal,
  • the terminal as a signature, encrypts the HASH using the private key and a PIN code and
  • the terminal sends the encrypted HASH and the certificate to the server that recompose the signed document thus available to the recipient of the document.
  • the server After reception by the server of the photo of the signer's identity document, the server checks the authenticity of the signer's identity document, preferably by character recognition and image processing.
  • the steps of sending a service message (MS) and returning the code, taking the photo of the identity document and authenticating the signer's identity document constitute a global authentication step of the signatory.
  • the method of the invention can therefore be extended to an electronic signature method, a document of a recipient, by a signer having a smart telephone mobile terminal and to a camera, via the Internet and to using a signature server and an application store, connected to the Internet and having a signature application, with a secure cryptography library, a method in which
  • the recipient sends to the server the document to be signed and the telephone number of the signatory
  • the signer downloads the application on his terminal and connects to it,
  • the signatory proceeds to the signature of the electronic document, before sending it to the server where it is available to the recipient of the document.
  • the authentication of the signatory includes the steps according to which
  • the server sends a service message (MS) to the terminal with a user code for the continuation of the application, code that the terminal returns to it for security,
  • MS service message
  • the signatory using his terminal, takes at least one picture of his identity document which is sent to the server by the Internet,
  • the server checks the authenticity of the signatory's identity document.
  • the signature of the document comprises the steps according to which the terminal creates, from the secure library, a private key and a public key that is sent to the server,
  • the server creates the HASH of the document to be signed and the certificate of signature and sends them to the terminal
  • the terminal as a signature, encrypts the HASH using the private key and a PIN code and
  • the terminal sends the encrypted HASH and the certificate to the server that recompose the signed document thus available to the recipient of the document.
  • FIG. 1 is a general diagram of the system by means of which the method of the invention is implemented;
  • FIG. 2 is a block diagram of the steps of the method of the invention.
  • FIG. 3 is a block diagram of the signatory authentication step
  • FIG. 4 is a block diagram of the certificate creation step
  • FIG. 5 is a copy of a signature certificate
  • the method which will now be described is intended to be signed by a signatory equipped with a mobile telephone terminal 1, here smart phone type, and which has a camera 2 and a chip 3, a document proposed by a recipient, here an insurance broker, intended to receive the signed document and who has a terminal 4, the two terminals 1 and 4 can be connected to the Internet network 5 as well as to a signature server 6 and an application store 9, which can therefore also be connected to the Internet 5.
  • a signature application is implemented in a first part 7 'in the server 6 and in a second part 7 "in the application store 9.
  • the part 7' is the" server "application, the part 7", the mobile app.
  • a secure cryptography library 8 is located in the store 9, preferably, as here, in the mobile application 7 ".
  • the recipient begins, through its terminal 4, to send, via the Internet 5, to the server 6 the document to be signed by the owner of the terminal 1, that is to say the signatory. With the document to be signed, is also sent the phone number of the signer who knows the recipient.
  • the signer downloads, in his terminal 1, the signature application 7 'of the server 6 and the signature application 7 "of the store 9 and connects to this application, here through a user code and a password.
  • the signer displays the document to be signed and the phone number provided by the recipient, which he can view.
  • the signatory then clicks on the icon "to sign", then, by another click, must accept the general conditions of the use of the signature application.
  • the recipient read i sends (1 02) directly over the Internet 5 a service message (MS), here an SMS, with a single-use code for the continuation of the application, code that the terminal 1 returns to the recipient by security for once again confirm that his phone number is the correct one.
  • MS service message
  • the recipient proceeds to take a picture 1 03 and takes photos of the front and back of his identity card, if it is this piece of identification. Note that other pieces of identity are possible such as a passport.
  • the shooting conditions are inevitably random, as to the orientation of the map, the ambient light and the disturbing reflections. For subsequent control this should be taken into consideration.
  • identity documents to avoid counterfeits, have many visual elements that create noise that disrupts the recognition of their data.
  • identity documents there may be several types of identity documents in each country, with different zone compositions, which must also be taken into account in their recognition.
  • Terminal 1 sends the photos to the server 6.
  • the control 1 04 of the authenticity of the identity card of the signatory is done as follows, by character recognition and image processing.
  • the data areas are precisely recognized by a pre-cut that remains difficult given the freedom of the shooting by the signatory, with a background, orientation and lighting that can leave something to be desired. In any case, arbitration and corrections are necessary.
  • the saturation channel makes it possible to detect the chip of the identity card.
  • the value channel is used to detect the orientation, the face, the machine readable zone (readable zone, MRZ) and, if it exists, the barcode.
  • Points are detected that may be on an object outline in the image. These points are connected to form candidate lines representing the real edges of all the photographed objects of the image.
  • To straighten the image we extract from the set D of the candidate straight lines di, a set of orientation angles E
  • orientations are sorted according to the number of occurrences. The most present orientation E, is retained and all orientations whose difference with E, in the implementation here performed, less than 3 degrees are rejected. If an element of the line of orientation E can not be detected, we deduce that the orientation is bad and we start again by rejecting the orientation E, and selecting the su ivante. Detection of map elements
  • the image can undergo an "advanced morphological transformation" that highlights the element.
  • An iteration loop on one of the threshold parameters makes it possible to cover some photographs of more extreme contrasts. As soon as the element is detected, we leave the iteration.
  • T text areas, F, areas to be blurred.
  • An adjustment step can be made by comparing names determined by character recognition of the front and back faces, which are in two different formats. It will be noted that the applicant, for these control steps, made use of the "Open Computer Vision" library via Emgu Computer Vision. The purpose of this check is to ensure, with a sufficient degree of certainty, that the person using the signing application is who they claim to be. We make sure that the photographed part is probably a true identity document, that the front face of the part corresponds to its back side, that the part is not outdated and that the holder is major.
  • a cleaning step 1 4 which aims to expell the certificate that will be created data relating to the privacy of the signatory, such as the national registry number.
  • the entire terminal 1 of the signer and the server 6 will create data for certification of the signature.
  • This data includes the signatory's last name, first name and date of birth, his email address, the "reduced" telephone number, and the unique serial number of his certificate.
  • the terminal 1 From the secure library 8 of the application (7 "), the terminal 1 creates (1 1 1) a private key and a cryptographic public key stored in the mobile application 7".
  • This library can be provided by Whitecryption-Approval NIST FIPS 1 40-2 Level 1
  • the terminal 1 sends (1 1 2) the public key to the server 6 to link the data of the signer to the public key, sealed by a signature of a certification authority.
  • the server creates (1 1 3) then the certificate (FIG. 5) that it sends (1 1 4) to the terminal 1.
  • the server 6 in which was entered the document to be signed in PDF format, electronically transforms (1 2) this document into a string of characters (HASH) and that's what the signatory has to sign.
  • the server 6 sends it to the terminal 1.
  • the terminal encrypts the HASH using the private key and a PIN code that is involved at this point in the process.
  • This PIN code has been chosen by the signatory (digital or alphanumeric) for the purposes of signing and to allow access to the private key.
  • the terminal sends the HASH and the certificate to the server that recompose the signed document (Figure 6) before making it available to the signatory. He could also send it to the recipient.
  • this electronic signature method that has just been described is to be implemented by a signer of a document of a recipient when the signatory wants to make this signature for the first time with a terminal with which he had never made such an electronic signature. In other words, it is a first signature with a new empty terminal of the signature application.
  • the recipient sends the server (6) the document to be signed and the telephone number of the signatory
  • the server (6) creates the HASH of the document to be signed and sends it to the terminal (1), the terminal (1), by way of signature, encrypts the HASH using the private key and the PIN code previously chosen by the signatory and
  • the terminal (1) sends the encrypted HASH and the certificate to the server (6) which recomposes the signed document thus available for the recipient of the document.
  • the signature application has been downloaded to the terminal, the server already has the photo of the signer's ID, the private and public keys have already been created and sent to the server and the signature certificate has already been created. .

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Theoretical Computer Science (AREA)
  • Physics & Mathematics (AREA)
  • Computer Hardware Design (AREA)
  • Software Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • General Physics & Mathematics (AREA)
  • General Health & Medical Sciences (AREA)
  • Bioethics (AREA)
  • Health & Medical Sciences (AREA)
  • Management, Administration, Business Operations System, And Electronic Commerce (AREA)
EP17735171.5A 2016-08-02 2017-07-07 Verfahren zur elektronischen unterzeichnung eines dokuments mittels eines smartphones Withdrawn EP3300545A1 (de)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
BE2016/5625A BE1023971B1 (fr) 2016-08-02 2016-08-02 Procede de signature electronique d'un document
PCT/EP2017/067134 WO2018024445A1 (fr) 2016-08-02 2017-07-07 Procede de signature electronique d'un document au moyen d'un téléphone inteligent

Publications (1)

Publication Number Publication Date
EP3300545A1 true EP3300545A1 (de) 2018-04-04

Family

ID=56737841

Family Applications (1)

Application Number Title Priority Date Filing Date
EP17735171.5A Withdrawn EP3300545A1 (de) 2016-08-02 2017-07-07 Verfahren zur elektronischen unterzeichnung eines dokuments mittels eines smartphones

Country Status (6)

Country Link
EP (1) EP3300545A1 (de)
BE (1) BE1023971B1 (de)
FR (1) FR3054906B1 (de)
GB (1) GB2555167A (de)
NL (1) NL2019358B1 (de)
WO (1) WO2018024445A1 (de)

Families Citing this family (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
FR3092419B1 (fr) * 2019-02-05 2021-05-21 In Idt Procédé et Système pour authentifier une signature manuscrite.
CN114338035B (zh) * 2021-12-15 2024-10-01 南京壹证通信息科技有限公司 一种基于密钥协同签名的移动端pdf电子签章方法及系统

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
DE102013100635A1 (de) * 2013-01-22 2014-07-24 IDnow GmbH Benutzer-Identifikation
US20160360403A1 (en) * 2015-01-05 2016-12-08 Ebid,Products & Solutions, S.L. Procedure for generating a digital identity of a user of a mobile device, digital identity of the user, and authentication procedure using said digital identity of the user
DE102015206623A1 (de) * 2015-04-14 2016-10-20 IDnow GmbH Digitale signatur mit fern-identifizierung

Also Published As

Publication number Publication date
FR3054906B1 (fr) 2019-06-07
NL2019358B1 (en) 2018-02-09
BE1023971B1 (fr) 2017-09-26
GB201711702D0 (en) 2017-09-06
FR3054906A1 (fr) 2018-02-09
WO2018024445A1 (fr) 2018-02-08
GB2555167A (en) 2018-04-25

Similar Documents

Publication Publication Date Title
EP3690686B1 (de) Authentifizierungsverfahren, server und elektronische identitätsvorrichtung
US20180026790A1 (en) Evidence system and method to determine whether digital file is forged or falsified by using smart phone and smart phone having certification function of smart phone screen capture image and method thereof
EP3665600B1 (de) Verfahren zur elektronischen signierung eines dokuments durch eine vielzahl von unterzeichnern
EP2591463B1 (de) Sicheres System und Verfahren zur Feststellung und Aufzeichnung einer Identität
KR101765328B1 (ko) 전자 계약을 위한 신분증 정보 취득 모바일 시스템
WO2019233951A1 (fr) Une application logicielle et un serveur informatique pour authentifier l'identité d'un créateur de contenu numérique et l'intégrité du contenu du créateur publié
EP2619941A1 (de) Verfahren, server und system zur authentifizierung einer person
CN108124093B (zh) 防止终端拍照造假的方法及系统
FR3054906B1 (fr) Procede de signature electronique d'un document
KR20160123752A (ko) 스마트폰 화면 캡쳐 이미지 인증 기능을 가지는 스마트폰 및 스마트폰 화면 캡쳐 이미지 인증 방법
WO2022079110A1 (fr) Procede et dispositif de signature et de certification a distance de donnees d'identification d'une personne
EP2954449B1 (de) Authentifizierung einer digitalisierten handschriftlichen signatur
EP2005379B1 (de) System zum sichern von elektronischen transaktionen über ein offenes netzwerk
EP3594880A1 (de) Gesichertes übertragungsverfahren von kryptografischen daten
AU2018455995A1 (en) Universal certified and qualified contracting method
WO2020225292A1 (fr) Procede de generation d'un code d'archivage pour creer une empreinte d'un contenu multimedias
EP4193283B1 (de) Verfahren zur erzeugung eines sicheren digitalen dokuments, das auf einem mobilen endgerät gespeichert ist und mit einer digitalen identität assoziiert ist
KR20160124053A (ko) 스마트폰 화면 캡쳐 이미지 인증 기능을 가지는 스마트폰 및 스마트폰 화면 캡쳐 이미지 인증 방법
EP4519779A1 (de) Tragbare, unabhängige vorrichtung zur sicherung der datenübertragung und entsprechendes verfahren
EP2992640B1 (de) Verfahren zur erzeugung von mindestens einer abgeleiteten identität
FR3093836A1 (fr) Identité numérique
KR20150067558A (ko) 증명사진 등록 시스템
WO2007048839A1 (fr) Procede de securisation des paiements par decoupage des montants
FR3065552A1 (fr) Procede et systeme d’authentification et de non-repudiation
CH710819B1 (fr) Système et procédé de contrôle d'accès à une prestation.

Legal Events

Date Code Title Description
STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: UNKNOWN

STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: THE INTERNATIONAL PUBLICATION HAS BEEN MADE

PUAI Public reference made under article 153(3) epc to a published international application that has entered the european phase

Free format text: ORIGINAL CODE: 0009012

STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE

17P Request for examination filed

Effective date: 20171117

AK Designated contracting states

Kind code of ref document: A1

Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR

AX Request for extension of the european patent

Extension state: BA ME

STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: EXAMINATION IS IN PROGRESS

17Q First examination report despatched

Effective date: 20190115

STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWN

18D Application deemed to be withdrawn

Effective date: 20190528