A Prototype for PDF Documents Integrity Verification Using Chinese National Cryptographic Algorithms and Hardware Isolation
Abstract
Digitally signed PDFs carry legal binding force in corporate procurement and financial workflows, backed by the U.S. eSign Act (2000) and EU eIDAS (2014). Yet their integrity guarantees are persistently challenged by evolving exploitation techniques. In 2019, Incremental Saving Attacks revealed post-signature modifications could bypass viewer-side verification; in 2021, Shadow Attacks further exploited standard-compliant incremental updates to pre-embed invisible content and alter post-signing presentation, with 16 of 29 mainstream viewers including Adobe Acrobat confirmed vulnerable. Automated tools like PDF-Attacker lower attack barriers, while software detectors such as PDF-Detector suffer from tamper-prone records on general hosts. To address this flaw, we present PDF-Inspector, a hardware-assisted PDF integrity inspection system that combines fingerprint-based operator authentication with the SM3 cryptographic hash algorithm. It generates hardware-signed audit reports on matches and triggers payment suspension on mismatch, defending all three Shadow Attack variants and eliminating host-side tampering risks. End-to-end simulation validates its effectiveness without disrupting daily operations, providing a practical hardware-hardened defense for legally binding signed PDF documents.