The modern world of digital document management requires efficiency, and heavy laptops with a set of specific utilities are becoming a thing of the past. Increasingly, users need to check agreement or sign act directly from their mobile device while on the road or in a meeting. The question of how to open an electronic signature on Android is becoming critically important for entrepreneurs, lawyers and ordinary citizens interacting with government services.
However, the procedure for viewing and using an EDS (Electronic Digital Signature) on a mobile platform has its own unique features that differ from the usual work on a PC. Unlike computers, where it is enough to install CryptoPro CSP and browser plugins, the ecosystem requires specialized applications and a special approach to management. Below we will analyze all the nuances of this process, from choosing software to solving common compatibility problems. Android requires specialized applications and a special management approach cryptographic keys. Below we will analyze all the nuances of this process, from choosing software to solving common compatibility problems.
The main difficulty is that the electronic signature itself is not just a picture or a file that can be opened with a standard image viewer. This is a complex mathematical object that requires verification through special encryption algorithms. Understanding this structure will help you avoid mistakes and work securely with documents anywhere in the world.
Choosing the right software for working with digital signatures
The first step towards successfully working with documents is installing the correct software. Standard Android file managers, such as My Files or Google Filesonly display the file extension (usually .sig, .p7s or .sig7), but cannot decrypt the contents or check the validity of the signature. This requires specialized cryptographic utilities.
The most popular and reliable solution in Russian practice is the application CryptoARM Mobile. This tool allows you not only to view signed documents, but also to create new signatures directly on the device. An alternative can be applications from Mindigits or specialized clients from certification authorities, which often have limited functionality, but provide basic verification.
It is important to consider that free versions of apps often have restrictions on the number processed files or size key container. For professional activities, it is recommended to purchase a license, which removes restrictions and provides access to advanced audit functions. In addition, some banks offer their own applications for signing documents if you use their acquiring or corporate services.
- 📱 CryptoARM Mobile is a universal solution for working with GOST encryption and various signature formats.
- 🔐 Gosklyuch —an official application for working with documents signed with a simple electronic signature through State Services.
- 📄 ViPNet CSP —an alternative crypto provider, often used in government agencies and law enforcement agencies.
Before installing, be sure to check the compatibility of the application version with your version. Android. Outdated versions of the OS (below 8.0) may not support modern security standards, which will lead to errors when trying to initialize the cryptographic module.
File formats and features of opening them
Users are often faced with a misunderstanding of which file they need to open. An electronic signature can exist in two main types: attached and detached. In the case of an attached signature, the document and cryptographic information are combined into one file, which usually has the extension .sig or .p7s.
When you try to open such a file in a text editor, you will see only a set of unreadable characters. This is normal, since the hashes and certificates are encrypted inside the binary container. The digital signature application will automatically recognize the structure and extract the source document for display, while simultaneously checking data integrity.
The detached signature is a separate file that lies next to the main document (for example, PDF or XML). In this case, you need to tell the application the path to both files to check. The system will check the hash sum of the document contents with the data from the signature file and issue a verdict on authenticity.
| Signature type | File extension | Required actions | Where it occurs |
|---|---|---|---|
| Attached | .sig,.p7s | Open the file in the crypto application | Invoices, contracts |
| Detached | .sig (separately) | Select a document and signature file | Reporting to the Federal Tax Service, trading |
| Visualization | .pdf (marked) | Open in a PDF reader with PAdES support | International contracts |
| XML signature | .xml (inside the code) | Specialized XML validator | Electronic checks, registers |
What to do if the file has extension .enc? If you see a file with the extension .enc, this means that the document is encrypted and not just signed. To open it, you will need not only a signing certificate, but also the recipient's private key or decryption password. Without this data, viewing the content is impossible.-->
Particular attention should be paid to the formats used in specific departments. For example, the tax service often uses specific reporting formats that require preliminary conversion or the use of specialized plugins inside the main application.
Setting up tokens and root tokens on Android
Working with an enhanced qualified electronic signature (ECES) often requires a physical key carrier, such as Rutoken, JaCarta or Galaktika. Connecting these devices to a smartphone is possible thanks to OTG (On-The-Go) technology, which allows the mobile device to operate in host mode.
The connection process begins with checking physical compatibility. You will need an adapter from USB Type-A (standard flash drive connector) to your phone connector (Type-C or Micro-USB). After physical connection, the phone must detect a new device, as evidenced by a notification in the status bar.
⚠️ Attention
⚠️ Attention
Not all tokens support working with mobile devices. Before purchasing an adapter, make sure that your token model has drivers for the ARM architecture and is compatible with the Android version of your smartphone.
The next step is to install drivers or plugins. Many modern applications, such as CryptoARM, have built-in modules for working with popular tokens, but for some models (especially older versions of JaCarta) you may need to install a separate service "Rutoken for Android" from the Google Play store.
☑️ Preparing a token for work
After successful connection and authorization using the PIN code, the certificate should appear in the list of available keys inside the application. If this does not happen, try changing the connection port or rebooting the device, since sometimes USB drivers are not initialized correctly the first time.
Step-by-step guide for viewing a signed document
Let's consider a detailed algorithm of actions using the example of the most common scenario: checking an attached electronic signature in the format .sig using CryptoARM Mobile applications. This process is intuitive, but requires attention to detail.
Run the installed application and grant it the necessary permissions to access the device memory. Without permission to read files, the app simply will not see the document that you downloaded from mail or instant messenger. Navigation within the application is usually built on the principle of a file manager.
Find the desired file in the list and click on it. The application will automatically analyze the structure of the signature. If the document is signed correctly and the certificates are not expired, you will see a checkmark or the inscription “Signature is correct.” In case of errors, the system will indicate a specific reason: the certificate has expired, the document was changed after signing, or the chain of trust is broken.
To view the contents of a document inside the application, there is usually a “View” button or an eye icon. This allows you to open an attached PDF or XML file without leaving the crypto environment. In some cases, you may need to export the document to an external viewer if the built-in module does not support complex rich text.
If you use cloud storage, many applications support direct integration with Google Drive or Yandex.Disk. This eliminates the need to download the file to the device, saving space and speeding up the work process. It is enough to log in to the cloud service directly from the crypto-utility menu.
Problems with certificates and ways to solve them
One of the most common problems when working with digital signatures on On Android, the error is “Certificate not found” or “Trust chain not built.” This is due to the fact that root certificates of certification authorities (CAs) are not installed on mobile devices by default, unlike full-fledged Windows operating systems.
To solve this problem, you must manually install the root certificate of your CA. It is usually available for download on the website of the issuing organization in the format .cer or .crt. After downloading, the file must be imported into the application storage through the security settings or the special “Certificates” section.
⚠️ Attention: Install root certificates only from the official websites of certification authorities. Downloading such files from unverified sources can compromise the security of your device and lead to a spoofed signature.
Another common problem is the expiration of the certificate. In this case, the application will honestly warn you about the invalidity of the signature. It is impossible to renew the validity of an old certificate; a new one must be issued by a certification authority. However, for archival documents, the old signature remains legally significant if the certificate was valid at the time of signing.
Sometimes there is a conflict between the versions of crypto providers. If you work with documents signed in an older version of the software (for example, CryptoPro 4.0), and you have a new module installed, algorithm compatibility errors may occur. In such cases, updating the application to the latest version or using compatibility mode in the settings helps.
Security of storing keys on a mobile device
Using a smartphone to work with an electronic signature imposes increased security requirements. Losing your device or having an attacker gain access to your unlocked screen could result in documents being signed on your behalf, which can have serious financial and legal consequences.
Never store clear copies of private keys in the shared phone memory or in cloud storage without additional encryption. The ideal option is to use secure containers or hardware tokens that are physically removed from the device after operation.
Be sure to set up a smartphone screen lock using biometrics (fingerprint, Face ID) or a complex pattern. Avoid simple PIN codes like “1234” or “0000” as they are easy to guess. Many crypto applications allow you to set up an additional password to enter the app itself.
A hardware token connected via OTG is the safest way to store a key on Android, since the private key never leaves the token device and is not copied to the phone’s memory.
When installing applications from third-party sources (not Google Play), be sure to check the digital signature of the token itself. APK installation file. Fraudsters often create fake versions of popular crypto utilities that steal data the first time they are launched. Trust only official stores or developer sites.
Frequently asked questions (FAQ)
Is it possible to open an electronic signature without installing special applications?
No, it is impossible to open and check the digital signature using standard Android tools. Signature files have a binary structure and require cryptographic libraries for decryption and verification. You will definitely need to install specialized software, such as CryptoARM or analogues.
Why does the application write “Certificate verification error”, although the validity period is normal?
Most likely, your device does not have the root certificate of the certification authority that issued the signature. The problem may also be a lack of Internet (the application cannot check the revocation status using CRL/OCSP) or an incorrect date and time on the smartphone.
Does my phone support working with Rutoken?
Most modern smartphones running Android 8.0 and higher support OTG technology, which is necessary to work with tokens. However, for an accurate check, it is better to go to the token manufacturer’s website and look at the list of compatible devices, since some budget models may not supply power to the USB port.
What should I do if I forgot the PIN code for the token on my phone?
The number of attempts to enter the PIN code is limited (usually 10 attempts). After the limit is reached, the token is blocked. To unlock, you will need the PUK code that comes with the token. If the PUK code is also lost, you will have to reissue the certificate on a new medium.
Is it possible to sign a document on Android if it was created on an iPhone?
Yes, the electronic signature format is universal and does not depend on the operating system on which the original document was created. The main thing is that you have your current certificate installed on your Android device and the necessary software for signing.