Attribute-Based Digital Signature Delegation via Re-Signing Unit
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing attribute-based digital signature systems lack flexibility in delegating signing authority, as they require direct transfer of signature keys, which can lead to security risks and increased key management burdens, especially in healthcare scenarios where secure and efficient delegation of signing capabilities is crucial.
Innovation Solution
An attribute-based digital signature system with a re-signing unit that allows delegation of signing authority based on attributes, enabling conversion of signatures from one set of attributes to another without transferring the original signature key, using a semi-trusted proxy to manage re-signing operations and enforce attribute-based policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If signature keys are directly transferred to delegatees for signing operations, then signing authority can be delegated, but security risks increase and key management burden increases
Solution Approach 1:
The patent segments the signature key into two separate components: a first key component kept by the delegator and a second key component held by the delegatee. Neither component alone can perform signing operations. The delegator's signature key is segmented such that the delegatee only receives a partial component, eliminating the security risk of full key exposure while enabling controlled delegation of signing authority.
Solution Approach 2:
The patent introduces a semi-trusted re-signing unit as an intermediary that facilitates the delegation process. This unit holds the delegator's signature key component and collaborates with the delegatee's component to generate signatures. The intermediary mechanism allows the delegator to delegate signing capability without directly exposing their private key to the delegatee, thus maintaining security while enabling versatility.
2Ease of operation
If signature keys are directly transferred to delegatees, then signing operations can be performed, but key management complexity increases
Solution Approach 1:
By segmenting the signature key into distributed components, the patent simplifies key management for delegatees who only need to securely store their smaller key component rather than managing complete private keys. The complexity of key management is distributed and reduced for individual users while maintaining operational capability.
Solution Approach 2:
The re-signing unit acts as a managed intermediary that handles the complex key combination operations. Instead of requiring delegatees to manage and combine key components themselves, the semi-trusted unit performs the key management complexity centrally, simplifying the operational burden on individual users while enabling signing operations.
3Reliability
If traditional attribute-based signatures are used, then data origin can be verified, but flexibility in delegating signing authority is limited
Solution Approach 1:
The patent applies segmentation to the attribute-based signature scheme by dividing the signature key based on attribute sets. The delegator's attributes are segmented and distributed such that the delegatee receives key components corresponding to specific attribute subsets. This enables flexible delegation where different attribute combinations can be authorized without compromising the ability to verify data origin through attribute-based validation.
Solution Approach 2:
The patent introduces dynamic flexibility to attribute-based signatures by allowing the delegator to dynamically specify which attribute subsets should be delegated. The system can adaptively adjust which key components are distributed to delegatees based on the delegator's current authorization needs, while maintaining the static security property that only valid attribute combinations can produce verifiable signatures.
Data Source
AI summary
An attribute-based digital signature system is disclosed. A first signature generating unit (1) is used for generating a first signature (10) for a document (11), based on a first signature key (12) and the document (11). A re-signing unit (2) is used for generating a second signature (13) for the document (11), based on the first signature (10) and a re-signing key (14), wherein the re-signing unit (2) is arranged for handling attributes (15, 16) associated with the first signature (10) and/or the second signature (13). The second signature (13) is associated with a second set of attributes (16,16′) determined by the re-signing key (14), wherein the second set of attributes (16) comprises a plurality of attributes. The first signature (10) is associated with a first set of attributes (15), wherein the first set of attributes (15) comprises a plurality of attributes, and the re-signing unit (2) is arranged for generating the second signature (13) only if the first set of attributes (15) satisfies a set of conditions (17, 17′).


