Biometric Distributed Signatures Without User Secret Key Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing digital signature algorithms, such as EdDSA, require managing secret information on the signer's side, which can be burdensome, especially in two-party distributed signature schemes, and do not effectively incorporate biometric information for key generation and signature verification.
Innovation Solution
A biometric-based distributed signature scheme is proposed, where a first signature generation apparatus and a second signature generation apparatus utilize helper keys and biometric information to generate and verify signatures without needing to manage secret information on the signer's side, using a system that includes a first helper key, helper data, and third secret information for distributed signature generation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If digital signature algorithms (e.g., EdDSA) are used, then signature verification security is improved, but secret information management burden increases
Solution Approach 1:
The patent extracts the secret information management burden from the signature generation process by introducing a separate key generation apparatus that holds the secret information. The signature generation apparatus only receives public keys and messages, generating signatures without needing to manage secret information itself. This separation resolves the contradiction by maintaining security through proper secret key management while easing the operational burden on signature generators.
Solution Approach 2:
The patent introduces a key generation apparatus as an intermediary that bridges the gap between secure secret key storage and signature generation. This intermediary holds the secret information, generates public keys, and provides them to signature generation apparatuses, allowing signatures to be created without the signature generators needing to manage secret information directly.
2Reliability
If biometric information is incorporated into signature schemes, then user authentication is improved, but system complexity increases
Solution Approach 1:
The patent segments the authentication system into distinct functional modules: a key generation apparatus that incorporates biometric information to generate public keys, and signature generation apparatuses that use these public keys without handling biometric data. This segmentation allows biometric authentication to be integrated securely while keeping the overall system complexity manageable by separating sensitive biometric processing from routine signature operations.
3Reliability
If distributed signature schemes are implemented, then security is improved, but operational burden on signers increases
Solution Approach 1:
The patent introduces a key generation apparatus as an intermediary that pre-generates and distributes public keys to multiple signature generation apparatuses. This allows distributed signature schemes to be implemented where multiple apparatuses can sign messages independently using their respective public keys, maintaining security through distribution while reducing operational burden by eliminating the need for complex coordination during signature generation.
Data Source
AI summary
A first signature generation apparatus generates a second distributed key and by using a second distributed key and third secret information and exchanging information with a second signature generation apparatus, generates a second distributed signature for a message. The second signature generation apparatus acquires second biometric information and restores second secret information using second biometric information and helper data, generates a first distributed key, and by using the first distributed key and the second secret information, and exchanging information with the first signature generation apparatus, generates the first distributed signature for the message, wherein one of the first signature generation apparatus or the second signature generation apparatus generates a signature for the message using the first distributed signature or the second distributed signature.


