CORE Cryptographic Signature Scheme for Digital Forensics

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cryptographic digital forensic tools face challenges in achieving non-repudiation, public verifiability, and high space efficiency while maintaining breach-resiliency and scalability, particularly due to limitations in symmetric and asymmetric cryptographic techniques.

Innovation Solution

The development of novel forward-secure and aggregate signature schemes, referred to as CORE, which offer signature and partial public key aggregation with high efficiency for a practically unbounded number of time periods, utilizing Boneh-Lynn-Shacham and Efficient and Tiny Authentication signatures to reduce key sizes and computational overhead.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If symmetric cryptography based secure audit logging techniques are used, then computation and communication efficiency is improved, but non-repudiation and public verifiability cannot be achieved

Engineering Contradiction:
Improvecomputation and communication efficiencyVSAvoidnon-repudiation and public verifiability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent combines symmetric and asymmetric cryptographic techniques into a hybrid signature scheme. The symmetric key provides efficient authentication for log entries, while the asymmetric key enables non-repudiation and public verifiability. This merging allows the system to achieve both computational efficiency and cryptographic reliability that neither technique can provide alone.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If asymmetric cryptographic techniques are used, then non-repudiation and public verifiability are achieved, but space efficiency and computational overhead are reduced

Engineering Contradiction:
Improvenon-repudiation and public verifiabilityVSAvoidkey sizes and computational overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the cryptographic functionality into two distinct parts: symmetric key operations for efficient log entry authentication and asymmetric key operations for non-repudiation. This segmentation allows each cryptographic primitive to be used only where necessary, reducing overall key sizes and computational overhead compared to using pure asymmetric cryptography for all authentication needs.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies asymmetric cryptography partially - only for the non-repudiation component of authentication, while using more efficient symmetric cryptography for the remaining authentication needs. This partial application of asymmetric cryptography achieves the necessary reliability without the full computational and space overhead of pure asymmetric systems.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If forward-secure signature schemes are implemented, then signer-side compromise resiliency is achieved, but signature and public key sizes increase

Engineering Contradiction:
Improvesigner-side compromise resiliencyVSAvoidsignature and public key sizes
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent segments the forward-secure signature scheme into symmetric and asymmetric components, where the symmetric key handles the majority of signing operations with compact representations, and the asymmetric key provides forward security with smaller overhead than traditional forward-secure schemes. This segmentation reduces overall signature and public key sizes while maintaining compromise resiliency.

Inventive Principle:
Principle #1Segmentation

4Reliability

If distributed verification and encryption are used, then breach-resiliency is improved, but continuous availability of distinct non-colluding parties is required

Engineering Contradiction:
Improvebreach-resiliencyVSAvoidavailability requirements
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements a self-service mechanism where a single verifier can independently verify log authenticity using the published public key and verification algorithm. This eliminates the need for continuous availability of multiple distributed verifiers, as the verification process is self-contained and can be performed by any entity with the public key, while still providing breach-resiliency through cryptographic guarantees.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11588645B1Systems and methods for compromise resilient and compact authentication for digital forensics
Publication Date: 2023.02.21 UNIV OF SOUTH FLORIDA
  • US11588645B1 patent drawing
  • US11588645B1 patent drawing
  • US11588645B1 patent drawing

AI summary

A new compromise-resilient and compact cryptographic tool is provided that ensures a breach-resilient authentication and integrity of system measurements in computer systems. The described methods are forward-secure digital signatures with signature and partial public key aggregation capabilities. The methods reduce the total space overhead of signature and public key storage. The methods offer a high space efficiency for systems who has relatively low state transitions, wherein the same message is continuously signed and then followed by different messages.