CORE Cryptographic Signature Scheme for Digital Forensics
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cryptographic digital forensic tools face challenges in achieving non-repudiation, public verifiability, and high space efficiency while maintaining breach-resiliency and scalability, particularly due to limitations in symmetric and asymmetric cryptographic techniques.
Innovation Solution
The development of novel forward-secure and aggregate signature schemes, referred to as CORE, which offer signature and partial public key aggregation with high efficiency for a practically unbounded number of time periods, utilizing Boneh-Lynn-Shacham and Efficient and Tiny Authentication signatures to reduce key sizes and computational overhead.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If symmetric cryptography based secure audit logging techniques are used, then computation and communication efficiency is improved, but non-repudiation and public verifiability cannot be achieved
Solution Approach 1:
The patent combines symmetric and asymmetric cryptographic techniques into a hybrid signature scheme. The symmetric key provides efficient authentication for log entries, while the asymmetric key enables non-repudiation and public verifiability. This merging allows the system to achieve both computational efficiency and cryptographic reliability that neither technique can provide alone.
2Reliability
If asymmetric cryptographic techniques are used, then non-repudiation and public verifiability are achieved, but space efficiency and computational overhead are reduced
Solution Approach 1:
The patent segments the cryptographic functionality into two distinct parts: symmetric key operations for efficient log entry authentication and asymmetric key operations for non-repudiation. This segmentation allows each cryptographic primitive to be used only where necessary, reducing overall key sizes and computational overhead compared to using pure asymmetric cryptography for all authentication needs.
Solution Approach 2:
The patent applies asymmetric cryptography partially - only for the non-repudiation component of authentication, while using more efficient symmetric cryptography for the remaining authentication needs. This partial application of asymmetric cryptography achieves the necessary reliability without the full computational and space overhead of pure asymmetric systems.
3Reliability
If forward-secure signature schemes are implemented, then signer-side compromise resiliency is achieved, but signature and public key sizes increase
Solution Approach 1:
The patent segments the forward-secure signature scheme into symmetric and asymmetric components, where the symmetric key handles the majority of signing operations with compact representations, and the asymmetric key provides forward security with smaller overhead than traditional forward-secure schemes. This segmentation reduces overall signature and public key sizes while maintaining compromise resiliency.
4Reliability
If distributed verification and encryption are used, then breach-resiliency is improved, but continuous availability of distinct non-colluding parties is required
Solution Approach 1:
The patent implements a self-service mechanism where a single verifier can independently verify log authenticity using the published public key and verification algorithm. This eliminates the need for continuous availability of multiple distributed verifiers, as the verification process is self-contained and can be performed by any entity with the public key, while still providing breach-resiliency through cryptographic guarantees.
Data Source
AI summary
A new compromise-resilient and compact cryptographic tool is provided that ensures a breach-resilient authentication and integrity of system measurements in computer systems. The described methods are forward-secure digital signatures with signature and partial public key aggregation capabilities. The methods reduce the total space overhead of signature and public key storage. The methods offer a high space efficiency for systems who has relatively low state transitions, wherein the same message is continuously signed and then followed by different messages.


