Digital Seals for Non-Repudiation of Electronic Attestations
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current electronic identity and credentialing systems face challenges in ensuring secure and reliable identity management over information networks, as they are vulnerable to identity theft, fraud, and lack comprehensive authentication mechanisms, particularly in online transactions where parties are unknown to each other.
Innovation Solution
The system employs personal identity devices that mimic physical credentialing by binding users' identities to their devices through cryptographic means, enabling secure issuance, control, and verification of electronic identities, using multi-factor authentication and digital sealing to ensure only the owner can use their credentials for privileged operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If digital certificates are distributed electronically through PKI, then identity provisioning can be automated and scaled, but the system becomes vulnerable to identity theft and fraud
Solution Approach 1:
The patent segments the identity verification process into multiple independent verification steps, where each verifier can independently validate the identity without relying on a centralized authority. This distributes trust across multiple entities rather than concentrating it in a single PKI system, thereby maintaining automation while improving security against centralized attacks.
Solution Approach 2:
The patent implements preliminary identity verification through a chain of verifiers before the final credential issuance. Each verifier in the chain performs authentication and validation in advance, creating a layered security approach that prevents fraudulent identities from reaching the final issuance stage, thus maintaining both automation and security.
2Reliability
If multi-factor authentication is implemented, then identity assurance is strengthened, but the complexity of the authentication process increases
Solution Approach 1:
The patent designs the verification system where each verifier performs multiple functions: authentication, validation, and attestation. This multi-functionality reduces the need for separate dedicated components for each security function, thereby strengthening identity assurance while managing overall system complexity through role consolidation.
Solution Approach 2:
The patent introduces intermediary verifiers that mediate between the identity holder and the final credential issuer. These intermediaries simplify the complexity by handling the computationally intensive verification tasks and presenting simplified validation results to the final issuer, thus distributing complexity across multiple manageable components.
3Reliability
If digital seals are used for non-repudiation, then the authenticity of attestations is guaranteed, but the computational overhead increases
Solution Approach 1:
The patent implements digital seals selectively only for critical attestation points where non-repudiation is most needed, rather than applying cryptographic sealing to every transaction or data element. This partial application approach maintains authenticity guarantees for essential operations while reducing overall computational overhead and energy consumption.
Solution Approach 2:
The patent performs preliminary hashing and preparation of data before applying digital seals. By pre-processing the data into fixed-size hashes and organizing it in advance, the actual cryptographic sealing operation becomes more efficient and requires less computational energy, while still guaranteeing attestation authenticity when needed.
Data Source
AI summary
The described method is analogous to handling credentials in the physical world where agents and notary publics affix their attestations using their notary seals. The described method enables a person having a personal identity device and an electronic credential (e-credential) to create a digital seal to affix the owner's identity and attestation to an electronic artifact such as a transaction, document, or e-credential. The e-credential owner cannot repudiate having affixed the attestation to the electronic artifact. This enables other parties, including the e-credential owner, to inspect the digital seal affixed to the electronic artifact to identify the owner and the electronic artifact, verify the digital seal, and thereby obtain objective evidence that the attestation is truthful. The private embossing key of the owner's e-credential is used to cryptographically bind the owner's identity and attestation to the electronic artifact by means of a digital seal, while the public inspection key of the owner's e-credential is used to cryptographically verify the digital seal and attestation.


