Digital Signature Key Pair Distribution via Segmented Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing public key infrastructure (PKI) enrollment methods are vulnerable to man-in-the-middle attacks and are cumbersome due to the need for secure transmission of security-critical data, particularly in the distribution of private keys and activation codes.
Innovation Solution
A method where a generic cryptographic key pair is generated and distributed, with access granted using a primary authentication factor and a supplementary authentication factor, allowing the user to associate the key pair with their identity, reducing the need for secure initial key pair association and enabling secure digital signing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If secure transmission of private keys and activation codes is implemented using traditional PKI enrollment methods, then security is improved, but the process becomes cumbersome and complex
Solution Approach 1:
The patent segments the authentication process into two distinct phases: enrollment (where the key pair is generated and the primary activation code is received) and usage (where the supplementary activation code is provided). This segmentation allows the complex secure transmission requirements to be isolated to the enrollment phase, while the usage phase becomes simpler. The private key is segmented from the activation codes, with the key stored securely and the codes transmitted separately through different channels.
Solution Approach 2:
The patent performs preliminary actions during enrollment by generating the cryptographic key pair and receiving the primary activation code before the actual digital signing operations begin. The private key is pre-stored in secure storage, and the primary activation code is pre-transmitted through a secure channel. This preliminary setup eliminates the need for repeated secure transmissions during subsequent signing operations, simplifying the overall process while maintaining security.
2Reliability
If secure transmission channels are used for distributing private keys and activation codes, then security is improved, but the ease of operation deteriorates
Solution Approach 1:
The patent segments the distribution process into two independent channels: a secure channel for the primary activation code during enrollment, and a less restrictive channel for the supplementary activation code during usage. The private key is segmented and stored securely without requiring active transmission. This segmentation allows the system to maintain high security where needed while improving ease of operation for routine signing operations.
Solution Approach 2:
The system enables self-service by allowing users to perform digital signing operations independently after enrollment. The supplementary activation code can be provided by the user themselves during the signing process without requiring intervention from the certificate authority or repeated secure transmissions. This self-service capability significantly improves ease of operation while maintaining security through the pre-configured authentication factors.
3Reliability
If traditional PKI enrollment methods are used to bind subjects to public keys, then certificate validity is ensured, but vulnerability to man-in-the-middle attacks persists
Solution Approach 1:
The patent introduces an intermediary mechanism in the form of a certificate authority that verifies the primary activation code before issuing the certificate. The CA acts as a trusted mediator that binds the subject's identity to the public key through this verification process. This intermediary step prevents man-in-the-middle attacks by ensuring that only authenticated users can obtain certificates, while the segmented activation code system adds an additional layer of protection against interception and replay attacks.
Solution Approach 2:
The patent performs preliminary authentication verification during enrollment before the certificate is issued. The certificate authority verifies the primary activation code in advance, establishing a trusted binding between the subject and public key before any signing operations occur. This preliminary action prevents man-in-the-middle attacks by ensuring authentication happens before the cryptographic credentials are made active, eliminating the vulnerability window that exists in traditional enrollment methods.
Data Source
AI summary
The invention provides a method for providing a strong link between a Subject and a cryptographic public/private key pair. The proposed Subject device and key distribution algorithm is less prone to man-in-the middle attacks as comparable known algorithms, thereby inherently strengthening the trustworthiness of any digital signature made with a private key distributed to a user in accordance with the proposed method. The invention additionally enables distribution of authentication factors over unsecure channels and reducing the need of sensitive information transmission by at the same time augmenting security for finally associating a generated public/private key pair to a Subject and using it for signature creation purposes.


