Distributed Symmetric Audit Logging for Non-Repudiation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cryptographic secure audit logging techniques face challenges in achieving non-repudiation and compromise resiliency, particularly at the verifier side, while maintaining efficiency and post-quantum security, as symmetric key-based methods lack non-repudiation and public verifiability and public key-based methods are costly and lack post-quantum security.

Innovation Solution

The Compromise-Resilient, Append-only and Distributed Symmetric Audit Logging (CADSA) scheme distributes verification tasks among multiple parties, using symmetric keys to ensure conditional non-repudiation and forward-security, while retaining the efficiency and post-quantum security of symmetric key-based methods, by having each verifier possess only a part of the signer's key, requiring minimal computational and communication overhead.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If symmetric key-based cryptographic methods are used for audit logging, then computational efficiency and post-quantum security are improved, but non-repudiation and public verifiability are lost

Engineering Contradiction:
Improvecomputational efficiencyVSAvoidnon-repudiation
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the verification process by distributing verification capabilities among multiple verifier parties, each holding a portion of the verification key. This allows the system to maintain symmetric key efficiency while achieving distributed verification and conditional non-repudiation, as no single verifier can forge authentication tags alone

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces asymmetric key pairs for verifier parties while maintaining symmetric keys for the signer. This hybrid approach enables public verifiability and non-repudiation through the asymmetric verification keys, while preserving the computational efficiency of symmetric cryptography for the core authentication mechanism

Inventive Principle:
Principle #4Asymmetry

2Reliability

If public key cryptography is used for audit logging, then non-repudiation and public verifiability are achieved, but computational cost and key size increase significantly

Engineering Contradiction:
Improvenon-repudiationVSAvoidcomputational cost
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent segments the cryptographic functionality by using symmetric keys for the signer to generate authentication tags (computationally efficient) and asymmetric keys only for verifier parties to verify tags (enabling public verifiability). This division allows the system to achieve non-repudiation without subjecting the signer to costly asymmetric operations

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies asymmetric cryptography locally only where needed (at verifier parties) rather than universally throughout the system. The signer continues to use efficient symmetric key operations, while only the verifier parties incur the computational overhead of asymmetric cryptography, minimizing overall system cost

Inventive Principle:
Principle #3Local quality

3Device complexity

If a single trusted verifier holds all verification keys, then verification is simplified, but verifier compromise compromises all signers' security

Engineering Contradiction:
Improveverification complexityVSAvoidcompromise resiliency
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the verification key among multiple verifier parties, so that each verifier holds only a portion of the total verification capability. This segmentation ensures that compromise of a single verifier does not compromise the security of all signers, as the adversary would need to compromise all verifiers to forge authentication tags

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a key generation center as an intermediary that distributes segmented verification keys to multiple verifier parties. This intermediary enables the system to achieve both simplified verification (through centralized key management) and improved compromise resiliency (through key segmentation among multiple verifiers)

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10587416B1System and method of audit log protection
Publication Date: 2020.03.10 UNIV OF SOUTH FLORIDA
  • US10587416B1 patent drawing
  • US10587416B1 patent drawing

AI summary

A computer data security system, useful in protecting audit logs, includes symmetric key based techniques, requires only a small-constant number of cryptographic hash operations at the signer side sending a prospective audit log or other computer record data to a primary repository to achieve forward-secure and append-only authentication. The verification is performed by independent parties sharing parts of the symmetric key, wherein the presence of single honest party among all verifier parties ensures a conditional non-repudiation. It also ensures that an active adversary cannot generate authentication tags on behalf of the signer, unless it compromises all verification parties.