Dynamic Cryptographic Signature Evolution for Trust Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cryptographic signature verification processes fail when signatures become invalid due to expiration, weakness, or loss of trust, leading to delays and additional work for entities involved in creating new signatures, often requiring human intervention and disrupting device or network functionality.

Innovation Solution

A verifying entity dynamically determines a new valid signature by identifying and updating invalid signature attributes, allowing the trust verification process to continue uninterrupted, using a unified service to evolve old signatures into new ones in response to invalidity events such as expired keys or discovered weaknesses.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a static cryptographic signature is used to verify trust of an object, then the verification process is simple and straightforward, but the process fails when the signature becomes invalid (expired, revoked, or weakened)

Engineering Contradiction:
Improvetrust verification reliabilityVSAvoidsignature validity adaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies dynamics by transforming the static cryptographic signature into a dynamic structure that can evolve over time. When an invalidity event occurs (expiration, revocation, weakness detection), the system automatically generates and applies a validity extension that updates the signature's validity period without requiring complete re-verification. This allows the signature to adapt its validity state dynamically while maintaining trust verification reliability.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the validity period parameter of the cryptographic signature through automated extension mechanisms. When the signature approaches expiration or encounters invalidity events, the system automatically extends the validity period by generating new expiration timestamps and updating the signature structure, thereby adapting to changing validity requirements without manual intervention.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If a new cryptographic signature is created manually when the old one becomes invalid, then the signature remains secure and valid, but the process requires human intervention and causes delays

Engineering Contradiction:
Improvesignature validityVSAvoidtrust verification time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by establishing automated validity extension mechanisms in advance before invalidity events occur. The system pre-configures extension policies, trusted entity identifiers, and automated workflows that trigger immediately when invalidity events are detected, eliminating the need for manual signature creation and reducing verification time while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system performs self-service by automatically detecting invalidity events, generating validity extensions, and updating signatures without human intervention. The automated processes include monitoring signature validity periods, detecting expiration or revocation events, retrieving trusted entity information, and applying extensions—all executed by the system itself, thereby eliminating delays associated with manual operations.

Inventive Principle:
Principle #25Self-service

3Reliability

If additional work is performed to create and re-submit a new signature when verification fails, then trust can be re-established, but resource consumption increases and user experience deteriorates

Engineering Contradiction:
Improvetrust re-establishmentVSAvoidverification process efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent ensures continuity of useful action by maintaining the original trust verification process without interruption. When invalidity events occur, the system seamlessly applies validity extensions that allow the verification process to continue using the same signature structure and trusted entities, avoiding the need to abandon and restart verification workflows, thereby maintaining productivity and user experience.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The patent introduces an intermediary validity extension mechanism that mediates between the original cryptographic signature and the trust verification process. This extension acts as a bridge that validates the signature's continued trustworthiness without requiring complete re-verification, reducing resource consumption while maintaining trust re-establishment reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If hardcoded signatures are used to handle invalidity events, then the system can respond to signature failures, but the device complexity increases and the system becomes less flexible

Engineering Contradiction:
Improveinvalidity event responseVSAvoidsignature management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by creating a multi-functional validity extension mechanism that handles multiple types of invalidity events (expiration, revocation, weakness detection) through a single automated process. The extension system works with various signature types and trusted entities without requiring separate hardcoded solutions for each scenario, thereby reducing device complexity while maintaining reliable response to invalidity events.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10218515B2Evolving a signature during trust verification of an object
Publication Date: 2019.02.26 MICROSOFT TECHNOLOGY LICENSING LLC
  • US10218515B2 patent drawing
  • US10218515B2 patent drawing
  • US10218515B2 patent drawing

AI summary

The techniques described herein dynamically determine a new signature that is valid and that can be used to verify trust of an object (e.g., a certificate, an executable file, user credentials, etc.). The dynamic determination of the new signature is implemented by an entity performing a trust verification process. The entity can execute a single unified service to establish trust in the object. The dynamic determination, or the ability for an invalid signature to evolve into a newer version that can be trusted, is implemented in response to an invalidity event indicating that the initial signature is no longer valid for trust verification purposes. Example invalidity events can comprise the expiration of a time sensitive signature attribute (e.g., an expired private key), a recently discovered weakness associated with an individual signature attribute (e.g., a key of insufficient length), or a determination that a certificate authority can no longer be trusted.