Digital Certificate Issuance via Encrypted Image Envelope
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current digital certificate issuing systems are vulnerable to hacking and phishing attacks, particularly during the re-issuance process, as personal authentication information is transmitted online without face-to-face verification, and the risk of leakage is high due to the use of simple numerals and texts for authentication, leading to potential misuse by third parties.
Innovation Solution
A method and system for issuing, updating, and re-issuing digital certificates using an encrypted image, where a user-selectable image is combined with the digital certificate using steganography to create a sealed digital envelope image, which is transmitted to the user terminal only after valid authentication, and can be stored in a sealed state for secure extraction.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If personal authentication information is transmitted online for re-issuance without face-to-face verification, then convenience and efficiency of digital certificate re-issuance is improved, but security and risk of hacking/phishing attacks deteriorates
Solution Approach 1:
The patent introduces a proxy server as an intermediary between the user terminal and certificate server. The proxy server receives personal authentication information from the user terminal, transmits it to the certificate server for processing, and then delivers the digital envelope image back to the user terminal. This intermediary structure allows secure online re-issuance while maintaining security through the proxy server's authentication and encryption mechanisms.
Solution Approach 2:
The patent replaces the traditional mechanical face-to-face verification system with a digital encryption system. Instead of physical presence verification, the system uses encrypted image transmission and digital envelope technology to authenticate users and protect personal information during online re-issuance operations.
2Ease of operation
If simple numerals and texts are used for personal authentication, then ease of operation and user convenience is improved, but vulnerability to keyboard hacking and phishing attacks deteriorates
Solution Approach 1:
The patent changes the parameter of authentication from simple text-based inputs to image-based authentication. Users select images from a gallery instead of typing passwords, fundamentally altering the authentication mechanism to resist keyboard hacking while maintaining ease of use through visual selection.
Solution Approach 2:
The patent uses image copying and encryption instead of text-based authentication. The selected image is copied, encrypted, and transmitted as a digital envelope, creating a secure representation of authentication that cannot be easily replicated or hacked through keyboard interception.
3Ease of operation
If digital certificate is stored in PC or portable storage medium, then accessibility and ease of use is improved, but prevention of theft and misuse deteriorates
Solution Approach 1:
The patent embeds the digital certificate inside an encrypted image, creating a nested structure where the certificate is contained within the image data. This nesting mechanism protects the certificate from theft while maintaining accessibility, as the encrypted image can be stored and transmitted securely without exposing the underlying certificate.
Solution Approach 2:
The encrypted image acts as an intermediary between the digital certificate and the storage medium. Instead of storing the certificate directly, the system stores the encrypted image which contains the certificate, providing an additional layer of protection against theft and unauthorized access.
4Device complexity
If conventional digital certificate issuing system is used, then system simplicity and ease of implementation is maintained, but inability to prevent hacking attacks between users and certificate agencies deteriorates
Solution Approach 1:
The patent introduces a proxy server as an intermediary component that handles authentication and encryption operations. This adds a layer of security without fundamentally complicating the overall system architecture, as the proxy server integrates with existing certificate issuance workflows while providing enhanced protection against phishing attacks.
Solution Approach 2:
The patent replaces conventional text-based authentication mechanisms with image-based encryption technology. This substitution maintains system simplicity from the user's perspective while significantly improving security against phishing attacks through the use of encrypted digital envelope images.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
This approach enhances security by preventing misuse of digital certificates even if personal information is leaked, improves user recognition and intuitiveness, especially on devices with small displays, and increases the efficiency and stability of the digital certificate updating and re-issuing process by minimizing hacking and phishing risks.
Implementation Method 1
combining the digital certificate with the user select image using steganography to create a sealed digital envelope image
Data Source
AI summary
The disclosure relates to a system and method for issuing a digital certificate using an encrypted image, in which a digital certificate is sealed in a digital envelope image so as to protect a digital certificate user from damages caused by hacking, phishing attacks and the like in the course of issuance, update and re-issuance of the digital certificate, and the method for issuing a digital certificate comprises the steps of: storing a user select image for issuing the digital certificate, by a proxy server or a certificate server; and requesting the certificate server to issue the digital certificate and, if the digital certificate is issued, creating a sealed digital envelope image by combining the digital certificate with the user select image and transmitting the digital envelope image to a user terminal.


