Event Log Tamper Resistance via Digital Signatures
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing event logging systems lack tamper resistance, making it difficult to ensure regulatory compliance without modifying existing workflows or incurring additional costs, as they struggle to verify if event records have been modified.
Innovation Solution
Implementing a tamper resistance mechanism by generating and storing digital signatures for event records, allowing for the validation of records to detect tampering, while preserving the existing format and infrastructure of event logging systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If digital signatures are added to event records to provide tamper resistance, then security and compliance capability are improved, but device complexity and processing overhead increase
Solution Approach 1:
The patent segments the signature management by creating separate signature records that are independently stored and managed. Each signature record contains a signature value, public key, and metadata, allowing the system to verify event records without requiring complex integrated signature management. This segmentation reduces system complexity while maintaining tamper resistance.
Solution Approach 2:
The patent introduces signature records as intermediary objects that mediate between event records and verification processes. These signature records contain the necessary cryptographic information (signatures, public keys) to verify event record authenticity without requiring the verification system to directly handle complex cryptographic operations on the original event data, thus simplifying the overall system architecture.
2Reliability
If multiple signatures are stored for each event record to enhance verification capability, then compliance and security are improved, but storage requirements and processing time increase
Solution Approach 1:
The patent creates signature records that are copies containing essential verification information (signatures, public keys, metadata) separate from the original event records. This copying approach allows multiple signatures to be stored and managed efficiently without duplicating the entire event record data, reducing storage requirements while maintaining verification capability.
Solution Approach 2:
Instead of storing multiple signatures directly within each event record, the patent inverts the approach by creating separate signature records that reference event records. This inversion allows the system to manage multiple signatures efficiently through a dedicated signature management structure, reducing the storage overhead on event records themselves while maintaining the ability to verify multiple signatures.
3Reliability
If signature validation is performed on existing event logs, then tamper detection capability is improved, but processing time and computational resources increase
Solution Approach 1:
The patent performs preliminary actions by pre-computing and storing signature values, public keys, and metadata in separate signature records at the time of event record creation. This preliminary preparation of verification data eliminates the need for complex real-time cryptographic computations during validation, significantly reducing validation time while maintaining robust tamper detection capability.
Solution Approach 2:
The patent extracts the computationally intensive signature verification logic into separate signature records that contain pre-computed signature values and public keys. This extraction allows the validation process to simply compare event record hashes against pre-stored signature values without performing complex cryptographic operations, dramatically reducing processing time and computational resource requirements.
Data Source
AI summary
Embodiments are described for generating, by the processor, a first event record in response to an event being performed by the computer and generating, by the processor, a first tamper resistance record in response to the first event record being generated. The first tamper resistance record includes a first signature is created based at least in part on the first event record and a second signature is created based at least in part on the first event record. Aspects also includes validating the first event record based on the first signature and the second signature in the first tamper resistance record in response to a request to detect tampering of the first event record.


