Mobile Phone Secure Partition for Qualified Electronic Signatures

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current digital identity authentication methods, such as username/password combinations, OTP devices, credit card codes, and PKI with unprotected private keys, are vulnerable to security threats like interception and copying, limiting their effectiveness in ensuring secure access to network services and electronic payments.

Innovation Solution

A qualified electronic signature system utilizing a mobile phone with a security memory that stores a private key independently of the SIM card, enabling secure digital signatures through a secure partition protected by an activation code, ensuring the private key is not copied and maintaining high security levels compliant with national and international standards.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If username and password are used for digital identification, then access to network services is enabled, but security is compromised due to ease of interception and copying

Engineering Contradiction:
Improveaccess to network servicesVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the private key from unprotected storage locations and places it into a dedicated security memory component (SE/TEE) that is physically isolated from the main system bus and memory. This extraction and relocation of the sensitive cryptographic material into a protected enclave resolves the security vulnerability of username/password systems while maintaining ease of operation.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a security memory component as an intermediary between the processor and the private key. This mediator component provides a trusted interface that allows cryptographic operations to occur without exposing the private key to potential interception, thus resolving the contradiction between operational ease and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If OTP devices are used for digital identification, then security is improved compared to username/password, but the device information can still be replicated through hacker attacks

Engineering Contradiction:
ImprovesecurityVSAvoidinformation copying
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the private key from the main system memory and relocates it to a dedicated security memory component that is physically separated and protected from hacking attempts. This extraction prevents information copying attacks while maintaining the security benefits of OTP devices.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies local quality by creating a specialized security memory component with unique protective characteristics (physical isolation, protected interfaces, secure cryptographic operations) that are not present in standard memory systems. This localized security enhancement prevents information copying while maintaining overall system functionality.

Inventive Principle:
Principle #3Local quality

3Ease of operation

If private keys are stored in unprotected areas such as client file system, then digital signatures can be generated, but the private key is vulnerable to extraction and copying

Engineering Contradiction:
Improvedigital signature generationVSAvoidprivate key protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the private key from unprotected storage locations (file system, database) and relocates it to a dedicated security memory component. This extraction enables digital signature generation to continue while simultaneously providing the private key protection that was previously absent.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a security memory component as an intermediary that handles all private key operations. This mediator enables digital signature generation while protecting the private key from extraction and copying, resolving the contradiction between operational ease and key protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If USB tokens or smartcards are used for qualified electronic signature, then high security level is achieved, but device complexity and maintenance requirements increase

Engineering Contradiction:
Improvesecurity levelVSAvoiddevice installation and maintenance
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the security memory component with the mobile device's existing architecture, integrating cryptographic functionality into the device itself rather than requiring separate USB tokens or smartcards. This merging achieves high security levels while reducing device complexity and eliminating maintenance requirements for external hardware.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a universal security memory component that provides qualified electronic signature capabilities within the mobile device itself, eliminating the need for device-specific external tokens or cards. This multi-functional approach achieves high security while reducing complexity by consolidating functionality into a single integrated component.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2582115B8A qualified electronic signature system, associated method and mobile phone device for a qualified electronic signature
Publication Date: 2016.03.16 BONSIGNORE ANTONIO SALVATORE PIERO VITTORIO

AI summary

A qualified electronic signature system configured to exchange data with first processing means (100; 303; 210) of the requester configured to allow a requester (300, 400) to generate requests (305) requesting a qualified electronic signature through said system to a recipient (365; 400), said system comprising second processing means (210) of the recipient (365; 400) configured to allow the recipient (365; 400) of the request (305) to sign his/her qualified electronic signature, said second processing means (210) comprising a mobile phone device for qualified electronic signature of mobile type, adapted to exchange text-based communications (340) on mobile telecommunications networks on the basis of an identifier of the recipient subscribed to the mobile telephone service comprised in a Subscriber Identity Module (120) with which he/she is associated, According to the invention, said second processing means (210) comprise means (220) for making the qualified electronic signature through a security memory (200) comprising a secure partition in which at least one private key (201) is stored, said qualified electronic signature system also comprising a dedicated server network (302, 310, 315) to place said first processing means (100; 303; 210) of the requester in communication with said second processing means (210) of the recipient, comprising at least one front-end server (310) configured to receive and validate the request (305) requesting qualified electronic signature sent by said first processing means (100; 303; 210), one or more applicative servers (315) configured to send said text-based communications on the mobile telecommunication network (340) to said recipient (365; 400) said front-end server (310) being configured to send said validated request (308) to a respective applicative server (315) on the basis of the identifier of the recipient (365; 400) or his/her telephone number, on the basis of the type of request (305) said applicative server (315) being configured to forward this request (305) as text-based communication on the mobile telecommunication network (340) through said identifier of the subscriber of the mobile telephone service in said Subscriber Identity Module (120) to said second processing means (210), said second processing means (210) also being configured (220), in particular through a dedicated software application, to employ said private key (201) in said security memory (200) and sign an electronic signature through encryption of the hash of said text-based communication on the mobile telecommunication network (340) or parts thereof by means of said private key (201).