Mobile Phone Secure Partition for Qualified Electronic Signatures
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current digital identity authentication methods, such as username/password combinations, OTP devices, credit card codes, and PKI with unprotected private keys, are vulnerable to security threats like interception and copying, limiting their effectiveness in ensuring secure access to network services and electronic payments.
Innovation Solution
A qualified electronic signature system utilizing a mobile phone with a security memory that stores a private key independently of the SIM card, enabling secure digital signatures through a secure partition protected by an activation code, ensuring the private key is not copied and maintaining high security levels compliant with national and international standards.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If username and password are used for digital identification, then access to network services is enabled, but security is compromised due to ease of interception and copying
Solution Approach 1:
The patent extracts the private key from unprotected storage locations and places it into a dedicated security memory component (SE/TEE) that is physically isolated from the main system bus and memory. This extraction and relocation of the sensitive cryptographic material into a protected enclave resolves the security vulnerability of username/password systems while maintaining ease of operation.
Solution Approach 2:
The patent introduces a security memory component as an intermediary between the processor and the private key. This mediator component provides a trusted interface that allows cryptographic operations to occur without exposing the private key to potential interception, thus resolving the contradiction between operational ease and security.
2Reliability
If OTP devices are used for digital identification, then security is improved compared to username/password, but the device information can still be replicated through hacker attacks
Solution Approach 1:
The patent extracts the private key from the main system memory and relocates it to a dedicated security memory component that is physically separated and protected from hacking attempts. This extraction prevents information copying attacks while maintaining the security benefits of OTP devices.
Solution Approach 2:
The patent applies local quality by creating a specialized security memory component with unique protective characteristics (physical isolation, protected interfaces, secure cryptographic operations) that are not present in standard memory systems. This localized security enhancement prevents information copying while maintaining overall system functionality.
3Ease of operation
If private keys are stored in unprotected areas such as client file system, then digital signatures can be generated, but the private key is vulnerable to extraction and copying
Solution Approach 1:
The patent extracts the private key from unprotected storage locations (file system, database) and relocates it to a dedicated security memory component. This extraction enables digital signature generation to continue while simultaneously providing the private key protection that was previously absent.
Solution Approach 2:
The patent introduces a security memory component as an intermediary that handles all private key operations. This mediator enables digital signature generation while protecting the private key from extraction and copying, resolving the contradiction between operational ease and key protection.
4Reliability
If USB tokens or smartcards are used for qualified electronic signature, then high security level is achieved, but device complexity and maintenance requirements increase
Solution Approach 1:
The patent merges the security memory component with the mobile device's existing architecture, integrating cryptographic functionality into the device itself rather than requiring separate USB tokens or smartcards. This merging achieves high security levels while reducing device complexity and eliminating maintenance requirements for external hardware.
Solution Approach 2:
The patent creates a universal security memory component that provides qualified electronic signature capabilities within the mobile device itself, eliminating the need for device-specific external tokens or cards. This multi-functional approach achieves high security while reducing complexity by consolidating functionality into a single integrated component.
Data Source
AI summary
A qualified electronic signature system configured to exchange data with first processing means (100; 303; 210) of the requester configured to allow a requester (300, 400) to generate requests (305) requesting a qualified electronic signature through said system to a recipient (365; 400), said system comprising second processing means (210) of the recipient (365; 400) configured to allow the recipient (365; 400) of the request (305) to sign his/her qualified electronic signature, said second processing means (210) comprising a mobile phone device for qualified electronic signature of mobile type, adapted to exchange text-based communications (340) on mobile telecommunications networks on the basis of an identifier of the recipient subscribed to the mobile telephone service comprised in a Subscriber Identity Module (120) with which he/she is associated, According to the invention, said second processing means (210) comprise means (220) for making the qualified electronic signature through a security memory (200) comprising a secure partition in which at least one private key (201) is stored, said qualified electronic signature system also comprising a dedicated server network (302, 310, 315) to place said first processing means (100; 303; 210) of the requester in communication with said second processing means (210) of the recipient, comprising at least one front-end server (310) configured to receive and validate the request (305) requesting qualified electronic signature sent by said first processing means (100; 303; 210), one or more applicative servers (315) configured to send said text-based communications on the mobile telecommunication network (340) to said recipient (365; 400) said front-end server (310) being configured to send said validated request (308) to a respective applicative server (315) on the basis of the identifier of the recipient (365; 400) or his/her telephone number, on the basis of the type of request (305) said applicative server (315) being configured to forward this request (305) as text-based communication on the mobile telecommunication network (340) through said identifier of the subscriber of the mobile telephone service in said Subscriber Identity Module (120) to said second processing means (210), said second processing means (210) also being configured (220), in particular through a dedicated software application, to employ said private key (201) in said security memory (200) and sign an electronic signature through encryption of the hash of said text-based communication on the mobile telecommunication network (340) or parts thereof by means of said private key (201).