Mobile Terminal QES System Secure Key Extraction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current digital identity authentication methods, such as username/password combinations, OTP devices, credit card codes, and PKI technologies, are vulnerable to security breaches and user experience issues due to the risk of key copying and require complex user management, limiting their effectiveness in ensuring secure and efficient access to network services.

Innovation Solution

A Qualified Electronic Signature (QES) system utilizing a mobile processing terminal with a security memory that stores and protects private keys, allowing secure digital signatures through a secure partition, independent from mobile network operators and services, using asymmetric encryption like RSA, and a PIN code for activation, ensuring high security and mobility.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If username and password are used for digital identification, then access to network services is enabled, but security is compromised due to easy interception and database exposure

Engineering Contradiction:
Improveaccess to network servicesVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the private key from vulnerable storage locations (client file system, database) and places it in a certified secure repository that is protected against extraction and copying. This separation removes the security vulnerability while maintaining authentication functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a certified repository as an intermediary between the user and the authentication system. This repository acts as a secure mediator that holds the private key and provides it for signing operations without exposing it to network interception or database attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If OTP devices are used for enhanced security, then authentication is improved, but the solution remains vulnerable to hacker attacks on centralized databases

Engineering Contradiction:
Improveauthentication securityVSAvoidhacker attack risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the private key from centralized databases and places it in distributed certified repositories located in user devices. This eliminates the single point of failure that hackers could exploit in centralized storage.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments the authentication system so that each user has their own certified repository in their device, rather than relying on a centralized database. This distribution architecture prevents hackers from compromising all users through a single attack point.

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If private keys are stored in client file system for electronic signatures, then digital signing is enabled, but security is compromised due to lack of protection against key extraction

Engineering Contradiction:
Improvedigital signing capabilityVSAvoidprotection against key extraction
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the private key from the unprotected client file system and stores it in a certified repository that is specifically designed and certified to protect against extraction and copying operations.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The certified repository acts as an intermediary that enables digital signing operations while providing certified protection against key extraction. It mediates between the application needing signatures and the private key that must be protected.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If USB tokens or smartcards are used for QES, then high security is achieved, but device complexity and maintenance requirements increase

Engineering Contradiction:
Improvesecurity levelVSAvoidhardware requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes the mobile device serve multiple functions: it acts as both the communication device and the secure repository for the private key. This eliminates the need for separate USB tokens or smartcards while maintaining certified security protection.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges the functionality of the mobile device with the secure repository that previously required separate hardware tokens. The certified repository is integrated into the mobile device, combining communication and security functions in one device.

Inventive Principle:
Principle #5Merging (Combining)

5Reliability

If multiple identifier parameters are required for network services, then security is enhanced, but usability deteriorates due to user burden of remembering credentials

Engineering Contradiction:
ImprovesecurityVSAvoiduser usability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The certified repository automatically manages the private key without requiring user intervention for key management operations. The system handles key protection, extraction control, and signing operations automatically, reducing the user burden while maintaining security.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10158491B2Qualified electronic signature system, method and mobile processing terminal for qualified electronic signature
Publication Date: 2018.12.18 BONSIGNORE ANTONIO SALVATORE PIERO VITTORIO
  • US10158491B2 patent drawing
  • US10158491B2 patent drawing
  • US10158491B2 patent drawing

AI summary

A Qualified Electronic Signature (QES) system configured to exchange data with first processing means of the requester configured to allow a requester to generate requests requesting a qualified electronic signature through said system to a recipient. The system comprises second processing means of the recipient configured to allow the recipient of the request to sign with his qualified electronic signature. Said second processing means comprise a mobile processing terminal for qualified electronic signature of mobile type, adapted to receive request messages at least on a wireless network able to address said messages, through proximity or remote communications, on the basis of at least one terminal identifier of said mobile processing terminal to said user recipient; said second processing means are adapted to send qualified electronic signature at least on a wireless network suitable for proximity or remote communications in order to verify the signature of the recipient through said system and perform the request.