Multi-Dongle Digital Signature Security via Mutual Presence Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for providing digital multi-signatures lack security as individual signatures can be produced at arbitrary times and compiled later, compromising the reliability of the signing process.

Innovation Solution

A set of dongles where each dongle verifies the presence of at least one other dongle before computing a digital signature, ensuring that multiple secret keys are present and available simultaneously, using zero-knowledge proofs and direct wireless connections to enhance security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If individual signatures are produced at arbitrary different points in time and compiled later, then the signing process is flexible and easy to operate, but the security of the generation process is compromised

Engineering Contradiction:
Improveflexibility of signing processVSAvoidsecurity of generation process
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies preliminary action by requiring all dongles to be present and verify each other's presence before any digital signature computation begins. This pre-condition ensures that the secure signing environment is established in advance, preventing arbitrary separate signing while maintaining operational flexibility through a coordinated workflow.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent merges the presence verification and signature computation steps into a single coordinated process. All dongles must be present and mutually verify before signing occurs, combining what were previously separate operations (individual signing at different times) into a unified secure process that maintains flexibility while improving security.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If multiple dongles are required to be present simultaneously for signing, then the security is improved, but the complexity of the device and operation increases

Engineering Contradiction:
Improvesecurity of signature generationVSAvoidcomplexity of multi-dongle system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements feedback through a presence verification mechanism where each dongle verifies the presence of other dongles in the set before allowing signature computation. This feedback loop ensures that the required number of dongles are present simultaneously, enhancing security while managing complexity through automated verification protocols.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The dongles perform self-verification of each other's presence through cryptographic proofs exchanged between them. This self-service approach reduces the need for external verification infrastructure, managing system complexity while maintaining the security requirement of multiple simultaneous dongles.

Inventive Principle:
Principle #25Self-service

3Reliability

If presence verification of other dongles is required before signing, then the security against adversaries is enhanced, but the time required for the signing process increases

Engineering Contradiction:
Improvesecurity against adversariesVSAvoidtime for signature generation
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The presence verification is performed as a preliminary action before signature computation begins. By establishing the secure multi-dongle environment in advance through mutual verification, the actual signing process can proceed efficiently without repeated verification overhead, balancing security enhancement with time efficiency.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Once the presence verification is successfully completed, the signature computation is rushed through immediately while all dongles remain present. This minimizes the time the system remains in a vulnerable state and reduces overall process time by efficiently completing the signing operation after the security check is satisfied.

Inventive Principle:
Principle #21Skipping (Rushing through)

Data Source

PatentUS11646889B2Dongles and method for providing a digital signature
Publication Date: 2023.05.09 RIDDLE & CODE GMBH
  • US11646889B2 patent drawing
  • US11646889B2 patent drawing
  • US11646889B2 patent drawing

AI summary

Set of two or more dongles for providing a digital signature,wherein each dongle holds a secret key,wherein each dongle is configured to receive a message, to compute a digital signature of the received message using the secret key, and to transmit the computed digital signature,wherein at least one of the dongles is configured to, before computing the digital signature, verify the presence of at least one other dongle belonging to the set, and to compute the digital signature only upon successful verification of the presence of one or more other dongles.