Multi-Signature Tokens Across Diverse Keystores for Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing digital signature systems are vulnerable to cyber-attacks, requiring frequent key pair revocation and re-issuance, which is resource-intensive and compromises trust in enterprise systems.

Innovation Solution

A multi-signature token is generated using multiple private keys from keystores with different implementations, providing enhanced security by requiring unauthorized access to multiple distinct security protocols to forge or compromise the token.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional digital signature systems are used, then the system is simple to operate, but the system becomes vulnerable to cyber-attacks and requires frequent key pair revocation and re-issuance

Engineering Contradiction:
Improvesecurity against cyber-attacksVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the digital signature system into multiple independent key pairs, where each key pair is stored in a separate keystore with different security implementations. This segmentation means that compromising one key pair does not compromise the entire system, as other key pairs remain secure. The multi-signature token requires signatures from multiple key pairs, creating a segmented security architecture that resists single-point failures and cyber-attacks.

Inventive Principle:
Principle #1Segmentation

2Reliability

If frequent key pair revocation and re-issuance is performed to maintain security, then security is maintained, but processing resources and time are consumed

Engineering Contradiction:
Improvesecurity maintenanceVSAvoidprocessing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent establishes multiple key pairs in advance, before any security breach occurs. These pre-established key pairs are stored in keystores with different security implementations. When a security breach is detected or suspected, the system can immediately revoke only the compromised key pair(s) while continuing to use the remaining secure key pairs, avoiding the need for frequent complete key pair re-issuance and maintaining processing efficiency.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If multiple private keys from different keystores are used to generate multi-signature token, then security is enhanced against cyber-attacks, but the complexity of key management increases

Engineering Contradiction:
Improvesecurity against key hijackingVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a multi-signature token as an intermediary mechanism that simplifies key management. Instead of manually managing multiple key pairs and their signatures, the system generates a unified multi-signature token that encapsulates signatures from multiple key pairs. This token serves as a mediator that handles the complexity of multi-key coordination, making the system easier to manage while maintaining enhanced security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12388635B2Systems, methods, and media for generating and using a multi-signature token for electronic communication validation
Publication Date: 2025.08.12 FMR CORP
  • US12388635B2 patent drawing
  • US12388635B2 patent drawing
  • US12388635B2 patent drawing

AI summary

Techniques are provided for generating and using a multi-signature token for electronic message validation according to the one or more embodiments as described herein. Specifically, a multi-signature token may be generated that includes at least two digital signatures and information (e.g., user information). Each of the at least two digital signatures may be generated using a private key of at least two key pairs that are maintained on a plurality of keystores that have at least two different implementations (e.g., security protocols). If the at least two digital signatures are valid, the multi-signature token may be determined to be valid and the client request may optionally be performed. If at least one of the at least two digital signatures is invalid, the client request is optionally not performed.