One-Step Digital Signature Trust for Self-Signed Certificates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current software applications poorly handle digitally signed documents with self-signed certificates or those not rooted in a Certificate Authority, leading to unknown signature status issues, which undermine trust in the signer and the software providing the document.

Innovation Solution

A method and apparatus for one-step signature trust that validates a document's integrity and offers recipients the option to establish trust in digital certificates, adding them to their list of trusted certificates if chosen, thereby resolving trust issues related to self-signed or untrusted certificates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If digital signatures use self-signed certificates or certificates not rooted in a Certificate Authority, then the signer has flexibility and control over their own identity verification, but the recipient cannot verify the signature status, leading to unknown signature status and loss of trust

Engineering Contradiction:
Improveflexibility in certificate issuanceVSAvoidsignature verification trust
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a software application as an intermediary that mediates between the self-signed certificate and the recipient. The application acts as a trusted mediator that can verify and validate self-signed certificates, presenting them to the recipient with explicit trust indicators. This resolves the contradiction by providing a intermediary layer that bridges the gap between flexible self-signed certificates and reliable verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the trust verification process into distinct components: certificate validation, trust status determination, and presentation to the recipient. By separating these functions, the system can handle self-signed certificates differently from CA-signed certificates, applying appropriate verification methods to each segment while maintaining overall system reliability.

Inventive Principle:
Principle #1Segmentation

2Loss of information

If current software applications present error messages for untrusted certificates, then the recipient is informed of the trust issue, but the recipient receives little or no guidance on how to resolve it, requiring manual intervention

Engineering Contradiction:
Improvetrust status informationVSAvoidtrust resolution process
Core Design Contradiction:
Loss of informationVSEase of operation

Solution Approach 1:

The patent implements self-service by enabling the recipient to directly interact with the software application to establish trust in self-signed certificates. The application provides a user-friendly interface where recipients can review certificate details and explicitly trust them with a single action. This eliminates the need for manual intervention or complex resolution processes, allowing users to self-resolve trust issues easily.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent incorporates feedback mechanisms that provide the recipient with clear information about the trust status and the actions taken. When a recipient trusts a self-signed certificate, the system provides immediate feedback confirming the trust establishment and updating the signature status. This feedback loop guides the recipient through the trust resolution process without requiring external assistance.

Inventive Principle:
Principle #23Feedback

3Reliability

If digital certificates are not trusted on the recipient's machine, then security is maintained by not accepting unverified signatures, but the legitimate use of self-signed documents is prevented, undermining trust in the signer

Engineering Contradiction:
Improvesecurity verificationVSAvoidacceptance of self-signed documents
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic trust management where the trust status of self-signed certificates can change based on user actions. Initially, self-signed certificates are treated with caution (security-focused), but when a recipient explicitly trusts them, the system dynamically adjusts to accept these certificates. This dynamic approach allows the system to adapt between security verification and acceptance of self-signed documents based on real-time user decisions.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the trust parameter for self-signed certificates from a fixed default state to a flexible state that can be modified by user input. The system maintains a parameter that tracks whether a self-signed certificate has been trusted, allowing it to switch between verification modes. This parameter change enables the system to both maintain security standards and accept legitimate self-signed documents when appropriate.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8914639B2Method and apparatus for one-step signature trust for digitally-signed documents
Publication Date: 2014.12.16 ADOBE INC
  • US8914639B2 patent drawing
  • US8914639B2 patent drawing
  • US8914639B2 patent drawing

AI summary

A computer implemented method and apparatus for one-step signature trust of digitally signed documents comprising determining whether a digital signature is otherwise valid except for a lack of trust in a digital certificate; offering a recipient an option to establish trust in the digital certificate; and adding the digital certificate to a list of the recipient's trusted digital certificates when recipient opts to establish trust.