One-Time Electronic Signature Generation via Hardware Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Electronic signatures face challenges due to insufficient security and complexity, leading to limited success and reduced confidence in their validity and usability, particularly in verifying identities for financial transactions and other secure processes.
Innovation Solution
A system that verifies user identity and device authenticity through physical means, generates unique one-time-use electronic signatures by encrypting hardware identifiers and user information, and processes these signatures within a provider's computerized system to ensure security and simplicity, reducing the need for complex user interactions and third-party verifications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If electronic signature security levels are increased to improve security, then security is improved, but device complexity increases
Solution Approach 1:
The system divides the electronic signature verification process into distinct segments: hardware identification, cryptographic key generation, and signature creation. Each component operates independently but contributes to the overall security, allowing high security without requiring all components to be complex simultaneously
Solution Approach 2:
The system performs preliminary actions by pre-generating cryptographic key pairs and storing them securely in the device before any signature operation. This preliminary setup enables fast, simple signature operations without requiring complex real-time computation, thus achieving high security with operational simplicity
2Reliability
If electronic signature protocols are made more secure through regulations, then security is improved, but ease of operation deteriorates
Solution Approach 1:
The device performs self-service by automatically managing cryptographic operations including key generation, storage, and signature creation without requiring user intervention for complex security protocols. The user simply needs to provide biometric authentication, making the system both secure and easy to operate
Solution Approach 2:
The system introduces an intermediary layer in the form of a trusted provider that manages the cryptographic infrastructure and verifies device authenticity. This intermediary handles the complexity of security protocols while presenting a simple interface to end users, resolving the contradiction between security and ease of operation
3Reliability
If hardware identifiers are verified to ensure device authenticity, then reliability is improved, but device complexity increases
Solution Approach 1:
The system performs preliminary verification of hardware identifiers during device initialization and provider registration. By pre-verifying and storing authentic hardware identifiers, the system enables rapid subsequent verification without repeating complex checks, thus ensuring device authenticity while maintaining operational simplicity
Solution Approach 2:
The system creates and stores a copy of the verified hardware identifiers in a secure database during the provider registration process. This copied information is then used for rapid verification without requiring repeated physical inspection of the device, reducing verification complexity while maintaining reliability
Data Source
AI summary
Physically supplied user information is used to first verify the identity of a user before an app is supplied to a user device. Hardware identifiers of the user device are reviewed to determine whether to allow or deny use of the app on the user device. Once the app is approved, a user request is received by the app which is forwarded to the provider. The provider approves or disapproves of the request based, in part, on whether data in the request matches data maintained by the provider. Such approval/disapproval is provided from the provider to a party responsible for satisfying the user request. In addition, the provider generates a one-time-use electronic signature using data from a sequencer and data from the request, and the one-time-use electronic signature can be supplied to a signature repository and/or added to legal documents.


