Random Number Enhancer for Digital Signature Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Digital signature security is compromised due to the generation of low-quality pseudo random numbers, particularly in ECDSA algorithms, making systems vulnerable to attacks where the same random numbers are used for multiple signatures, allowing attackers to predict the private key and leading to non-repudiation issues.

Innovation Solution

Enhancing the generated random numbers by binding them to the message or a secret seed value, ensuring each signature has a unique r-component, and updating the seed value after each signing operation to prevent predictable random number generation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional random number generation is used in ECDSA, then the system is simpler to implement, but the security is compromised due to low-quality pseudo random numbers

Engineering Contradiction:
ImprovesecurityVSAvoidrandom number generation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a random number enhancer as an intermediary component between the random number generator and the ECDSA signature algorithm. This enhancer takes the generated random number and processes it through additional cryptographic operations (including XOR with message bits and modular exponentiation) to produce an enhanced random number that guarantees uniqueness and unpredictability, thereby resolving the security issue without requiring the entire system to be fundamentally redesigned

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent performs preliminary processing of the random number before it is used in the ECDSA algorithm. The random number is enhanced by combining it with message-specific data and cryptographic operations in advance, ensuring that when the enhanced random number is used for signature generation, it already possesses the necessary quality attributes (uniqueness, unpredictability) to prevent security attacks

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the same random number is reused for multiple signatures, then the random number generation is simpler, but the system becomes vulnerable to attacks where attackers can predict the private key

Engineering Contradiction:
Improvenon-repudiation integrityVSAvoidrandom number generation operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies local quality enhancement by making the random number processing message-specific. Each random number is enhanced using bits from the specific message being signed, ensuring that the enhancement process is tailored to each individual signature operation. This guarantees that even if the base random number generator produces repeated values, the final enhanced random numbers will be unique and unpredictable for each signature

Inventive Principle:
Principle #3Local quality

3Reliability

If a fixed secret seed value is used for PRNG, then the device capabilities are limited but the implementation is simpler, but the random numbers lack requisite quality for security

Engineering Contradiction:
Improverandom number qualityVSAvoidPRNG implementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The random number enhancer serves as a mediator that works with whatever quality of random numbers are produced by the underlying PRNG. Whether the PRNG uses a fixed seed or more complex generation methods, the enhancer processes the output through additional cryptographic operations to guarantee the required quality attributes, thereby resolving the quality issue without forcing complex changes to the PRNG itself

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9300472B2Method and apparatus for improving digital signatures
Publication Date: 2016.03.29 WSOU INVESTMENTS LLC
  • US9300472B2 patent drawing
  • US9300472B2 patent drawing
  • US9300472B2 patent drawing

AI summary

Systems and methods are provided for enchancing pseudo random number generation to thwart various security attacks to a system that relies on digital signature security measures. For example, a random number may be bound to a message that is to be signed using a digital signature. Alternatively, a random number may be bound to a secret seed value, which may be updated subsequent to each signing. Alternatively still, a random number may be bound to both the message to be signed using a digital signature and a secret seed value.