Remote Electronic Signature System Using Multi-Unit Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing card-based electronic signature methods are cumbersome, costly, and time-consuming to implement, especially for large-scale adoption in electronic legal transactions, as they require individual signature cards and card readers, which is inefficient and expensive.

Innovation Solution

A method for securely executing a remote signature on an electronic document using a network-based system where multiple network units communicate through test messages, each signed by the corresponding unit, ensuring authentication and integrity verification, eliminating the need for physical signature cards or readers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If card-based electronic signature methods are used, then security is improved, but device complexity and cost increase

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces physical signature cards with a software-based solution where the private key is stored in a protected memory area of a server. Instead of requiring users to possess physical cards, the system creates a digital copy of the signing capability that can be accessed remotely through authenticated connections, eliminating the need for card readers and physical media while maintaining security through cryptographic protection.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent substitutes the mechanical card-based system with an electronic/network-based system. The physical interaction between card and card reader is replaced by digital communication protocols over a network. The private key remains protected through cryptographic mechanisms rather than physical security measures, and authentication is performed through digital certificates and encrypted communications instead of physical card insertion.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 3:

The patent creates a universal signing system where a single server infrastructure can serve multiple users and multiple types of electronic documents. The server-based architecture allows the same system to handle different users, different document types, and different signing scenarios without requiring separate physical infrastructure for each user, thereby reducing overall device complexity and cost while maintaining security through centralized key management.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If individual signature cards and card readers are provided for each user, then security is improved, but productivity and ease of operation deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoidproductivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent merges the signing capability from individual user cards into a centralized server system. Multiple users share a common infrastructure where the private key is stored and managed centrally rather than distributed across many individual cards. This consolidation eliminates the need for each user to have their own card and reader, streamlining the process and improving productivity while maintaining security through centralized cryptographic protection and access control.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent enables users to perform electronic signatures autonomously through a web-based interface without requiring physical card insertion or specialized hardware. Users can initiate signing operations, upload documents, and complete signatures through standard internet browsers, making the process as convenient as other online activities. The system handles authentication and key management automatically in the background, improving ease of operation while maintaining security.

Inventive Principle:
Principle #25Self-service

3Reliability

If card-based signature methods are implemented, then security is improved, but loss of time and cost increase

Engineering Contradiction:
ImprovesecurityVSAvoidloss of time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary authentication and setup actions during initial system configuration. User identities are verified and digital certificates are issued before actual signing operations begin. The private key is pre-configured in the protected memory area of the server with appropriate access controls. This preliminary setup eliminates the need for time-consuming physical card distribution and installation processes for each user, reducing overall implementation time while maintaining security through pre-established cryptographic credentials.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces the time-consuming physical card distribution process with rapid digital provisioning. Instead of manually distributing physical signature cards to each user, the system generates and delivers digital credentials through automated processes over the network. Users can obtain their signing capabilities instantly through online registration and authentication, eliminating the time required for physical card manufacturing, distribution, and installation while maintaining equivalent security through cryptographic protection.

Inventive Principle:
Principle #26Copying

Data Source

PatentEP3767513B1Method for secure execution of a remote signature, and security system
Publication Date: 2021.09.15 BANK VERLAG
  • EP3767513B1 patent drawingFigure 1
  • EP3767513B1 patent drawingFigure 2
  • EP3767513B1 patent drawingFigure 3~4

AI summary

The invention relates to a method for securely performing a remote signature of an electronic document. In the method according to the invention, the user logs in to a first network unit. The user then selects an electronic document to be signed. If the user's identity could be confirmed during login, the first network unit generates a first verification message. This first verification message is signed by the network unit and then transmitted to a second network unit. The user must then authenticate themselves to the second network unit. The second network unit verifies the user's authenticity and the first verification message. If this verification is successful, the second network unit generates a second verification message and signs it. The second verification message is then transmitted from the second network unit to the third network unit.The third network unit verifies the second verification message and then signs the previously selected electronic document, provided the verification of the second verification message was successful.