Secure Cryptographic Environment Binding PIN to Digital Signatures

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current strong authentication implementations for online transactions face challenges in providing secure, user-friendly, and privacy-friendly solutions that meet the requirements of high assurance levels, particularly in resisting attackers with moderate to high attack potential, while also supporting remote electronic signatures and timely revocation.

Innovation Solution

The proposed solution involves a centralized authentication model that utilizes a Secure Cryptographic Environment (SCE) on mobile devices to securely generate and store cryptographic keys, combined with Split-ECDSA and PIN-Binder mechanisms to strongly bind the user PIN to digital signatures, ensuring secure authentication and signature generation without exporting private keys, and allows for flexible implementation on mobile applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a centralized authentication model with SCE and Split-ECDSA is used, then security against moderate to high attack potential is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication system into multiple components: a Secure Cryptographic Environment (SCE) for key generation and storage, a Split-ECDSA mechanism that divides signature generation between the SCE and application layer, and a centralized authentication provider. This segmentation allows each component to specialize in specific security functions while maintaining overall system security without requiring the entire system to be complex.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a centralized authentication provider as an intermediary between users and service providers. This intermediary handles the complex authentication logic, key management, and signature verification, thereby simplifying the implementation for individual service providers while maintaining high security standards through the SCE and Split-ECDSA mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If strong authentication binding possession and knowledge factors is implemented, then resistance to attackers is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveresistance to attackersVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent merges the possession factor (secure storage in SCE) and knowledge factor (PIN or password) into a unified authentication mechanism. The Split-ECDSA signature generation process combines these factors such that both are required simultaneously, creating strong authentication binding while providing a seamless user experience where the user simply enters their PIN and the system handles the rest of the complex cryptographic operations automatically.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If private keys are not exported from SCE, then security is improved, but adaptability deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidadaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent replaces the traditional mechanical approach of key export and import with a cryptographic substitution mechanism. Instead of exporting private keys, the system uses the Split-ECDSA approach where the SCE provides cryptographic proofs and signature components without revealing the private key. This substitution maintains security while achieving adaptability through the standardized interface that allows different applications to utilize the secured keys without direct access.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Ease of manufacture

If centralized authentication is used, then ease of implementation for service providers is improved, but loss of information increases

Engineering Contradiction:
Improveease of implementationVSAvoidprivacy
Core Design Contradiction:
Ease of manufactureVSLoss of information

Solution Approach 1:

The patent extracts personally identifiable information (PII) from the authentication process. The centralized authentication provider handles user identification and registration, but the actual authentication and signature verification can be performed without exposing PII to service providers. The SCE and Split-ECDSA mechanism allow verification of authentication status and signature validity without revealing underlying personal information, thereby reducing information loss while maintaining ease of implementation.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP4208982B1Method for electronic signing and authenticaton strongly linked to the authenticator factors possession and knowledge
Publication Date: 2024.10.02 WELLET BV
  • EP4208982B1 patent drawingFigure 1
  • EP4208982B1 patent drawingFigure 2
  • EP4208982B1 patent drawingFigure 3

AI summary

The invention consists of a method for a user to generate digital signatures based on a device, e.g. a smart phone, and secret knowledge of the user (Personal Identification Number or PIN) that are completely under control of the user. Characteristic of the invention is that it is based on a software application (A-APP) in the device that innovatively uses a secure part of the device (Secure Cryptographic Environment or SCE) to bind the signature to both the possession of the SCE and the secret knowledge of the user to the digital signature in such a way that the resulting digital signatures complies with regular digital signatures standards. In effect it is like the SCE has implemented a PIN that only allows access to the digital signature generation function after the user has correctly entered that whereas in reality the SCE is completely oblivious of the PIN. Part of the invention is letting a certificate issuer place the generated public keys in digital certificates together with user information. The invention also entails various applications of the method and system including the setup of a centralized authentication provider providing user authentication and the direct use of the setup of service providers to authenticate users and providing additional services including remote signing. By placing a separated, trusted environment within the authentication provider or certificate issuer the invention caters for privacy friendly authentication mechanisms.