Secure Device Digital Signing Malware Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for digitally signing documents using PCs or similar devices are insecure due to the risk of malware manipulation, where users cannot trust what is displayed on an unsecured device, leading to potential alterations in the document being signed.
Innovation Solution
A secure device protected against malicious software, capable of establishing a secure connection via a host like a PC connected to a telecommunication network, allows users to access and verify document contents, execute digital signing commands, and send the signed document securely to a recipient, using interfaces like displays and external output devices for verification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a PC or similar device is used for digital signing, then ease of operation is improved, but security and reliability deteriorate due to malware manipulation risks
Solution Approach 1:
The system separates the signing device into two distinct parts: a secure element (such as a smart card or secure chip) that stores cryptographic keys and performs signing operations, and a host device (PC, smartphone, or tablet) that provides the user interface and document handling. This segmentation ensures that the critical signing function is isolated in a trusted environment, preventing malware on the host from compromising the signing process.
Solution Approach 2:
The patent introduces a secure device as an intermediary between the user and the signing process. This intermediary verifies document contents through multiple channels (display, audio output, printer) before allowing signing, acting as a mediator that prevents direct manipulation by malware on the host device while maintaining ease of operation through the host's interface.
2Ease of operation
If document contents are displayed on the terminal for verification, then ease of operation is improved, but security deteriorates because malware can manipulate the display
Solution Approach 1:
The patent applies local quality by using multiple independent output channels (visual display, audio output, physical printing) to present document contents. Each channel provides the same information in a different form, making it difficult for malware to manipulate all channels simultaneously. The user can verify consistency across these different local outputs to detect tampering.
Solution Approach 2:
The secure device acts as an intermediary that controls the verification process. It retrieves document contents from the host, verifies them through multiple output channels, and only allows signing if verification succeeds. This intermediary role prevents direct manipulation by host malware while maintaining user-friendly verification.
3Reliability
If a secure device is used to prevent malware manipulation, then reliability is improved, but device complexity increases
Solution Approach 1:
The secure device is designed to be self-contained and self-sufficient for the critical signing function. It has its own secure storage for cryptographic keys, its own processing unit for verification, and its own interface for user interaction. This self-service capability eliminates the need for complex trust relationships with the host device while maintaining simplicity in the overall system architecture.
Solution Approach 2:
The secure device is designed to work with multiple types of host devices (PCs, smartphones, tablets) and multiple output channels (display, audio, printer). This multi-functionality allows a single secure device design to serve various purposes and platforms, reducing overall system complexity despite the added security functionality.
Data Source
AI summary
A method for digitally signing a document, a secure device, and a computer program product for implementing the method. The method employs a secure device which is protected against malicious software or malware and is adapted to establish a secure connection to a recipient via a host. The method includes: connecting to a terminal; accessing the contents of a document received by the secure device; instructing at the secure device to communicate the accessed contents to an output device other than the terminal such that the contents can be verified by a user; ascertaining at the secure device a command received to digitally sign the document; executing at the secure device the ascertained command; and instructing to send a digitally signed document to a recipient over a connection established via the host connected to a telecommunication network.


