Secure Device Digital Signing Malware Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for digitally signing documents using PCs or similar devices are insecure due to the risk of malware manipulation, where users cannot trust what is displayed on an unsecured device, leading to potential alterations in the document being signed.

Innovation Solution

A secure device protected against malicious software, capable of establishing a secure connection via a host like a PC connected to a telecommunication network, allows users to access and verify document contents, execute digital signing commands, and send the signed document securely to a recipient, using interfaces like displays and external output devices for verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a PC or similar device is used for digital signing, then ease of operation is improved, but security and reliability deteriorate due to malware manipulation risks

Engineering Contradiction:
Improveease of operationVSAvoidreliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system separates the signing device into two distinct parts: a secure element (such as a smart card or secure chip) that stores cryptographic keys and performs signing operations, and a host device (PC, smartphone, or tablet) that provides the user interface and document handling. This segmentation ensures that the critical signing function is isolated in a trusted environment, preventing malware on the host from compromising the signing process.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a secure device as an intermediary between the user and the signing process. This intermediary verifies document contents through multiple channels (display, audio output, printer) before allowing signing, acting as a mediator that prevents direct manipulation by malware on the host device while maintaining ease of operation through the host's interface.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If document contents are displayed on the terminal for verification, then ease of operation is improved, but security deteriorates because malware can manipulate the display

Engineering Contradiction:
Improveease of operationVSAvoidmalware manipulation
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by using multiple independent output channels (visual display, audio output, physical printing) to present document contents. Each channel provides the same information in a different form, making it difficult for malware to manipulate all channels simultaneously. The user can verify consistency across these different local outputs to detect tampering.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The secure device acts as an intermediary that controls the verification process. It retrieves document contents from the host, verifies them through multiple output channels, and only allows signing if verification succeeds. This intermediary role prevents direct manipulation by host malware while maintaining user-friendly verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If a secure device is used to prevent malware manipulation, then reliability is improved, but device complexity increases

Engineering Contradiction:
ImprovereliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The secure device is designed to be self-contained and self-sufficient for the critical signing function. It has its own secure storage for cryptographic keys, its own processing unit for verification, and its own interface for user interaction. This self-service capability eliminates the need for complex trust relationships with the host device while maintaining simplicity in the overall system architecture.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The secure device is designed to work with multiple types of host devices (PCs, smartphones, tablets) and multiple output channels (display, audio, printer). This multi-functionality allows a single secure device design to serve various purposes and platforms, reducing overall system complexity despite the added security functionality.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8959354B2Method, secure device, system and computer program product for digitally signing a document
Publication Date: 2015.02.17 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US8959354B2 patent drawing
  • US8959354B2 patent drawing
  • US8959354B2 patent drawing

AI summary

A method for digitally signing a document, a secure device, and a computer program product for implementing the method. The method employs a secure device which is protected against malicious software or malware and is adapted to establish a secure connection to a recipient via a host. The method includes: connecting to a terminal; accessing the contents of a document received by the secure device; instructing at the secure device to communicate the accessed contents to an output device other than the terminal such that the contents can be verified by a user; ascertaining at the secure device a command received to digitally sign the document; executing at the secure device the ascertained command; and instructing to send a digitally signed document to a recipient over a connection established via the host connected to a telecommunication network.