Secure Session Creation Using Multiple Digital Signatures

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure session key encryption systems are vulnerable to compromise due to single-point failures, such as compromised certification authorities or certificates, which can lead to security breaches and man-in-the-middle attacks, and lack flexibility in managing expired or revoked keys.

Innovation Solution

Implementing a system that uses multiple digital signatures and public/private key pairs from multiple certification authorities to create a secure session, allowing seamless replacement of compromised keys and certificates without interrupting service, and employing certification requirements to verify the authenticity of interactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a single certificate and digital signature are used for secure session creation, then the system is simpler to manage, but the system becomes vulnerable to compromise and lacks flexibility when keys are compromised or expire

Engineering Contradiction:
ImproveFlexibility in managing compromised or expired keysVSAvoidSystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the security verification process by implementing multiple independent digital signatures and certification authorities instead of relying on a single certificate. This segmentation allows the system to maintain security functionality even when individual signatures are compromised, as other signatures remain valid and can be used for secure session creation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies preliminary action by pre-configuring multiple digital signatures and certification authorities in advance before any compromise occurs. This preparation ensures that when a key is compromised or expires, the system already has alternative valid signatures ready to use, enabling seamless replacement without service interruption.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If multiple digital signatures and certification authorities are implemented, then security is enhanced and flexibility is improved, but the system complexity increases

Engineering Contradiction:
ImproveSecurity against compromiseVSAvoidSystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements beforehand cushioning by establishing multiple redundant digital signatures and certification authorities in advance, creating a buffer against potential compromises. This cushioning ensures that even if one signature is compromised, the system has pre-prepared alternative signatures to maintain security, effectively cushioning the system against security failures.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Solution Approach 2:

The patent applies parameter changes by dynamically adjusting which digital signatures are active and validated based on their current security status. The system can change parameters such as signature validity, certification authority trust levels, and session creation permissions in response to compromise detection, enabling adaptive security management.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If multiple public keys are used to encrypt session keys, then security layers are increased, but the computational overhead and complexity of key management increase

Engineering Contradiction:
ImproveSecurity verification layersVSAvoidKey management ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies self-service by implementing automated mechanisms for validating multiple digital signatures and managing key replacement. The system automatically verifies signatures against certification authorities, detects compromised keys, and switches to alternative valid signatures without requiring manual intervention, thereby maintaining ease of operation despite multiple keys.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements feedback mechanisms that continuously monitor the security status of digital signatures and certification authorities. This feedback enables the system to detect compromised keys and automatically adjust validation rules, providing real-time security management that simplifies operation while maintaining multiple security layers.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10432595B2Secure session creation system utililizing multiple keys
Publication Date: 2019.10.01 BANK OF AMERICA CORP
  • US10432595B2 patent drawing
  • US10432595B2 patent drawing
  • US10432595B2 patent drawing

AI summary

Systems, computer products, and methods are described herein for an improved secure certificate system that utilizes multiple digital signatures, and in some cases multiple public keys within one or more certificates. The improved secure certificate systems allows for additional security by having multiple certification authorities validate the organization as the owner of the organization application (e.g., website, dedicated application, or the like), as well as allowing for the use of the multiple digital signatures and/or certificates to provide seamless verification of the organization application should one or more of the digital signatures and/or certificates become compromised. Moreover, security may be improved by utilizing multiple public keys to encrypt a session key for use in sending and receiving data.