Electronic Signature Generation via Server-Side Document Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for generating electronic signatures require users to download and temporarily store documents on their mobile devices, which is inconvenient and may compromise security, especially in ensuring the integrity and trustworthiness of cryptographic keys.
Innovation Solution
A method where the user records a document identifier, which is used by the signature server to download and store the document in their personal storage area, allowing the signature to be generated without the need for the user to store the document on their mobile device, utilizing a high-security module for secure key management and 2-factor authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the user downloads and temporarily stores the document on their mobile device, then the signature generation process can be completed, but the security of cryptographic keys and the convenience of the user are compromised
Solution Approach 1:
The patent extracts the document storage function from the mobile device and relocates it to the signature server. The mobile device only retains the minimal necessary components (signature application and communication interface), while the document is downloaded, stored, and signed on the server. This extraction eliminates the security risk of storing cryptographic keys on the mobile device while maintaining the ability to generate signatures.
Solution Approach 2:
The signature server acts as an intermediary between the user's mobile device and the document storage system. The server receives the document identifier from the mobile device, downloads the document, stores it temporarily in a secure area, generates the signature, and returns the result. This intermediary role allows the mobile device to avoid direct document storage while still completing the signature process.
2Adaptability or versatility
If the document is stored in a central location accessible by multiple users, then accessibility is improved, but security and integrity of the document are compromised
Solution Approach 1:
The patent implements local quality by creating a personalized secure storage area on the signature server for each user. The document is downloaded and stored in a user-specific location that is accessible only to that user's signature application. This allows the document to be centrally managed on the server while maintaining local security and integrity for each user.
Solution Approach 2:
The storage system is segmented into user-specific secure areas on the signature server. Each user has their own isolated storage space where documents are downloaded and stored after authentication. This segmentation ensures that even though the server is a central location, each user's documents remain secure and accessible only to them.
3Adaptability or versatility
If the user's mobile device contains all necessary functions for signature generation, then independence is improved, but device complexity and cost increase
Solution Approach 1:
The signature server provides universal functionality by handling document storage, retrieval, and signature generation for all users. Instead of each mobile device needing specialized hardware for document management and secure key storage, the server provides these functions universally to all clients. The mobile device only needs basic communication capabilities to interact with the server.
Solution Approach 2:
The signature server performs self-service by automatically downloading documents, storing them in secure user-specific areas, generating signatures using stored cryptographic keys, and returning results to users. This eliminates the need for complex hardware on mobile devices, as the server handles all complex operations autonomously based on simple requests from the mobile application.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The invention relates to a method for generating an electronic signature of a user (110) for an electronic document (109) stored in an electronic memory (174), a telecommunication terminal (106) of a telecommunication network (148) being assigned to the user (110), said method comprising the following steps: - detecting an identifier (178) of the document (109) by the telecommunication terminal (106), - sending a message (184) from the telecommunication terminal (106) to a signature computer-system (102), the message including the identifier and an identifier of the user (110), - access by the signature-computer-system (102) using the identifier (178) to the document (109) and storing the document (109) on the signature computer system (102) in a memory area of the user (110), - generating the electronic signature. According to the invention, the identifier contains an address, at which the document (109) is stored, and the identifier is an optically detectable code (178) which is detected using an optical interface (182) of the telecommunication terminal (106). The invention further relates to a signature server computer system, to a telecommunication system for generating a signature and to a telecommunication terminal for requesting the generation of a signature.