Electronic Signature Key Certificate Decoupling Publication Timing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing digital signature technologies, particularly asymmetric cryptography, are vulnerable to quantum computing attacks, and current key management systems result in key wastage and potential hijacking due to time-based publication constraints.
Innovation Solution
A method and apparatus for electronic signature that generates a key certificate based on a hash value and user identifier, records it on a tamper-proof public medium like a blockchain or bulletin board, and publishes the key only after the associated file is already on the medium, ensuring efficient key utilization and preventing hijacking by limiting key usage to a single file.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a key is published at the time of key generation according to time-based publication constraints, then the key management system operates with standardized timing, but the key may be wasted if not used immediately and the system becomes vulnerable to hijacking
Solution Approach 1:
The patent applies preliminary action by publishing the key certificate (containing hash value and user identifier) before publishing the actual key. This allows the system to prepare and validate key information in advance, ensuring the key will be used for a specific file without wasting the key if not immediately needed. The key is only published after the associated file is already on the public medium, preventing key wastage while maintaining security.
Solution Approach 2:
The patent introduces a key certificate as an intermediary between key generation and key publication. The key certificate contains the hash value and user identifier, serving as a preliminary validation layer. This intermediary mechanism allows the system to verify key integrity and intended usage before the actual key is published, preventing hijacking and ensuring the key is tied to a specific file.
2Reliability
If asymmetric cryptography is used for digital signatures, then signature authenticity is ensured through private key security, but the system becomes vulnerable to quantum computing attacks
Solution Approach 1:
The patent converts the potential harm of quantum computing vulnerability into benefit by using hash functions (which are quantum-resistant) to create the key certificate. Instead of relying solely on asymmetric cryptography that may be broken by quantum computers, the system uses the hash value of the private key combined with user identifier in the key certificate, providing a layer of security that remains valid even if the underlying asymmetric cryptography is compromised.
3Productivity
If the key is published immediately after generation, then the key management process is simplified and fast, but the key may be hijacked or wasted if not used for the intended file
Solution Approach 1:
The patent applies preliminary action by first publishing the key certificate (with hash value and user identifier) before publishing the actual key. This preliminary step ensures that when the key is eventually published, it is already associated with a specific file and user, preventing hijacking and wastage while maintaining an efficient workflow.
Solution Approach 2:
The patent implements feedback by using the hash value of the private key in the key certificate. This creates a verifiable link between the key and its intended usage. The system can verify that the published key matches the hash value in the key certificate, providing feedback that ensures key integrity and proper usage without compromising efficiency.
Data Source
Figure 1~2
AI summary
Disclosed are methods and apparatuses for electronic signature. The method for electronic signature comprises obtaining a hash value of a first key created for a user and a user identifier of the user, generating a key certificate of the first key based on the obtained hash value, the user identifier and a current key, recording the key certificate on a public medium, which public medium ensures that information published thereon is not tampered with, signing a file with the first key and recording a resulting file signature and the file on the public medium, and recording the first key on the public medium only after the file is already on the public medium. With the technical solution of the disclosure, a key can be effectively utilized.