Electronic Signature Key Certificate Decoupling Publication Timing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing digital signature technologies, particularly asymmetric cryptography, are vulnerable to quantum computing attacks, and current key management systems result in key wastage and potential hijacking due to time-based publication constraints.

Innovation Solution

A method and apparatus for electronic signature that generates a key certificate based on a hash value and user identifier, records it on a tamper-proof public medium like a blockchain or bulletin board, and publishes the key only after the associated file is already on the medium, ensuring efficient key utilization and preventing hijacking by limiting key usage to a single file.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a key is published at the time of key generation according to time-based publication constraints, then the key management system operates with standardized timing, but the key may be wasted if not used immediately and the system becomes vulnerable to hijacking

Engineering Contradiction:
Improvekey securityVSAvoidkey wastage
Core Design Contradiction:
ReliabilityVSLoss of substance

Solution Approach 1:

The patent applies preliminary action by publishing the key certificate (containing hash value and user identifier) before publishing the actual key. This allows the system to prepare and validate key information in advance, ensuring the key will be used for a specific file without wasting the key if not immediately needed. The key is only published after the associated file is already on the public medium, preventing key wastage while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a key certificate as an intermediary between key generation and key publication. The key certificate contains the hash value and user identifier, serving as a preliminary validation layer. This intermediary mechanism allows the system to verify key integrity and intended usage before the actual key is published, preventing hijacking and ensuring the key is tied to a specific file.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If asymmetric cryptography is used for digital signatures, then signature authenticity is ensured through private key security, but the system becomes vulnerable to quantum computing attacks

Engineering Contradiction:
Improvesignature authenticityVSAvoidquantum computing vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent converts the potential harm of quantum computing vulnerability into benefit by using hash functions (which are quantum-resistant) to create the key certificate. Instead of relying solely on asymmetric cryptography that may be broken by quantum computers, the system uses the hash value of the private key combined with user identifier in the key certificate, providing a layer of security that remains valid even if the underlying asymmetric cryptography is compromised.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

3Productivity

If the key is published immediately after generation, then the key management process is simplified and fast, but the key may be hijacked or wasted if not used for the intended file

Engineering Contradiction:
Improvekey management efficiencyVSAvoidkey usage security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies preliminary action by first publishing the key certificate (with hash value and user identifier) before publishing the actual key. This preliminary step ensures that when the key is eventually published, it is already associated with a specific file and user, preventing hijacking and wastage while maintaining an efficient workflow.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback by using the hash value of the private key in the key certificate. This creates a verifiable link between the key and its intended usage. The system can verify that the published key matches the hash value in the key certificate, providing feedback that ensures key integrity and proper usage without compromising efficiency.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3700122B1Method and device for electronic signature
Publication Date: 2023.09.06 CROSBIL LTD
  • EP3700122B1 patent drawingFigure 1~2

AI summary

Disclosed are methods and apparatuses for electronic signature. The method for electronic signature comprises obtaining a hash value of a first key created for a user and a user identifier of the user, generating a key certificate of the first key based on the obtained hash value, the user identifier and a current key, recording the key certificate on a public medium, which public medium ensures that information published thereon is not tampered with, signing a file with the first key and recording a resulting file signature and the file on the public medium, and recording the first key on the public medium only after the file is already on the public medium. With the technical solution of the disclosure, a key can be effectively utilized.