Electronic Signature Security System Using Cryptographic Hash Binding
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing electronic signature security systems are vulnerable to hacking and unauthorized access, particularly due to the display of transaction records and reliance on location and sequential identifiers, which can be exploited to break encryption codes.
Innovation Solution
A system that captures electronic signatures on a peripheral device separate from the main processor, binding signature and record data together at the point-of-use with a unique key, using a shared secret not transmitted over the medium, and employing a hashing algorithm to enhance security and compliance with regulatory requirements.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If transaction records and sequential identifiers are displayed and transmitted, then ease of operation and verification is improved, but security against hacking and unauthorized access deteriorates
Solution Approach 1:
The patent extracts the harmful sequential identifier from the transaction record and replaces it with a cryptographic hash value. This hash is derived from the transaction data and signature but does not reveal the original sequential identifier, thus maintaining verification capability while eliminating the security vulnerability of exposed sequential numbering
Solution Approach 2:
The patent transforms the transaction record parameters by applying cryptographic hashing to the signature and transaction data. This changes the representation from plain text sequential identifiers to hashed values that are computationally infeasible to reverse, thereby improving security while preserving the ability to verify transaction integrity
2Ease of operation
If signature data is transmitted over the medium, then ease of operation is improved, but security against interception and hacking deteriorates
Solution Approach 1:
The patent applies preliminary cryptographic hashing to the signature and transaction data before transmission. By pre-processing the data with hash functions, the system prepares the information in a secure format that maintains operational ease while protecting against interception and hacking during transmission
Solution Approach 2:
The cryptographic hash function acts as an intermediary between the original signature data and the transmitted representation. This intermediary transforms the sensitive signature into a hashed form that can be transmitted safely without exposing the original data, yet still allows verification of the original signature's integrity
3Ease of manufacture
If location identifiers and sequential numbers are used in encryption codes, then ease of manufacture and implementation is improved, but reliability and security of the encryption deteriorates
Solution Approach 1:
The patent changes the encryption parameters from using plain text location identifiers and sequential numbers to using cryptographic hash values derived from the transaction data. This parameter change maintains implementation simplicity while dramatically improving encryption reliability by making the codes computationally infeasible to break through traditional methods
Data Source
AI summary
One embodiment of the invention enhances the security of electronic signatures during transmission. A peripheral device, which may be located remotely and separate from a host processing system, captures the signature. The peripheral device then binds the signature to the particular transaction record and transmits it to the host processing system. The host processing system validates or confirms the received signature before accepting the transaction. Binding the signature and record data together at the point-of-use reduces the likelihood that someone may be able to hack into the transmission medium, encrypted or not, and obtain the raw signature data. By binding or associating the signature and transaction record data together at the point-of-use, each transaction has a unique key, further foiling attempts at hacking. In various implementations, rather than associating the whole signature with the transaction record data, signature sample points or segments are encrypted with transaction record data.


