Signature Server Architecture for Thin Client Electronic Signatures
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In information processing systems of the thin client type, generating an electronic signature for document data is challenging due to the restriction on local or network connections, which hinders the retrieval of signature keys and increases security risks during key movement.
Innovation Solution
A signature support system comprising a remote machine, a local machine providing terminal services, a document management server, and a signature server, where the remote machine accesses the document management server to correlate document data with a document ID and the signature server to generate and register a pair of signature and verification keys using biological information, eliminating the need to fetch the signature key from the remote machine.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the remote machine is configured to inhibit local or network connection to external memory and storage devices, then security against information leakage is improved, but the ability to retrieve signature keys is worsened
Solution Approach 1:
The patent introduces a signature server as an intermediary between the remote machine and the signature key storage. The signature server holds the signature keys securely and provides them to the remote machine through controlled communication channels, eliminating the need for direct local storage or physical media connection while maintaining security.
Solution Approach 2:
The patent replaces the mechanical/physical system of storing signature keys on local or network-connected external memory devices with a network-based service architecture. Instead of physically connecting storage devices to the remote machine, the system uses secure network communication with the signature server to provide key access.
2Ease of operation
If the signature key is moved from key generation mechanism to owner by storing in external memory, then key accessibility is improved, but security risks during movement are worsened
Solution Approach 1:
The signature server acts as a secure intermediary that manages signature key distribution. Instead of directly moving keys from the key generation mechanism to the owner's external memory, the system uses the signature server as a controlled intermediate storage and distribution point, reducing security risks during key movement.
Solution Approach 2:
The system creates a controlled copy of the signature key in the signature server's secure environment, allowing the owner to access the key through the server without requiring physical movement of the original key material. This eliminates security risks associated with key transport while maintaining accessibility.
Data Source
AI summary
A signature support system includes a local machine, a remote machine, a document management server, and a signature server. The remote machine uses terminal services of the local machine to access the document management server, and correlates document data with a document ID serving as identification information for the document data, to register the document data in the document management server. Similarly, the signature server is accessed, and caused to generate a pair of a signature key and a verification key, and the keys are correlated with biological information read by a biological information reader, and are registered in the signature server. The signature server generates signature data for the document data that is correlated with the document ID received from a user, and is registered in the document management server, by using the signature key correlated with the biological information read by the biological information reader, and registered in the signature server.


