Digital Signature Terminal Module Switching for Secure Mobile Key Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Computer terminals lack a secure environment for calculating digital signatures due to software and hardware deficiencies, leading to security risks such as private key leakage, especially in mobile devices without USB interfaces.

Innovation Solution

A digital signature terminal comprising a first module with a communication component and a second module for generating digital signatures, where the first module can connect or disconnect from the second module based on user instructions, ensuring secure storage and transmission of digital signatures through a memory and communication components.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If USB keys and smart cards are used for digital signature operations, then security of key storage and data operations is improved, but device complexity increases and usability is limited to devices with USB interfaces

Engineering Contradiction:
Improvesecurity of key storageVSAvoidcompatibility with mobile devices
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a portable digital signature terminal as an intermediary device between the mobile device and the digital signature operation. This terminal includes a processor, memory, and communication interface that can interface with mobile devices without requiring USB interfaces. The terminal performs secure signature operations externally, eliminating the need for USB keys or smart cards while maintaining security and expanding compatibility to all mobile devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If computer terminals are used for digital signature calculations, then ease of operation is improved, but security deteriorates due to software and hardware deficiencies

Engineering Contradiction:
Improveuser interface availabilityVSAvoidsecurity of signature calculation
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the digital signature operation into two separate components: a user interface portion that remains on the mobile device for ease of operation, and a secure calculation portion that is performed on the portable digital signature terminal. This segmentation allows the mobile device to maintain its user-friendly interface while the security-critical signature calculation is performed in a dedicated, secure environment on the terminal, thereby resolving the contradiction between ease of operation and security.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If mobile devices without USB interfaces are used, then adaptability is improved, but ease of operation with digital signature devices deteriorates

Engineering Contradiction:
Improvemobile device compatibilityVSAvoiddigital signature operation accessibility
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The portable digital signature terminal serves as an intermediary that bridges mobile devices without USB interfaces and the digital signature operation. It includes a communication interface that can connect to various mobile devices through different protocols (such as NFC, Bluetooth, or other wireless interfaces), enabling these devices to perform secure signature operations without requiring USB connectivity, thus maintaining both adaptability and ease of operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12041179B2Digital signature terminal and secure communication method
Publication Date: 2024.07.16 SHANGHAI FINANASIA INC
  • US12041179B2 patent drawing
  • US12041179B2 patent drawing
  • US12041179B2 patent drawing

AI summary

A digital signature terminal device and a secure communication method are provided. The digital signature terminal includes a first module and a second module. The first module includes a communication component configured to communicate with outside and includes a central unit. The central unit includes a memory configured to store data received by the communication component. The central unit is configured to receive an operation from a user, and is controlled, in response to the operation from the user, to be simultaneously connected to the second module and disconnected from the communication component or to be simultaneously disconnected from the second module and connected to the communication component. The second module includes a signature component configured to generate a digital signature for the data, and the second module is configured to send the digital signature to the memory.