Digital Signature Verification Attack Resilience

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing digital signature verification tools are vulnerable to attacks and suffer from low speed and high false positive errors in identifying malicious files, leading to unauthorized access and data protection issues.

Innovation Solution

A system and method that includes a certificate database and a trusted certificate database to validate digital signatures by checking certificate and file integrity, determining the trustworthiness of certificates, and categorizing files as trusted or non-trusted, with a security assurance tool restricting access to non-trusted files.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If digital signature verification tools are used to identify malicious files, then file security is improved, but the tools become vulnerable to attacks and modifications

Engineering Contradiction:
Improvefile securityVSAvoidvulnerability to attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by detecting attacks on digital signature verification tools before they can compromise file security. The system proactively monitors for modifications or replacements of verification tools and responds to threats before they can successfully execute, thereby maintaining reliability while preventing vulnerability exploitation

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary security mechanism that sits between the digital signature verification process and the files being verified. This intermediary layer detects and responds to attacks on the verification tools themselves, providing an additional protective barrier that maintains file security while shielding the verification process from attacks

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If digital signature verification is performed using system tools, then verification capability is provided, but the speed of verification is low

Engineering Contradiction:
Improveverification capabilityVSAvoidverification speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies preliminary action by pre-loading and caching verification data, including digital signatures and certificate information, before actual verification is needed. This preparation work is performed in advance so that when verification is required, the system can operate faster without compromising the reliability of the verification capability

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces dynamic optimization to the verification process by adapting verification strategies based on detected patterns and cached information. The system dynamically adjusts verification depth and methods based on preliminary analysis, enabling faster verification while maintaining reliability through selective application of full verification protocols

Inventive Principle:
Principle #15Dynamics

3Reliability

If digital signature verification is performed using system tools, then signature checking is provided, but false positive errors are high

Engineering Contradiction:
Improvesignature checkingVSAvoidfalse positive rate
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent applies feedback mechanisms by continuously analyzing verification results and adjusting verification parameters based on observed patterns. The system uses feedback from previous verification outcomes to refine its detection algorithms, reducing false positives while maintaining accurate signature checking through iterative improvement based on accumulated data

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent employs parameter changes by adjusting verification thresholds and criteria based on contextual information and observed file patterns. The system dynamically modifies verification parameters such as trust thresholds and validation strictness levels to optimize the balance between accurate malicious file detection and minimizing false positives

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3674944B1System and method for attack resiliency in verifying digital signatures of files
Publication Date: 2021.12.15 AO KASPERSKY LAB
  • EP3674944B1 patent drawingFigure 1
  • EP3674944B1 patent drawingFigure 2
  • EP3674944B1 patent drawingFigure 3

AI summary

Disclosed are systems and methods for responding to attack on a digital signature check tool by alternatively verifying a digital signature of a file. A check tool can detect an attack on the user computing device against a system tool for verifying digital signatures of files, obtain a file, the file to be analyzed by the at least one system tool for verifying digital signatures of files, determine a DS certificate of a digital signature of the file is valid, determine the digital signature is valid, and if the DS certificate is valid, determine the DS certificate is trusted.