Time-Based Digital Signature for Long-Term Data Integrity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing digital signature systems face challenges in long-term data retention due to cryptographic key expiration, revocation, and changes in algorithms, leading to discontinuity and compromised data integrity.
Innovation Solution
A time-based digital signature system that utilizes trusted time stamp tokens to refresh and re-sign data, ensuring continuity and integrity through a crypto-based solution that adapts to changes in cryptography and digital signature schemas, using methods like ANSI X9.73 and CMS standards.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Duration of action of stationary object
If traditional digital signature systems are used for long-term data retention, then data can be signed and verified initially, but cryptographic keys expire and algorithms change causing loss of data integrity and continuity
Solution Approach 1:
The system performs preliminary actions by creating multiple digital signatures at different time points and storing them in advance. When a key expires or algorithm changes, previously created signatures can be verified, and new signatures can be generated using updated keys, ensuring continuous data integrity without interruption.
Solution Approach 2:
The system changes cryptographic parameters over time by transitioning from old cryptographic keys and algorithms to new ones. Multiple signatures are created with different key pairs, allowing the system to adapt to algorithm changes while maintaining verification capability through the chain of signatures.
2Reliability
If cryptographic keys are revoked or expired, then security is maintained by invalidating old keys, but continuity of data verification is compromised
Solution Approach 1:
The system ensures continuous verification capability by creating an unbroken chain of digital signatures. When keys are revoked or expired, the system generates new signatures that reference previous signatures, maintaining an continuous verification path from the original data through all key transitions to the current state.
Solution Approach 2:
Previous digital signatures act as intermediaries between old and new cryptographic keys. These intermediate signatures bridge the gap when keys are revoked or expired, allowing verification to continue through the chain without direct dependence on the expired or revoked keys.
3Ease of operation
If digital certificates are issued with fixed expiration dates, then certificate management is simplified, but long-term data integrity cannot be maintained through cryptographic transitions
Solution Approach 1:
The system dynamically adapts cryptographic parameters over time rather than using fixed expiration dates. Digital signatures are created with different key pairs at different times, allowing the system to transition between cryptographic algorithms and keys while maintaining verification capability, thus adapting to changing security requirements.
Solution Approach 2:
The digital signature system serves multiple functions: it provides initial authentication, enables verification through key transitions, supports algorithm migrations, and maintains long-term data integrity. The chain of signatures universally handles various cryptographic scenarios beyond simple expiration management.
Data Source
AI summary
A method includes receiving an event, the event associated with a digital signature in a first time-based message comprising a first trusted time stamp token generated using a first hash of digitally signed content from a trusted timing authority; generating a first block on a distributed ledger; generating a second hash of the first trusted time stamp token; receiving a second trusted time stamp token from the trusted timing authority in response to transmitting the second hash to the trusted timing authority; and generating a second block on the distributed ledger; wherein verification of data integrity of the digitally signed content is provided via the first hash of the digitally signed content and second hash of the first trusted time stamp token and via the hash of the first block and a hash of the second block.


