Time Stamp Apparatus Key Compromise Certification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing time stamp systems face issues where compromised time stamps become invalid, preventing long-term certification of document existence, and resistance to private key compromise is not effective for maintaining document authenticity over time.

Innovation Solution

A system and method that includes a time stamp providing apparatus and an obtaining apparatus, where the providing apparatus generates and transmits time stamps using updated private keys, and the obtaining apparatus detects key updates, calculates hash values, and stores time stamps to ensure continuous certification of document existence by updating and moving data accordingly.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Duration of action of stationary object

If time stamps are generated using a single private key for long-term certification, then document existence can be certified over time, but if the private key is compromised, all past time stamps become invalid

Engineering Contradiction:
Improvecertification periodVSAvoidsecurity against key compromise
Core Design Contradiction:
Duration of action of stationary objectVSReliability

Solution Approach 1:

The private key is segmented into multiple key pairs (first private key and second private key) with different validity periods. Time stamps are divided into those generated by the first private key and those generated by the second private key. This segmentation allows the system to limit the impact of key compromise to only the time period associated with the compromised key, while other time stamps remain valid.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically transitions from using a first private key to a second private key when security concerns arise or the first key's validity period expires. The time stamp providing apparatus can switch keys based on detected compromise or predetermined schedules, allowing the certification system to adapt to security requirements while maintaining continuous operation.

Inventive Principle:
Principle #15Dynamics

2Reliability

If private keys are updated frequently to maintain security, then resistance to key compromise is improved, but time stamps generated during transition periods may become invalid

Engineering Contradiction:
Improvesecurity against key compromiseVSAvoidcertification continuity
Core Design Contradiction:
ReliabilityVSDuration of action of stationary object

Solution Approach 1:

The system performs preliminary actions by generating and storing multiple time stamps for the same data using different private keys before a key compromise is detected. When the first private key is compromised, the system can still provide valid time stamps using the second private key that was prepared in advance, ensuring certification continuity without interruption.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system changes the parameter of private key identity from a single static key to multiple dynamic keys. By modifying which private key is used for time stamp generation based on security conditions and time periods, the system maintains both security and certification continuity throughout key transition periods.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If multiple private keys are used to maintain security, then resistance to compromise is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity against key compromiseVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The time stamp providing apparatus is designed with multi-functionality to handle multiple private keys and their corresponding time stamps. The apparatus can generate, store, and validate time stamps from different keys, and can detect key compromise conditions. This universal design allows the same system to perform both long-term certification and security updates without requiring separate systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7890764B2System, apparatus, program and method for obtaining time stamp
Publication Date: 2011.02.15 KK TOSHIBA
  • US7890764B2 patent drawing
  • US7890764B2 patent drawing
  • US7890764B2 patent drawing

AI summary

A time stamp obtaining apparatus for maintaining the certificate of the existence of electronic filing document including: a receiving unit 12 receiving hash value of the document data; a transmitting section 15c transmitting the hash value to time stamp providing apparatus 30a; a storing processing section 15d inserting the time stamp encoded with private key in unupdated data 16b concerning time stamp received since point to which private key is updated and storing; an update detecting section 11 detecting the update of private key; a calculation section 13b calculating hash value for all time stamps included in the unupdated data 16b; a transmitting section 13c transmitting the hash value; a storing processing section 13d moving the unupdated data 16b to past data 16c concerning time stamp received before point to which private key is updated last time when time stamp is received, storing it, and storing the time stamp newly received as new unupdated data 16b; is provided.