Trusted Third Party Digital Timestamping for Service Access Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing mechanisms for verifying services accessed in communications systems, particularly those using host servers with virtual machines, are inadequate as they can be replicated, leading to challenges in authenticating service access.
Innovation Solution
A method and host server configuration that utilizes a digital trusted timestamping scheme to verify log entries by obtaining and digitally signing service access records with a trusted third party, creating aggregates for further signing and verification, ensuring the integrity and authenticity of service access tracking.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If hardware fingerprint mechanism is used for verification, then service access verification is simplified, but the mechanism can be replicated by copying virtual machines leading to security vulnerabilities
Solution Approach 1:
The patent introduces a trusted third party (TTP) as an intermediary that issues digital certificates and timestamps for service access verification. The TTP acts as a mediator between the virtual machine and the verification system, providing cryptographic proof that cannot be replicated by simple copying. This resolves the contradiction by maintaining verification simplicity while ensuring authenticity through the intermediary's trusted digital signatures.
Solution Approach 2:
The patent replaces the mechanical hardware fingerprint mechanism with a cryptographic digital certificate system. Instead of relying on physical hardware characteristics that can be copied, the system uses digital signatures and timestamps that provide mathematical proof of authenticity. This substitution maintains ease of operation through software-based verification while eliminating the security vulnerability of replicable hardware fingerprints.
2Reliability
If digital trusted timestamping scheme is implemented, then service access verification reliability is improved, but system complexity increases due to trusted third party integration
Solution Approach 1:
The patent implements preliminary action by having the trusted third party issue digital certificates and timestamps in advance, before service access verification is needed. The TTP pre-establishes cryptographic trust relationships and maintains a timeline of service accesses that can be verified later without requiring the TTP to be actively involved in each verification event. This reduces system complexity by separating certificate issuance from verification operations.
Solution Approach 2:
The patent adds a temporal dimension to the verification system through timestamps and chronological ordering of service accesses. By organizing verification data in a time-based sequence with cryptographic links between consecutive entries, the system achieves high reliability without requiring complex real-time coordination. This dimensional approach simplifies the architecture by using the time dimension to establish trust rather than complex inter-component communication.
Data Source
AI summary
There is provided mechanisms for verifying a log entry in a communications system. A method is performed by a host server. The method comprises obtaining a log entry of a service access tracker. The log entry indicates access to a service during a client session, the service being tracked by the service 5 access tracker. The method comprises providing the log entry to a trusted third party for digital signing thereof using a digital trusted timestamping scheme. The method comprises verifying that the log entry has been digitally signed by the trusted third party. The method comprises providing a new aggregate comprising the digitally signed log entry and a previous aggregate 10 of previously digitally signed and aggregated log entries to the trusted third party for digital signing thereof using the digital trusted timestamping scheme. The method comprises verifying that the new aggregate has been digitally signed by the trusted third party.


