Verification Key Management Server for Bid Request Authenticity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In the context of real-time bidding for advertising, there is a challenge in verifying the authenticity of verification keys used for bid requests, as existing systems do not adequately manage key revocation, leading to potential spoofing of bid requests with compromised keys.
Innovation Solution
A signature verification system comprising a signature generation server, a signature verification server, and a verification key management server, which work together to ensure that only the latest, authentic verification keys are used for verifying bid requests, by reporting and registering publisher identification and verification keys, and transmitting them securely across the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If key management is entrusted to the publisher in the ads.cert specification, then the publisher can independently manage verification keys, but the authenticity and validity of verification keys cannot be confirmed, leading to potential spoofing with compromised keys
Solution Approach 1:
The patent introduces a key management server as an intermediary between publishers and buyers. This server registers verification keys reported by publishers and provides them to buyers upon request, serving as a trusted mediator that confirms key authenticity without requiring buyers to directly trust publishers. The server acts as a central authority that validates and distributes keys, resolving the contradiction between independent management and authenticated verification.
Solution Approach 2:
The system implements a feedback mechanism where publishers report verification keys to the key management server, which then provides these keys to buyers who request them. This creates a closed-loop information flow that ensures buyers receive authenticated keys from a trusted source rather than directly from potentially compromised publisher sources, thereby confirming key authenticity while maintaining operational simplicity.
2Productivity
If the buyer obtains verification key files directly from the publisher's root domain, then the process is simple and direct, but the buyer cannot determine whether the verification key is a valid key generated by the publisher who issued the bid request
Solution Approach 1:
The key management server serves as an intermediary that buyers query to obtain verification keys. Instead of directly fetching keys from publisher domains, buyers request keys from this trusted intermediary, which then provides authenticated keys. This maintains operational efficiency through automated retrieval while significantly improving authenticity verification through the intermediary's validation role.
Solution Approach 2:
Publishers pre-report verification keys to the key management server before they are needed for bid verification. This preliminary action allows the server to have authenticated keys ready when buyers request them, eliminating the need for buyers to directly access publisher domains and ensuring they receive validated keys without delay, thus maintaining efficiency while improving security.
Data Source
AI summary
A signature verification system includes a signature generation server, a signature verification server, and a verification key management server that are connected to one another via a communication network. The signature generation server includes: reporting means for, when a signing key and a verification key are generated by a publisher, reporting the verification key and publisher identification information that identifies the publisher to the verification key management server; and signature generation means for signing a bid request issued by the publisher with use of the signing key. The verification key management server includes: registration means for registering the publisher identification information and the verification key that were reported by the reporting means in a storage unit in association with information that enables specifying a version of the verification key.


