Quantum-resistant double signature system
Abstract
A method includes verifying a digital signature on a dual-signed message by a relying party computing system. Verifying the digital signature on the dual-signed message includes generating a cryptographic hash of content identified in the dual-signed message and signing the cryptographic hash using public key of a signing party computing system to generate a verifying hash. Verifying the digital signature on the dual-signed message further includes comparing the verifying hash to a value of the dual-signed message. Verifying the digital signature on the dual-signed message further includes, responsive to the verifying hash matching the value of the dual-signed message, determining that the digital signature on the dual-signed message is valid. The method further includes identifying an attribute of the dual-signed message by the relying party computing system. The method further includes, based on identifying the attribute, receiving a verification notification for the dual-signed message by the relying party computing system.
Claims
exact text as granted — not AI-modifiedWhat is claimed :
1 . A method for validating a dual-signed message, comprising:
generating, by a computing system, a cryptographic hash of content identified in the dual-signed message; generating, by the computing system using the cryptographic hash, a verifying hash; and responsive to generating the verifying hash, determining, by the computing system, that the dual-signed message is valid.
2 . The method of claim 1 , further comprising performing a certificate path validation by tracking, by the computing system, a chain comprising a public key certificate of a signing party computing system back to a trust anchor.
3 . The method of claim 1 , wherein:
a key pair of the computing system is associated with a certificate in a public key infrastructure (PKI); and the method further comprises performing a certificate path validation by verifying, by the computing system, the certificate with the PKI.
4 . The method of claim 1 , wherein the dual-signed message is generated by signing a Cryptographic Message Syntax (CMS) attribute with a private key by a signature processing computing system using a quantum-resistant signature algorithm.
5 . The method of claim 1 , wherein:
a bundled certificate identifier comprises a signed attribute bound to the dual-signed message, the bundled certificate identifier comprising a certificate issuer and a certificate identifier; and the method further comprises performing a certificate path validation using the bundled certificate identifier.
6 . The method of claim 1 , further comprising:
matching, by the computing system, an attribute of the dual-signed message to a stored dual-signed message in a database; generating, by the computing system, a fresh cryptographic hash of content; and comparing, by the computing system, the fresh cryptographic hash to a hash of the dual-signed message.
7 . The method of claim 1 , further comprising transmitting, by the computing system, an attribute to a signature processing computing system, wherein the computing system receives a verification notification for the dual-signed message from the signature processing computing system.
8 . The method of claim 1 , wherein generating the verifying hash comprises signing, by the computing system, the cryptographic hash using a cryptographic key.
9 . The method of claim 1 , further comprising comparing, by the computing system, the verifying hash to a value of the dual-signed message.
10 . A method for validating a dual-signed message, comprising:
generating, by a computing system, a cryptographic hash of content; comparing, by the computing system, the cryptographic hash to a hash of the dual-signed message; and responsive to the cryptographic hash matching the hash of the dual-signed message, determining, by the computing system, that the dual-signed message is valid.
11 . The method of claim 10 , wherein the dual-signed message is generated by signing a Cryptographic Message Syntax (CMS) attribute with a private key by a signature processing computing system using a quantum-resistant signature algorithm.
12 . The method of claim 10 , wherein:
a bundled certificate identifier comprises a signed attribute bound to the dual-signed message, the bundled certificate identifier comprising a certificate issuer and a certificate identifier; and the method further comprises performing a certificate path validation using the bundled certificate identifier.
13 . The method of claim 10 , further comprising transmitting, by the computing system, an attribute to a signature processing computing system, wherein the computing system receives a verification notification for the dual-signed message from the signature processing computing system.
14 . A method for validating a dual-signed message, the method comprising:
generating, by a computing system, a cryptographic hash of content; comparing, by the computing system, a verifying hash corresponding to the cryptographic hash to a value of the dual-signed message; and responsive to the verifying hash matching the value of the dual-signed message, determining, by the computing system, that the dual-signed message is valid.
15 . The method of claim 14 , further comprising performing a certificate path validation by tracking a chain comprising a public key certificate of a signing party computing system back to a trust anchor.
16 . The method of claim 14 , wherein:
a key pair of the computing system is associated with a certificate in a public key infrastructure (PKI); and the method further comprises performing a certificate path validation by verifying, by the computing system, the certificate with the PKI.
17 . The method of claim 14 , wherein the dual-signed message is generated by signing a Cryptographic Message Syntax (CMS) attribute with a private key by a signature processing computing system using a quantum-resistant signature algorithm.
18 . The method of claim 14 , wherein:
a bundled certificate identifier comprises a signed attribute bound to the dual-signed message, the bundled certificate identifier comprising a certificate issuer and a certificate identifier; and the method further comprises performing a certificate path validation using the bundled certificate identifier.
19 . The method of claim 14 , further comprising:
matching, by the computing system, an attribute of the dual-signed message to a stored dual-signed message in a database; generating, by the computing system, a fresh cryptographic hash of content; and comparing, by the computing system, the fresh cryptographic hash to a hash of the dual-signed message.
20 . The method of claim 14 , further comprising transmitting an attribute of the dual-signed message to a signature processing computing system.Join the waitlist — get patent alerts
Track US2023291572A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.