Redefining Digital Web Signature Secrecy: A Client-Side Model for Enhanced Security and Compliance
Journal of the Brazilian Computer Society
Abstract
Web-based digital signature platforms prioritize convenience but often compromise secrecy, exposing sensitive documents and private keys to third-party systems. This paper introduces a client-side cryptographic model that eliminates such vulnerabilities by performing all cryptographic operations within the user's browser. Leveraging One-Time Certificates and adhering to Claude Shannon's secrecy principles, the model ensures that documents and keys remain secure by never leaving the client environment. The proposed approach addresses critical risks, including document exposure, metadata leakage, and key compromise, while maintaining compatibility with public key infrastructure standards and legacy systems. Performance evaluations show efficient signing and verification processes, with documents up to 5 MB signed in approximately 1 second and verified in 0.15 seconds. By removing reliance on external servers for sensitive operations, the model mitigates platform vulnerabilities, reduces liability, and ensures compliance with regulations like GDPR and LGPD. Key contributions include enhanced secrecy, simplified key management, and scalable real-world use-case performance. This work redefines digital signature security, offering a robust, privacy-preserving alternative for secrecy document signature and verification workflows.
Keywords: Digital signature, secrecy, Web signature, client-side signature
Materials
Reference…