Attribute Certificate Selection for PQC Protocol Transition

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cryptographic systems face challenges in transitioning between different cryptographic protocols, particularly with the advent of Cryptographically Relevant Quantum Computers (CRQC) and Post Quantum Cryptography (PQC), leading to inefficiencies and security threats.

Innovation Solution

Utilizing attribute certificates to identify and validate certificate chains, allowing relying parties to select appropriate public key certificates based on attributes such as protocol type, key management algorithms, and expiration dates, enabling seamless integration between conventional and PQC systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple public key certificates are maintained for different cryptographic protocols, then adaptability to different protocols is improved, but device complexity increases

Engineering Contradiction:
Improveadaptability to cryptographic protocolsVSAvoidcomplexity of certificate management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the certificate management by separating the attribute certificate (which identifies multiple public key certificates) from the actual public key certificates. This allows the system to handle multiple cryptographic protocols through a structured division where the attribute certificate acts as an index or descriptor, reducing the complexity of managing multiple certificates directly.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The attribute certificate serves as an intermediary between the relying party and the multiple public key certificates. Instead of directly managing and selecting from multiple public key certificates, the relying party uses the attribute certificate as a mediator to identify and select the appropriate public key certificate for the desired cryptographic protocol, thereby reducing complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If attribute certificates are used to identify multiple public key certificates, then ease of operation is improved, but information processing requirements increase

Engineering Contradiction:
Improveease of certificate selectionVSAvoidamount of certificate data
Core Design Contradiction:
Ease of operationVSQuantity of substance

Solution Approach 1:

The patent extracts the identifying information and metadata about multiple public key certificates into a separate attribute certificate. This extraction allows the main public key certificates to remain compact while the attribute certificate contains the necessary information for selection, balancing ease of operation with manageable data quantities.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS20250267013A1Public key infrastructure attribute certificate tweak (PACT)
Publication Date: 2025.08.21 WELLS FARGO BANK NA
  • US20250267013A1 patent drawing
  • US20250267013A1 patent drawing
  • US20250267013A1 patent drawing

AI summary

The present disclosure is directed to systems, methods, and non-transitory computer-readable media for receiving, by a relying party device from a subject device, an attribute certificate of a subject corresponding to the subject device, wherein the attribute certificate identifies a plurality of public key certificates, each of the plurality of public key certificates is part of a certificate chain, each of the plurality of public key certificates comprises a public key of the subject, selecting, by the relying party device, a public key certificate of the plurality of public key certificates using the attribute certificate, performing, by the relying party device, certificate chain validation of a certificate chain of the selected public key certificate, and in response to the certificate chain validation being successful, using, by the relying party device, a public key comprised in the selected public key certificate in a cryptographic operation.