Attribute Certificate Selection for PQC Protocol Transition
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cryptographic systems face challenges in transitioning between different cryptographic protocols, particularly with the advent of Cryptographically Relevant Quantum Computers (CRQC) and Post Quantum Cryptography (PQC), leading to inefficiencies and security threats.
Innovation Solution
Utilizing attribute certificates to identify and validate certificate chains, allowing relying parties to select appropriate public key certificates based on attributes such as protocol type, key management algorithms, and expiration dates, enabling seamless integration between conventional and PQC systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple public key certificates are maintained for different cryptographic protocols, then adaptability to different protocols is improved, but device complexity increases
Solution Approach 1:
The patent segments the certificate management by separating the attribute certificate (which identifies multiple public key certificates) from the actual public key certificates. This allows the system to handle multiple cryptographic protocols through a structured division where the attribute certificate acts as an index or descriptor, reducing the complexity of managing multiple certificates directly.
Solution Approach 2:
The attribute certificate serves as an intermediary between the relying party and the multiple public key certificates. Instead of directly managing and selecting from multiple public key certificates, the relying party uses the attribute certificate as a mediator to identify and select the appropriate public key certificate for the desired cryptographic protocol, thereby reducing complexity.
2Ease of operation
If attribute certificates are used to identify multiple public key certificates, then ease of operation is improved, but information processing requirements increase
Solution Approach 1:
The patent extracts the identifying information and metadata about multiple public key certificates into a separate attribute certificate. This extraction allows the main public key certificates to remain compact while the attribute certificate contains the necessary information for selection, balancing ease of operation with manageable data quantities.
Data Source
AI summary
The present disclosure is directed to systems, methods, and non-transitory computer-readable media for receiving, by a relying party device from a subject device, an attribute certificate of a subject corresponding to the subject device, wherein the attribute certificate identifies a plurality of public key certificates, each of the plurality of public key certificates is part of a certificate chain, each of the plurality of public key certificates comprises a public key of the subject, selecting, by the relying party device, a public key certificate of the plurality of public key certificates using the attribute certificate, performing, by the relying party device, certificate chain validation of a certificate chain of the selected public key certificate, and in response to the certificate chain validation being successful, using, by the relying party device, a public key comprised in the selected public key certificate in a cryptographic operation.


