Authenticated Key Exchange Between ID-Based and PKI Instruments
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In conventional mixed authentication systems, instruments using PKI-based authentication depend on the ID-based authentication of their communication partners, necessitating the generation of public keys and certificates, which limits their independence and increases time and cost.
Innovation Solution
A key exchange system that enables authentication between ID-based and PKI-based instruments by incorporating first and second verification units, signature generation units, and session key generation units to facilitate secure communication without relying on ID-based authentication for public key generation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If PKI-based authentication instrument generates public key using elliptic curve from ID-based authentication, then authentication can be performed, but the instrument cannot use any public key and must issue electronic certificate for communication partner
Solution Approach 1:
The patent segments the authentication process into independent components: ID-based authentication handles authentication between instruments, while PKI-based authentication handles certificate verification. The public key generation is separated from the authentication mechanism, allowing instruments to use pre-existing public keys without requiring certificate issuance for each communication partner.
Solution Approach 2:
The patent introduces a verification key and electronic certificate as intermediaries that bridge ID-based and PKI-based authentication systems. The verification key associated with the electronic certificate serves as a mediator that allows PKI-based instruments to verify identities without requiring the instrument to generate public keys through ID-based authentication, thus resolving the dependency issue.
2Reliability
If mixed authentication system uses ID-based authentication dependency, then authentication can be established, but time and cost for certificate issuance increases
Solution Approach 1:
The patent applies preliminary action by pre-generating and storing verification keys and electronic certificates in the instrument's storage unit before communication occurs. This allows the instrument to perform authentication without requiring real-time certificate issuance, thereby reducing authentication time while maintaining security through pre-established trust anchors.
Solution Approach 2:
The patent enables self-service authentication where the instrument can autonomously verify authentication results using stored verification keys and electronic certificates without requiring external certificate issuance operations. The instrument serves its own authentication needs by utilizing pre-configured cryptographic materials, eliminating time-consuming external certificate generation processes.
Data Source
AI summary
A key exchange system according to one aspect of the present disclosure is a key exchange system that realizes a key exchange with authentication between a first instrument that performs authentication based on an ID-based encryption and a second instrument that performs authentication based on an electronic certificate, wherein the first instrument includes a first verification unit configured to verify the electronic certificate, a second verification unit configured to verify a signature generated by the second instrument by using a verification key associated with the electronic certificate when the verification of the electronic certificate is successful, and a first session key generation unit configured to generate a session key to be used for encrypted communication with the second instrument by using the electronic certificate and shared information generated by a pairing operation when the verification of the signature is successful, and the second instrument includes a signature generation unit configured to generate the signature by using a signature key corresponding to the verification key, and a second session key generation unit configured to generate a session key to be used for the encrypted communication with the first instrument by using the electronic certificate and the shared information generated by the pairing operation.


