Authenticated Key Exchange Between ID-Based and PKI Instruments

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In conventional mixed authentication systems, instruments using PKI-based authentication depend on the ID-based authentication of their communication partners, necessitating the generation of public keys and certificates, which limits their independence and increases time and cost.

Innovation Solution

A key exchange system that enables authentication between ID-based and PKI-based instruments by incorporating first and second verification units, signature generation units, and session key generation units to facilitate secure communication without relying on ID-based authentication for public key generation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If PKI-based authentication instrument generates public key using elliptic curve from ID-based authentication, then authentication can be performed, but the instrument cannot use any public key and must issue electronic certificate for communication partner

Engineering Contradiction:
Improvepublic key selection freedomVSAvoidcertificate issuance requirement
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication process into independent components: ID-based authentication handles authentication between instruments, while PKI-based authentication handles certificate verification. The public key generation is separated from the authentication mechanism, allowing instruments to use pre-existing public keys without requiring certificate issuance for each communication partner.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a verification key and electronic certificate as intermediaries that bridge ID-based and PKI-based authentication systems. The verification key associated with the electronic certificate serves as a mediator that allows PKI-based instruments to verify identities without requiring the instrument to generate public keys through ID-based authentication, thus resolving the dependency issue.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If mixed authentication system uses ID-based authentication dependency, then authentication can be established, but time and cost for certificate issuance increases

Engineering Contradiction:
Improveauthentication securityVSAvoidcertificate issuance time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-generating and storing verification keys and electronic certificates in the instrument's storage unit before communication occurs. This allows the instrument to perform authentication without requiring real-time certificate issuance, thereby reducing authentication time while maintaining security through pre-established trust anchors.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables self-service authentication where the instrument can autonomously verify authentication results using stored verification keys and electronic certificates without requiring external certificate issuance operations. The instrument serves its own authentication needs by utilizing pre-configured cryptographic materials, eliminating time-consuming external certificate generation processes.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250330334A1Key exchange system, equipment, method, and program
Publication Date: 2025.10.23 NIPPON TELEGRAPH & TELEPHONE CORP
  • US20250330334A1 patent drawing
  • US20250330334A1 patent drawing
  • US20250330334A1 patent drawing

AI summary

A key exchange system according to one aspect of the present disclosure is a key exchange system that realizes a key exchange with authentication between a first instrument that performs authentication based on an ID-based encryption and a second instrument that performs authentication based on an electronic certificate, wherein the first instrument includes a first verification unit configured to verify the electronic certificate, a second verification unit configured to verify a signature generated by the second instrument by using a verification key associated with the electronic certificate when the verification of the electronic certificate is successful, and a first session key generation unit configured to generate a session key to be used for encrypted communication with the second instrument by using the electronic certificate and shared information generated by a pairing operation when the verification of the signature is successful, and the second instrument includes a signature generation unit configured to generate the signature by using a signature key corresponding to the verification key, and a second session key generation unit configured to generate a session key to be used for the encrypted communication with the first instrument by using the electronic certificate and the shared information generated by the pairing operation.