Cross-Certification Binding for RSA and Post-Quantum Certificate Authorities

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cryptographic systems lack efficient methods to securely bind different digital signature schemes, particularly in the context of quantum computing advancements, where traditional root certificates are vulnerable to tampering and compromise detection is challenging.

Innovation Solution

Implement cross-certification methods involving unique attributes and hash values embedded in cross certificates, allowing secure binding and tampering detection across different cryptographic systems, including RSA and post-quantum key generation techniques.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional root certificates using RSA or elliptic curve key generation are used, then security is maintained against classical computing attacks, but they become vulnerable to quantum computing attacks

Engineering Contradiction:
Improvesecurity against quantum computing attacksVSAvoidcompatibility with existing cryptographic systems
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces cross-certificates as an intermediary mechanism that bridges traditional RSA/elliptic curve certificate authorities and post-quantum certificate authorities. The cross-certification process allows a first root CA to issue certificates signed by a second root CA using post-quantum algorithms, creating a trusted pathway that enables quantum-resistant security while maintaining compatibility with existing X.509 infrastructure and applications

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cross-certification is implemented between different certificate authorities, then trust is established between systems, but detection of tampering or compromise becomes difficult

Engineering Contradiction:
Improvedetection of tamperingVSAvoidcross-certification structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a feedback mechanism where each cross-certificate includes embedded information about the signing relationship between CAs. This allows verification systems to trace and verify the authenticity of cross-certificates by checking the digital signatures and certificate chains, providing tamper-detection capability that feedbacks into the trust verification process

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent performs preliminary establishment of trusted relationships between CAs through the cross-certification process before any potential compromise or tampering can occur. By pre-establishing these trusted pathways with embedded verification information, the system prepares the infrastructure to detect and respond to future tampering attempts

Inventive Principle:
Principle #10Preliminary action

3Reliability

If alternative post-quantum keying structures are adopted, then security against quantum attacks is improved, but compatibility with existing X.509 standard systems is reduced

Engineering Contradiction:
Improvesecurity against quantum attacksVSAvoidimplementation complexity
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent creates a universal cross-certification framework that enables a single certificate authority infrastructure to serve multiple cryptographic purposes - both traditional RSA/elliptic curve security and post-quantum security. The cross-certificates act as multi-functional elements that can be verified by existing X.509-compliant applications while providing quantum-resistant security guarantees

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12388661B2Cross-certification for secure binding of cryptographic systems
Publication Date: 2025.08.12 ENTRUST CORP
  • US12388661B2 patent drawing
  • US12388661B2 patent drawing
  • US12388661B2 patent drawing

AI summary

Methods and systems for cross-certification to bind together two cryptographic systems are disclosed. One method includes receiving, from a first certificate authority at a second certificate authority, a cross certificate request, the cross certificate request including an attribute unique to the first certificate authority. The method also includes calculating a signature at the second certificate authority based at least in part on the attribute, and calculating a hash value based on a combination of the signature calculated at the second certificate authority and a key associated with the second certificate authority. The method includes generating a cross certificate and embedding the hash value as a certificate extension within the cross certificate.