Cross-Certification Binding for RSA and Post-Quantum Certificate Authorities
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cryptographic systems lack efficient methods to securely bind different digital signature schemes, particularly in the context of quantum computing advancements, where traditional root certificates are vulnerable to tampering and compromise detection is challenging.
Innovation Solution
Implement cross-certification methods involving unique attributes and hash values embedded in cross certificates, allowing secure binding and tampering detection across different cryptographic systems, including RSA and post-quantum key generation techniques.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional root certificates using RSA or elliptic curve key generation are used, then security is maintained against classical computing attacks, but they become vulnerable to quantum computing attacks
Solution Approach 1:
The patent introduces cross-certificates as an intermediary mechanism that bridges traditional RSA/elliptic curve certificate authorities and post-quantum certificate authorities. The cross-certification process allows a first root CA to issue certificates signed by a second root CA using post-quantum algorithms, creating a trusted pathway that enables quantum-resistant security while maintaining compatibility with existing X.509 infrastructure and applications
2Reliability
If cross-certification is implemented between different certificate authorities, then trust is established between systems, but detection of tampering or compromise becomes difficult
Solution Approach 1:
The patent implements a feedback mechanism where each cross-certificate includes embedded information about the signing relationship between CAs. This allows verification systems to trace and verify the authenticity of cross-certificates by checking the digital signatures and certificate chains, providing tamper-detection capability that feedbacks into the trust verification process
Solution Approach 2:
The patent performs preliminary establishment of trusted relationships between CAs through the cross-certification process before any potential compromise or tampering can occur. By pre-establishing these trusted pathways with embedded verification information, the system prepares the infrastructure to detect and respond to future tampering attempts
3Reliability
If alternative post-quantum keying structures are adopted, then security against quantum attacks is improved, but compatibility with existing X.509 standard systems is reduced
Solution Approach 1:
The patent creates a universal cross-certification framework that enables a single certificate authority infrastructure to serve multiple cryptographic purposes - both traditional RSA/elliptic curve security and post-quantum security. The cross-certificates act as multi-functional elements that can be verified by existing X.509-compliant applications while providing quantum-resistant security guarantees
Data Source
AI summary
Methods and systems for cross-certification to bind together two cryptographic systems are disclosed. One method includes receiving, from a first certificate authority at a second certificate authority, a cross certificate request, the cross certificate request including an attribute unique to the first certificate authority. The method also includes calculating a signature at the second certificate authority based at least in part on the attribute, and calculating a hash value based on a combination of the signature calculated at the second certificate authority and a key associated with the second certificate authority. The method includes generating a cross certificate and embedding the hash value as a certificate extension within the cross certificate.


