Cryptographic Key Replacement Without Secret Exposure
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing public-key cryptography systems lack a convenient and efficient method for replacing cryptographic keys in tokens without revealing the secret key, which is crucial for preventing unauthorized use and ensuring secure transitions when tokens are stolen, lost, or compromised.
Innovation Solution
A method and system that allow for the creation and management of multiple sets of cryptographic keys, where each set can be independently generated and output, enabling future replacement without revealing the secret key, with mechanisms to disable and re-enable keys to prevent unauthorized access and ensure secure transitions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the token is stolen or compromised, then the thief can use the stolen token for unauthorized access, but the owner cannot easily revoke the old token without revealing the secret key
Solution Approach 1:
The patent applies preliminary action by pre-generating replacement keys in advance while the original token is still functional. The system creates a second private key and corresponding public key before any compromise occurs, storing them securely. When the original token is stolen or compromised, the owner can immediately use the pre-prepared replacement key without needing to perform complex key generation or reveal the secret key, thus resolving the contradiction between security and ease of key replacement.
2Ease of operation
If the secret key is revealed during replacement, then the owner can create a new token, but the security of the original key is compromised
Solution Approach 1:
The patent applies the extraction principle by separating the replacement key generation process from the original secret key. The system extracts the ability to create replacement keys as an independent function that does not require revealing the original secret key. The second private key is generated and stored separately, allowing key replacement while keeping the original secret key confidential, thus resolving the contradiction between ease of replacement and security.
3Adaptability or versatility
If multiple key pairs are generated and stored, then future replacement is enabled, but the device complexity increases
Solution Approach 1:
The patent applies segmentation by dividing the key management system into distinct components: the original private key stored in the token, the replacement private key stored separately, and corresponding public keys registered with verifiers. This segmentation allows the system to manage multiple key pairs without creating a monolithic complex structure. Each key pair serves a specific purpose (original authentication or replacement authentication), making the overall system more manageable and less complex than it would be without this structured division.
Data Source
AI summary
Embodiments describe a method and/or system whereby a secret key in a cryptographic system may be replaced without revealing the secret key. One embodiment comprises creating a first private key and corresponding first public key. A second private key associated with the first private key and a second public key corresponding to the second private key are also created. The second private key is output once such that it can be re-created and the second public key is output when outputting the first public key. The first private key is used for authentication. The method further comprises re-creating the second private key; and using the second private key for authentication. Another embodiment comprises creating a private key and corresponding public key with associated system parameter; outputting the system parameter when outputting the public key; and using the private key for authentication. The method may further comprise creating a new private key using the previous key and the system parameter.


