Cryptographic Client Identifier for PKI Setup

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing Public Key Infrastructure (PKI) systems are costly and complex to set up and maintain, especially when multiple clients share a technical PKI authority, requiring explicit setup of clients which can be cumbersome and inefficient.

Innovation Solution

A method for issuing a cryptographically protected certificate of authenticity that includes providing a public user key and a public client key, forming a request (CSR) protected by the private client key, and issuing a certificate that contains the public user key and identifies the client using a cryptographic client identifier formed from the public client key.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a traditional PKI infrastructure is used with explicit client setup, then security and authentication are ensured, but the system becomes costly and complex to set up and maintain

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables self-service by allowing clients to automatically generate their own cryptographic client identifiers using their public client keys without requiring manual setup or configuration by the PKI authority. This automated self-identification process reduces the complexity of client setup while maintaining security through cryptographic verification.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces a registration authority as an intermediary that issues certificates containing cryptographic client identifiers. This intermediary simplifies the overall system by handling the complex task of client registration and identification automatically, reducing the burden on both the PKI authority and individual clients while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If multiple clients share a technical PKI authority, then resource utilization is improved, but the setup and management becomes more cumbersome

Engineering Contradiction:
Improveresource utilizationVSAvoidclient setup
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

Each client automatically generates its own cryptographic client identifier using its public client key, enabling independent self-service without requiring manual configuration by the shared PKI authority. This eliminates the need for explicit client setup while allowing multiple clients to efficiently share the same PKI infrastructure.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system changes the identification parameter from manual client configuration to cryptographic identification based on public keys. By using the public client key as the basis for generating cryptographic client identifiers, the system enables automatic differentiation of multiple clients sharing the same PKI authority without cumbersome setup procedures.

Inventive Principle:
Principle #35Parameter changes

3Loss of time

If cryptographic client identifiers are used instead of explicit client setup, then setup time and cost are reduced, but system security must be maintained

Engineering Contradiction:
Improvesetup timeVSAvoidsecurity
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

The patent replaces the mechanical process of explicit client setup with a cryptographic system. Instead of manually configuring and registering clients, the system uses cryptographic client identifiers generated from public keys, automatically providing both rapid setup and security verification through mathematical principles.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The registration authority acts as an intermediary that issues certificates containing cryptographic client identifiers, maintaining security by verifying and certifying client identities through cryptographic means rather than manual setup, thus preserving security while reducing setup time.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12316777B2Method for issuing a cryptographically protected certificate of authenticity for a user
Publication Date: 2025.05.27 SIEMENS AG
  • US12316777B2 patent drawing
  • US12316777B2 patent drawing

AI summary

Various embodiments of the teachings herein include a method for issuing a cryptographically protected certificate of authenticity for a user comprising: providing a public user key; providing a public client key for a client, the public client key assigned to the user; forming a request including the public user key, wherein the public user key is protected with the aid of a private client key assigned to the provided public client key; and issuing a cryptographically protected certificate of authenticity containing the public user key and identifying the client. The cryptographically protected certificate of authenticity contains or references a cryptographic client identifier formed depending at least in part on the public client key.