Delegated Decryption Key Generation for IBE Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing Identifier-Based Encryption (IBE) systems face a high load on the trusted authority for decryption key generation, especially when a large number of parties need to access services, leading to impractical decryption-key generation functionality.
Innovation Solution
Delegating key-provision authority to a trusted device, such as a personal digital assistant (PDA), which forms a chain of public/private cryptographic key pairs in a subversion-resistant manner, allowing the device to generate decryption keys under authorized conditions, thereby reducing the load on the trusted authority.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the trusted authority generates decryption keys for all parties accessing services, then service access control is ensured, but the trusted authority becomes overloaded and the system becomes impractical for large numbers of users
Solution Approach 1:
The patent introduces a delegate device (such as a PDA or trusted computing device) as an intermediary between the trusted authority and service access requests. This delegate device is provisioned with cryptographic materials and authority to generate decryption keys locally, thereby mediating the key generation process and relieving the trusted authority from handling every individual key generation request while maintaining security and access control integrity
2Reliability
If decryption key generation is centralized at the trusted authority, then security and authorization are maintained, but the system cannot scale to handle large numbers of service accesses
Solution Approach 1:
The patent segments the centralized key generation function into distributed components by delegating authority to multiple delegate devices. Each delegate device can independently generate decryption keys for authorized parties, transforming the monolithic trusted authority into a distributed system of authorized delegates, thereby enabling the system to scale horizontally while maintaining security through cryptographic verification of delegate authority
3Reliability
If the trusted authority handles all key provision requests, then complete control over access is maintained, but the response time and efficiency deteriorate due to the bottleneck
Solution Approach 1:
The patent performs preliminary action by pre-provisioning delegate devices with cryptographic materials and authorization credentials before they are needed for key generation. This advance preparation enables delegate devices to immediately generate decryption keys without contacting the trusted authority for each request, significantly reducing key generation time while maintaining security through pre-verified authority
Data Source
AI summary
A trusted authority delegates authority to a device. This delegation of authority is effected by providing a yet-to-be completed chain of public/private cryptographic key pairs linked in a subversion-resistant manner. The chain terminates with a penultimate key pair formed by public/private data, and a link towards an end key pair to be formed by an encryption/decryption key pair of an Identifier-Based Encryption, IBE, scheme. The private data is securely stored in the device for access only by an authorized key-generation process that forms the link to the end key pair and is arranged to provide the IBE decryption key generated using the private data and encryption key. This key generation/provision is normally only effected if at least one condition, for example specified in the encryption key, is satisfied. Such a condition may be one tested against data provided by the trusted authority and stored in the device.


