Dual-Key Digital Certificate for PQC Signature and Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing digital certificates cannot effectively support both signature verification and encryption functions in Post-Quantum Cryptography (PQC) algorithms, necessitating a new approach to ensure cryptographic security and efficiency.

Innovation Solution

A digital certificate design that incorporates multiple public cryptographic keys, each associated with different asymmetric cryptographic algorithms tailored for PQC, allowing for signature verification and encryption purposes, with security ensured by distinct cryptographic problems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a single public cryptographic key is used in a digital certificate, then the certificate structure remains simple and compatible with existing protocols, but the certificate cannot simultaneously support both signature verification and encryption functions in PQC algorithms

Engineering Contradiction:
Improvefunctional versatilityVSAvoidcertificate structure
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies multi-functionality by incorporating multiple public cryptographic keys (first public key for signature verification, second public key for encryption) within a single digital certificate. This allows the certificate to simultaneously support both signature verification and encryption functions using PQC algorithms, eliminating the need for separate certificates for each function while maintaining a unified certificate structure that is compatible with existing protocols.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If multiple public cryptographic keys are incorporated into a single digital certificate, then both signature verification and encryption functions can be supported, but the certificate complexity increases

Engineering Contradiction:
Improvefunctional versatilityVSAvoidcertificate structure
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies segmentation by dividing the cryptographic functions into distinct components: the first public key is dedicated to signature verification while the second public key is dedicated to encryption. Each key is associated with specific usage information that defines its intended purpose. This segmentation allows the certificate to manage multiple functions systematically, reducing the operational complexity of selecting and applying the correct key for different cryptographic operations.

Inventive Principle:
Principle #1Segmentation

3Reliability

If different asymmetric cryptographic algorithms are used for signature verification and encryption, then quantum computer-safe security is achieved, but the verification and encryption processes become more complex

Engineering Contradiction:
Improvecryptographic securityVSAvoidcryptographic operations
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by assigning different cryptographic algorithms to different keys based on their specific purposes: the first public key uses a signature verification algorithm (such as Dilithium or Falcon) while the second public key uses an encryption algorithm (such as Kyber). Each algorithm is selected and configured according to the local requirements of its specific function, optimizing security for each operation while maintaining overall system coherence through the unified certificate structure.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP4704371A1Digital certificate
Publication Date: 2026.03.04 BUNDESDRUCKEREI GMBH
  • EP4704371A1 patent drawingFigure 1
  • EP4704371A1 patent drawingFigure 2
  • EP4704371A1 patent drawingFigure 3

AI summary

A digital certificate (100) is disclosed, comprising a first public cryptographic key (112) and a second public cryptographic key (122). The first public cryptographic key (112) is associated with and configured for use in a first cryptographic algorithm. The second public cryptographic key (122) is associated with and configured for use in a second cryptographic algorithm. One of the two algorithms is a signature verification algorithm, and the public cryptographic key used in this signature verification algorithm is configured as a signature verification key for verifying one or more digital signatures (322) of the certificate holder (100). The other of the two algorithms is an encryption or key negotiation algorithm.The public cryptographic key to be used in this other algorithm is an encryption key for encrypting data (422). The public cryptographic key to be used in this key negotiation algorithm is an encryption key for negotiating a cryptographic key for encrypting data (422).