Dual-Key Digital Certificate for PQC Signature and Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing digital certificates cannot effectively support both signature verification and encryption functions in Post-Quantum Cryptography (PQC) algorithms, necessitating a new approach to ensure cryptographic security and efficiency.
Innovation Solution
A digital certificate design that incorporates multiple public cryptographic keys, each associated with different asymmetric cryptographic algorithms tailored for PQC, allowing for signature verification and encryption purposes, with security ensured by distinct cryptographic problems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a single public cryptographic key is used in a digital certificate, then the certificate structure remains simple and compatible with existing protocols, but the certificate cannot simultaneously support both signature verification and encryption functions in PQC algorithms
Solution Approach 1:
The patent applies multi-functionality by incorporating multiple public cryptographic keys (first public key for signature verification, second public key for encryption) within a single digital certificate. This allows the certificate to simultaneously support both signature verification and encryption functions using PQC algorithms, eliminating the need for separate certificates for each function while maintaining a unified certificate structure that is compatible with existing protocols.
2Adaptability or versatility
If multiple public cryptographic keys are incorporated into a single digital certificate, then both signature verification and encryption functions can be supported, but the certificate complexity increases
Solution Approach 1:
The patent applies segmentation by dividing the cryptographic functions into distinct components: the first public key is dedicated to signature verification while the second public key is dedicated to encryption. Each key is associated with specific usage information that defines its intended purpose. This segmentation allows the certificate to manage multiple functions systematically, reducing the operational complexity of selecting and applying the correct key for different cryptographic operations.
3Reliability
If different asymmetric cryptographic algorithms are used for signature verification and encryption, then quantum computer-safe security is achieved, but the verification and encryption processes become more complex
Solution Approach 1:
The patent applies local quality by assigning different cryptographic algorithms to different keys based on their specific purposes: the first public key uses a signature verification algorithm (such as Dilithium or Falcon) while the second public key uses an encryption algorithm (such as Kyber). Each algorithm is selected and configured according to the local requirements of its specific function, optimizing security for each operation while maintaining overall system coherence through the unified certificate structure.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A digital certificate (100) is disclosed, comprising a first public cryptographic key (112) and a second public cryptographic key (122). The first public cryptographic key (112) is associated with and configured for use in a first cryptographic algorithm. The second public cryptographic key (122) is associated with and configured for use in a second cryptographic algorithm. One of the two algorithms is a signature verification algorithm, and the public cryptographic key used in this signature verification algorithm is configured as a signature verification key for verifying one or more digital signatures (322) of the certificate holder (100). The other of the two algorithms is an encryption or key negotiation algorithm.The public cryptographic key to be used in this other algorithm is an encryption key for encrypting data (422). The public cryptographic key to be used in this key negotiation algorithm is an encryption key for negotiating a cryptographic key for encrypting data (422).