ECQV Certificate Cross-Domain Credential Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing implicit certificate systems, such as ECQV, limit the generation of public key pairs to a single certificate authority, requiring separate registration and increasing costs for provisioning credentials across multiple certificate authorities.

Innovation Solution

A method and system that allow a single private key to generate multiple public key pairs and implicit certificates across different certificate authorities, using an initial registered public key or implicit certificate to request credentials from multiple authorities, reducing registration costs and enabling multiple private keys to be derived from a single key.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a user requests separate ECQV certificates from multiple certificate authorities, then each certificate provides implicit authentication in its domain, but the registration cost and complexity increase proportionally with each additional authority

Engineering Contradiction:
Improveimplicit authentication coverageVSAvoidregistration process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes a single ECQV certificate universal across multiple certificate authority domains. The certificate structure includes multiple public key values (Q1, Q2, ..., Qn) that can be used in different CA domains, allowing one certificate to provide implicit authentication across multiple domains rather than requiring separate certificates for each domain

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent combines multiple certificate authority endorsements into a single certificate structure. Instead of obtaining separate certificates from each CA, the system merges their authentication capabilities into one certificate that contains public key values from multiple CAs, reducing the number of registration interactions needed

Inventive Principle:
Principle #5Merging (Combining)

2Adaptability or versatility

If separate ECQV certificates are obtained from multiple certificate authorities, then credentials are available across different domains, but the provisioning cost increases with each additional certificate

Engineering Contradiction:
Improvecross-domain credential availabilityVSAvoidprovisioning cost
Core Design Contradiction:
Adaptability or versatilityVSLoss of energy

Solution Approach 1:

The patent creates a universal certificate that functions across multiple certificate authority domains. A single certificate with multiple embedded public key values can be used for implicit authentication in any of the associated CA domains, eliminating the need to purchase and manage separate certificates for each domain

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent performs preliminary registration with multiple certificate authorities in advance, obtaining their public key values and embedding them in a single certificate structure before deployment. This preliminary action allows the certificate to be immediately usable across multiple domains without requiring additional provisioning transactions

Inventive Principle:
Principle #10Preliminary action

3Reliability

If ECQV certificates are generated with random public keys from computations, then each certificate is cryptographically secure, but the same public key cannot be used across different certificate authorities

Engineering Contradiction:
Improvecryptographic securityVSAvoidpublic key reusability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the certificate structure to include multiple distinct public key values (Q1, Q2, ..., Qn) that can be independently associated with different certificate authorities. Each public key maintains its cryptographic security properties while the overall certificate structure enables cross-domain usability by providing multiple key options

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transitions from a single public key dimension to multiple public key dimensions within one certificate. Instead of having one public key per certificate, the system embeds multiple public key values, adding a dimensional aspect that enables the same certificate to interface with multiple different certificate authority domains

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS9246900B2Using a single certificate request to generate credentials with multiple ECQV certificates
Publication Date: 2016.01.26 MALIKIE INNOVATIONS LTD
  • US9246900B2 patent drawing
  • US9246900B2 patent drawing
  • US9246900B2 patent drawing

AI summary

A method and apparatus are disclosed for using a single credential request (e.g., registered public key or ECQV certificate) to obtain a plurality of credentials in a secure digital communication system having a plurality of trusted certificate authority CA entities and one or more subscriber entities A. In this way, entity A can be provisioned onto multiple PKI networks by leveraging a single registered public key or implicit certificate as a credential request to one or more CA entities to obtain additional credentials, where each additional credential can be used to derive additional public key-private key pairs for the entity A.