Hybrid Security Certificates With Independent Multi-Cryptosystem Signatures

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security certificates rely on a single cryptosystem, making them vulnerable to quantum computer attacks and limiting flexibility in transitioning to new cryptographic standards.

Innovation Solution

Generate a hybrid security certificate using multiple cryptosystems, including a NIST-certified asymmetric cryptosystem and a quantum-resistant cryptosystem, with independent digital signatures that do not depend on each other, allowing for seamless transition between standards.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single cryptosystem is used in security certificates, then the certificate structure is simple and easy to implement, but the certificate becomes vulnerable to quantum computer attacks and lacks flexibility for transitioning to new cryptographic standards

Engineering Contradiction:
Improvesecurity strengthVSAvoidcertificate structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the security certificate into multiple independent signature components, each using a different cryptosystem (e.g., RSA signature, ECDSA signature, and/or quantum-resistant signature). This segmentation allows the certificate to incorporate multiple cryptographic algorithms without creating a single complex intertwined structure, thereby improving security while managing complexity through modular organization

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a composite security certificate that combines multiple cryptographic signature types (RSA, ECDSA, and quantum-resistant signatures) into a single certificate structure. This composite approach integrates different cryptographic 'materials' to achieve enhanced security properties that no single cryptosystem could provide alone, particularly resistance to both classical and quantum attacks

Inventive Principle:
Principle #40Composite materials

2Adaptability or versatility

If multiple cryptosystems are integrated into a single security certificate, then the certificate becomes resistant to quantum attacks and more flexible, but the certificate structure and processing become more complex

Engineering Contradiction:
Improveflexibility for standard transitionVSAvoidcertificate processing
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic adaptability by allowing the certificate to support multiple cryptosystems that can be independently validated. The certificate structure enables flexible configuration where different signature algorithms can be added, removed, or updated without requiring changes to the overall certificate framework, facilitating smooth transitions to new cryptographic standards as they become available

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent creates a universal certificate structure that can serve multiple cryptographic purposes simultaneously. The certificate is designed to work with traditional cryptosystems (RSA, ECDSA) and quantum-resistant cryptosystems alike, making it multi-functional and adaptable to various security requirements and future cryptographic standards without requiring separate certificate types

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If digital signatures are made interdependent across different cryptosystems, then the certificate provides comprehensive security coverage, but updating or changing one signature requires regenerating the entire certificate

Engineering Contradiction:
Improvesecurity coverageVSAvoidcertificate update
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent segments the digital signatures into independent, non-interdependent components. Each signature (RSA signature, ECDSA signature, quantum-resistant signature) is generated and validated separately without relying on the others. This independence allows individual signatures to be updated, regenerated, or revoked without affecting or requiring regeneration of the entire certificate, significantly improving ease of maintenance and updates

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP4298756B1Generating a hybrid security certificate using multiple cryptosystems
Publication Date: 2026.04.22 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • EP4298756B1 patent drawingFigure 1A~1B
  • EP4298756B1 patent drawingFigure 2
  • EP4298756B1 patent drawingFigure 3

AI summary

Processing within a computing environment is facilitated by generating a hybrid security certificate using multiple cryptosystems. The generating includes obtaining data for inclusion in the hybrid security certificate, and generating a first digital signature associated with a first cryptosystem to cover the data, and a second digital signature associated with a second cryptosystem to cover the data. The generating further includes providing the hybrid security certificate, where the hybrid security certificate includes the data, the first digital signature associated with the first cryptosystem, and the second digital signature associated with the second cryptosystem, and where the first digital signature has no dependency on a key of the second cryptosystem or the second digital signature, and the second digital signature has no dependency on a key of the first cryptosystem or the first digital signature.