Identifier-Based Encryption Sender Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing identifier-based cryptographic methods lack effective sender authentication mechanisms, relying on public key infrastructure and potentially compromising recipient privacy, especially in scenarios where both sender and recipient identities need to be verified.
Innovation Solution
A cryptographic method and apparatus that utilize a first trusted entity to verify an identifier string associated with a party, generate a secret key, and provide it to the party to encrypt messages and generate signature components, ensuring that a second trusted entity can verify the party's identity and compliance with conditions before decrypting the message, thereby ensuring sender authentication and privacy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a second trusted entity verifies recipient identity and conditions before decryption, then message security and privacy are improved, but device complexity and processing overhead increase
Solution Approach 1:
The patent applies preliminary action by having the second trusted entity verify the recipient's identity and check conditions against the identifier string before performing decryption. This pre-verification approach ensures that only authorized recipients can decrypt messages, improving security while maintaining efficient processing by avoiding unnecessary decryption operations on unauthorized users.
2Reliability
If signature verification is performed by the second trusted entity, then sender authentication is improved, but processing time increases
Solution Approach 1:
The patent merges the signature verification function with the existing decryption process at the second trusted entity. By combining these operations, the system performs both sender authentication and recipient verification in a unified process, improving sender authentication reliability while minimizing additional processing time through operational consolidation.
3Reliability
If the trusted entity dynamically computes decryption exponent from encryption exponent, then recipient privacy is protected, but computational complexity increases
Solution Approach 1:
The patent uses an intermediary approach where the trusted entity acts as a mediator between the encryption and decryption processes. The trusted entity dynamically computes the decryption exponent from the encryption exponent using a secure process, protecting recipient privacy while managing computational complexity through centralized trusted computation rather than distributed key management.
Data Source
AI summary
A cryptographic method and apparatus is provided in which an identifier-based encryption process is used to encrypt a message with an identifier string that specifies conditions to be checked by a trusted entity before providing a decrypted form of the encrypted message, or enabling its decryption. A further trusted entity is used to verify the identity of the message sender as indicated by a further identifier string, and to provide the sender with a secret key that the sender uses to generate complimentary signature components. These signature components are sent along with the encrypted message and are used, along with other data including the first identifier string and a public key of the further trusted entity, to authenticate the identity of the message sender.


