Identity-Based Key Management via Secure Channel Setup
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Identity-based cryptography (IBC) schemes lack methods for securely configuring channels between servers and users for private key issuance, leading to certificate management burdens and potential safety issues during key issuance processes.
Innovation Solution
An ID-based key management system that includes an authentication server for user authentication and secure channel setup using key exchange based on user IDs and passwords, generating and providing private keys through a secure channel, with the assistance of a hardware security module (HSM) and cyclically updated padding character strings to enhance security and key updating.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If PKI-based TLS/SSL is applied for secure channel configuration, then security of key issuance is improved, but certificate management burden increases and the merit of IBC (no separate certificate) is lost
Solution Approach 1:
The patent introduces a secure channel configuration unit that acts as an intermediary to establish secure communication between the private key issuance unit and the terminal. This unit uses the authenticated user's ID as a public key to encrypt session keys and establish secure channels without requiring traditional PKI certificates, thus maintaining IBC's certificateless advantage while ensuring secure key issuance
Solution Approach 2:
The patent changes the cryptographic parameters by using the user's ID directly as the public key in an ID-based cryptography system, replacing the traditional certificate-based public key infrastructure. This parameter change eliminates the need for separate certificate management while maintaining security through mathematical relationships between IDs and private keys
2Reliability
If traditional key issuance method is used, then security channel is established, but the merit of IBC (no separate certificate) is not available
Solution Approach 1:
The system enables self-service by allowing users to use their own IDs as public keys for secure communication. The secure channel configuration unit automatically establishes secure channels using the user's ID without requiring manual certificate management, making the system both secure and easy to operate
Solution Approach 2:
The user's ID serves multiple functions: it acts as both the user identifier and the public key for cryptographic operations. This multi-functionality eliminates the need for separate certificate structures while maintaining security channel capabilities
3Device complexity
If IBC scheme is used without secure channel configuration, then certificate management is simplified, but safety in key issuance process cannot be perfectly ensured
Solution Approach 1:
The patent performs preliminary authentication of the user's ID and password before the private key issuance process begins. The authentication server verifies the user's credentials and establishes a secure channel in advance, ensuring that only authenticated users can receive private keys through secure channels
4Reliability
If separate certificate is used for key issuance, then secure channel can be established, but burden for certificate management is imposed
Solution Approach 1:
The patent extracts the certificate management function from the system by using ID-based cryptography, where the user's ID directly serves as the public key. This extraction eliminates the need for separate certificate issuance, storage, and renewal processes that consume time and resources
Data Source
AI summary
A system and method for identity (ID)-based key management are provided. The ID-based key management system includes an authentication server configured to authenticate a terminal through key exchange based on an ID and a password of a user of the terminal, set up a secure channel with the terminal, and provide a private key based on the ID of the user to the terminal through the secure channel, and a private-key generator configured to generate the private key corresponding to the ID of the terminal user according to a request of the authentication server.


