Identity-Based Encryption for Postage Indicia Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current postal systems require costly key management systems and revocation processes for authenticating postage indicia, which add complexity and expense to the verification process.

Innovation Solution

Implementing an identity-based encryption scheme where a key generating authority provides a private key to the Postal Security Device, allowing the verification service to authenticate indicia using public information included in the indicium, eliminating the need for certificates and extensive key management systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional public key infrastructure with certificates is used for authenticating postage indicia, then security is provided through cryptographic verification, but key management complexity and costs increase significantly

Engineering Contradiction:
Improveauthentication securityVSAvoidkey management system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the certificate management burden from the system by using identity-based encryption where the public key is directly derived from identifiable attributes (PSD ID, serial number, register values) rather than requiring separate certificate issuance, storage, and validation infrastructure. This eliminates the need for complex certificate authority systems while maintaining cryptographic security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The public key in this system serves multiple functions simultaneously: it acts as both the cryptographic verification key and the identifier for the postage security device. The public key is constructed from the PSD's identifiable attributes, combining authentication and identification functions into a single universal mechanism that reduces system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If certificate-based authentication is implemented, then indicia can be verified as authentic, but the system requires extensive infrastructure for certificate distribution and management

Engineering Contradiction:
Improveindicia verificationVSAvoidsystem implementation ease
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The system enables self-service authentication where the verification of indicia authenticity is performed directly by the postal service using the public key derived from the indicia's embedded identifier. The indicia itself contains all necessary information (PSD ID, serial number, register values) to generate the public key, eliminating the need for external certificate distribution and management infrastructure.

Inventive Principle:
Principle #25Self-service

3Reliability

If private keys are stored in Postal Security Devices for generating digital signatures, then indicia authentication is enabled, but potential exposure and security risks increase over time

Engineering Contradiction:
Improvedigital signature capabilityVSAvoidkey validity duration
Core Design Contradiction:
ReliabilityVSDuration of action of stationary object

Solution Approach 1:

The system implements periodic key regeneration by allowing the private key to be routinely updated in the Postal Security Device. Each update generates a new private key and corresponding public key, creating periodic cycles of key validity. This limits the exposure window for any single private key while maintaining continuous authentication capability through the updated keys.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The system changes the cryptographic parameters by regenerating the private key with new random values and updating the corresponding public key derived from the PSD's identifiable attributes. This parameter change approach allows the system to maintain security by periodically altering the cryptographic keys while preserving the underlying identity-based authentication mechanism.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8676715B2System and method for authenticating indicia using identity-based signature scheme
Publication Date: 2014.03.18 PITNEY BOWERS INC
  • US8676715B2 patent drawing
  • US8676715B2 patent drawing
  • US8676715B2 patent drawing

AI summary

Methods and systems for verification of indicia that do not require key management systems, and in which revocation of key pairs is easily performed without adding costs to the verification process are provided. Indicia are generated and authenticated utilizing an identity-based encryption (IBE) scheme. A key generating authority generates a private key for a PSD, distributes the private key securely to the PSD, and provides public information for use by a verification service when verifying cryptographic digital signatures generated with the private key. The corresponding public key is a string consisting of PSD information that is provided as part of the indicium. The verification service can verify the signature of each indicium by obtaining the public key string from the indicium, and utilizing the key generating authority's public information.