Implicit Certificate Identity-Based Encryption Key Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing identity-based encryption systems lack practicality due to reliance on trusted authorities for key management and public key distribution, which limits their usability and security.

Innovation Solution

An identity-based encryption system utilizing implicit certificates issued by a certification authority, where the authority does not possess private keys, allowing recipients to construct their own private keys by combining received implicit certificates with their secret contributions and public information, enabling secure message transmission without relying on a trusted authority for key possession.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a trusted authority possesses private keys for identity-based encryption, then key management and public key distribution are simplified, but security is compromised because the authority can decrypt messages and forge signatures

Engineering Contradiction:
Improvekey managementVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the private key generation capability from the trusted authority by introducing a key generation trapdoor that only the recipient possesses. The authority issues only public information (implicit certificate) while the recipient's private key is constructed locally from secret contributions, eliminating the authority's ability to access private keys while maintaining simplified key management through the trapdoor mechanism.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The recipient constructs their own private key by combining the implicit certificate received from the CA with their own secret contribution and any public information related to the recipient. This self-service approach eliminates dependency on the trusted authority for key possession while maintaining security, as each recipient independently generates their private key without requiring authority access.

Inventive Principle:
Principle #25Self-service

2Reliability

If recipients must obtain public keys from a trusted authority before encryption, then key distribution is controlled, but usability is reduced and time is consumed

Engineering Contradiction:
Improvekey distribution controlVSAvoidusability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent performs preliminary action by having the recipient register their identity with the CA in advance, receiving an implicit certificate that contains public key reconstruction data. This preliminary registration eliminates the need for real-time public key acquisition during message encryption, as the recipient's public key can be reconstructed from pre-issued implicit certificate information when needed.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The implicit certificate acts as an intermediary between the trusted authority and the recipient, containing public key reconstruction data that enables key derivation without direct authority involvement. This intermediary mechanism maintains reliable key distribution control while improving usability by eliminating the need for recipients to actively obtain public keys from the authority before encryption.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If the certification authority issues explicit certificates containing private keys, then key distribution is simplified, but security is compromised and device complexity increases

Engineering Contradiction:
Improvekey distributionVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the private key information from the certificate issuance process by using a key generation trapdoor mechanism. The CA issues only public implicit certificates containing reconstruction data, while the private key is constructed by the recipient using their secret contribution and the trapdoor information, eliminating the need for the CA to possess or distribute private keys while maintaining simplified key distribution.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The recipient self-generates their private key by combining the implicit certificate from the CA with their own secret contribution and public information. This self-service mechanism eliminates the need for the CA to issue private keys, maintaining simplified key distribution while improving security by ensuring only the recipient possesses their private key information.

Inventive Principle:
Principle #25Self-service

4Ease of manufacture

If recipients use randomly generated public keys as identities, then encryption is simple, but adaptability is reduced and usability is poor

Engineering Contradiction:
Improveencryption simplicityVSAvoididentity flexibility
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent applies local quality by allowing recipients to choose their own identity parameters (such as email addresses or custom identifiers) rather than using randomly generated keys. The implicit certificate mechanism supports this by accepting user-chosen identities and generating corresponding public key reconstruction data, providing both encryption simplicity and identity flexibility simultaneously.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent enables parameter changes by allowing recipients to select their own identity parameters and public key characteristics. The implicit certificate system accommodates various identity formats and user-chosen parameters while maintaining the mathematical structure needed for encryption, thus improving adaptability without compromising encryption simplicity.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9071445B2Method and system for generating implicit certificates and applications to identity-based encryption (IBE)
Publication Date: 2015.06.30 MALIKIE INNOVATIONS LTD
  • US9071445B2 patent drawing
  • US9071445B2 patent drawing
  • US9071445B2 patent drawing

AI summary

The invention relates to a method of generating an implicit certificate and a method of generating a private key from a public key. The method involves a method generating an implicit certificate in three phases. The public key may be an entity's identity or derived from an entity's identify. Only the owner of the public key possesses complete information to generate the corresponding private key. No authority is required to nor able to generate an entity's private key.