Implicit Certificate Identity-Based Encryption Key Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing identity-based encryption systems lack practicality due to reliance on trusted authorities for key management and public key distribution, which limits their usability and security.
Innovation Solution
An identity-based encryption system utilizing implicit certificates issued by a certification authority, where the authority does not possess private keys, allowing recipients to construct their own private keys by combining received implicit certificates with their secret contributions and public information, enabling secure message transmission without relying on a trusted authority for key possession.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a trusted authority possesses private keys for identity-based encryption, then key management and public key distribution are simplified, but security is compromised because the authority can decrypt messages and forge signatures
Solution Approach 1:
The patent extracts the private key generation capability from the trusted authority by introducing a key generation trapdoor that only the recipient possesses. The authority issues only public information (implicit certificate) while the recipient's private key is constructed locally from secret contributions, eliminating the authority's ability to access private keys while maintaining simplified key management through the trapdoor mechanism.
Solution Approach 2:
The recipient constructs their own private key by combining the implicit certificate received from the CA with their own secret contribution and any public information related to the recipient. This self-service approach eliminates dependency on the trusted authority for key possession while maintaining security, as each recipient independently generates their private key without requiring authority access.
2Reliability
If recipients must obtain public keys from a trusted authority before encryption, then key distribution is controlled, but usability is reduced and time is consumed
Solution Approach 1:
The patent performs preliminary action by having the recipient register their identity with the CA in advance, receiving an implicit certificate that contains public key reconstruction data. This preliminary registration eliminates the need for real-time public key acquisition during message encryption, as the recipient's public key can be reconstructed from pre-issued implicit certificate information when needed.
Solution Approach 2:
The implicit certificate acts as an intermediary between the trusted authority and the recipient, containing public key reconstruction data that enables key derivation without direct authority involvement. This intermediary mechanism maintains reliable key distribution control while improving usability by eliminating the need for recipients to actively obtain public keys from the authority before encryption.
3Ease of operation
If the certification authority issues explicit certificates containing private keys, then key distribution is simplified, but security is compromised and device complexity increases
Solution Approach 1:
The patent extracts the private key information from the certificate issuance process by using a key generation trapdoor mechanism. The CA issues only public implicit certificates containing reconstruction data, while the private key is constructed by the recipient using their secret contribution and the trapdoor information, eliminating the need for the CA to possess or distribute private keys while maintaining simplified key distribution.
Solution Approach 2:
The recipient self-generates their private key by combining the implicit certificate from the CA with their own secret contribution and public information. This self-service mechanism eliminates the need for the CA to issue private keys, maintaining simplified key distribution while improving security by ensuring only the recipient possesses their private key information.
4Ease of manufacture
If recipients use randomly generated public keys as identities, then encryption is simple, but adaptability is reduced and usability is poor
Solution Approach 1:
The patent applies local quality by allowing recipients to choose their own identity parameters (such as email addresses or custom identifiers) rather than using randomly generated keys. The implicit certificate mechanism supports this by accepting user-chosen identities and generating corresponding public key reconstruction data, providing both encryption simplicity and identity flexibility simultaneously.
Solution Approach 2:
The patent enables parameter changes by allowing recipients to select their own identity parameters and public key characteristics. The implicit certificate system accommodates various identity formats and user-chosen parameters while maintaining the mathematical structure needed for encryption, thus improving adaptability without compromising encryption simplicity.
Data Source
AI summary
The invention relates to a method of generating an implicit certificate and a method of generating a private key from a public key. The method involves a method generating an implicit certificate in three phases. The public key may be an entity's identity or derived from an entity's identify. Only the owner of the public key possesses complete information to generate the corresponding private key. No authority is required to nor able to generate an entity's private key.


