Non-hierarchical PKI for User Key Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Public Key Infrastructure (PKI) systems face challenges in securely managing public keys for large numbers of users, particularly in ensuring key validity and scalability, as centralized Certification Authorities are inefficient and costly for individual users.
Innovation Solution
A three-level Public Key Infrastructure (PKI) 2.0 architecture is proposed, featuring a hierarchical structure for server certificates, internal hierarchies for Registration Authorities, and a non-hierarchical user-centric model for individual citizens/consumers, utilizing Electronic Notaries for self-signed public key certificates and opaque ownership certificates.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a hierarchical architecture with centralized Certification Authorities is used, then security and key validation are ensured, but cost and complexity increase significantly for individual users
Solution Approach 1:
The patent segments the hierarchical PKI structure into three distinct levels: recognized hierarchical IGCP for server certificates, internal hierarchical IGCP for Registration Authorities, and non-hierarchical user IGCP for individual citizens. This segmentation allows each level to operate with appropriate complexity, eliminating the need for individual users to interact with the complex centralized CA infrastructure while maintaining security through the hierarchical framework.
Solution Approach 2:
The patent introduces Registration Authorities as intermediary entities between individual users and the centralized Certification Authorities. These RAs manage public keys for large groups of users (employees, students, citizens) and handle the complexity of key validation and distribution, allowing individual users to benefit from secure key management without directly interacting with the complex hierarchical infrastructure.
2Reliability
If centralized Certification Authorities manage public keys for large numbers of users, then security is maintained, but scalability and cost-effectiveness deteriorate
Solution Approach 1:
The patent divides the user population into different segments managed by different IGCP levels. Individual citizens use the non-hierarchical user IGCP, while large groups (employees, students, citizens) use internal hierarchical IGCPs managed by Registration Authorities. This segmentation enables scalable key management where each segment can be managed independently with appropriate resources, avoiding the scalability limitations of a single centralized CA.
Solution Approach 2:
The patent employs multiple Certification Authorities at different levels (recognized CAs for server certificates, internal CAs for Registration Authorities, and self-signed certificates for users). This replication of trust anchors across multiple entities enables parallel processing of key validation operations and distributes the scalability burden across many smaller entities rather than relying on a single centralized CA.
3Reliability
If individual users obtain public key certificates from recognized Certification Authorities, then key validity is guaranteed, but annual certification fees and costs increase
Solution Approach 1:
The patent segments the certificate issuance process into different pathways: recognized CAs issue certificates for server certificates with full validation, internal CAs issue certificates for Registration Authorities, and users issue self-signed certificates for individual use. This segmentation allows individual users to obtain valid certificates at minimal cost through the non-hierarchical user IGCP without needing to pay annual fees to recognized CAs, while still maintaining key validity through the hierarchical trust framework.
4Productivity
If a non-hierarchical user-centric model is used for individuals, then costs are reduced and scalability improved, but security and trust mechanisms become more complex
Solution Approach 1:
The patent implements a nested structure where the non-hierarchical user IGCP is contained within the broader hierarchical PKI framework. Users issue self-signed certificates that can be validated by any entity in the hierarchical system through the chain of trust to root CAs. This nesting allows the simplicity of non-hierarchical user certificates to coexist with the security of the hierarchical framework, with the hierarchical layer providing the trust mechanisms that simplify user-side operations.
Data Source
AI summary
The invention relates to a non-hierarchical infrastructure for managing twin-security keys of physical persons or of elements comprising a public key and a private key with a public key certificate, said structure not comprising any certification authority distinct from the physical persons or elements, said structure comprising at least one registering authority and its electronic notary server. There is provided at least one registering authority and its electronic notary server for a circle of trust. The registering authority comprises local registering agencies. The local registering agency establishes, after face-to-face verification of the identity of the physical person or of the identification of the element, a public key certificate, and a "public key ownership certificate", which does not contain the public key of the person or of the element but the print thereof, and which is transmitted in a secure manner to the associated electronic notary server which stores it in a secure manner. The public key ownership certificate is signed with the private key of the physical person or of the element, or else encrypted with the private key of the physical person or of the element according to an atypical use of this key in order to render it opaque with the exception of its serial number. The public key ownership certificate can be requested online on the electronic notary server to verify the authenticity of the corresponding public key certificate and the authenticity of its public key. Application to citizens, consumers and professionals and beyond this to other elements, living or otherwise, requiring secure digital exchanges.