Non-hierarchical PKI for User Key Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Public Key Infrastructure (PKI) systems face challenges in securely managing public keys for large numbers of users, particularly in ensuring key validity and scalability, as centralized Certification Authorities are inefficient and costly for individual users.

Innovation Solution

A three-level Public Key Infrastructure (PKI) 2.0 architecture is proposed, featuring a hierarchical structure for server certificates, internal hierarchies for Registration Authorities, and a non-hierarchical user-centric model for individual citizens/consumers, utilizing Electronic Notaries for self-signed public key certificates and opaque ownership certificates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a hierarchical architecture with centralized Certification Authorities is used, then security and key validation are ensured, but cost and complexity increase significantly for individual users

Engineering Contradiction:
Improvekey validity assuranceVSAvoidinfrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the hierarchical PKI structure into three distinct levels: recognized hierarchical IGCP for server certificates, internal hierarchical IGCP for Registration Authorities, and non-hierarchical user IGCP for individual citizens. This segmentation allows each level to operate with appropriate complexity, eliminating the need for individual users to interact with the complex centralized CA infrastructure while maintaining security through the hierarchical framework.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces Registration Authorities as intermediary entities between individual users and the centralized Certification Authorities. These RAs manage public keys for large groups of users (employees, students, citizens) and handle the complexity of key validation and distribution, allowing individual users to benefit from secure key management without directly interacting with the complex hierarchical infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If centralized Certification Authorities manage public keys for large numbers of users, then security is maintained, but scalability and cost-effectiveness deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoidscalability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent divides the user population into different segments managed by different IGCP levels. Individual citizens use the non-hierarchical user IGCP, while large groups (employees, students, citizens) use internal hierarchical IGCPs managed by Registration Authorities. This segmentation enables scalable key management where each segment can be managed independently with appropriate resources, avoiding the scalability limitations of a single centralized CA.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent employs multiple Certification Authorities at different levels (recognized CAs for server certificates, internal CAs for Registration Authorities, and self-signed certificates for users). This replication of trust anchors across multiple entities enables parallel processing of key validation operations and distributes the scalability burden across many smaller entities rather than relying on a single centralized CA.

Inventive Principle:
Principle #26Copying

3Reliability

If individual users obtain public key certificates from recognized Certification Authorities, then key validity is guaranteed, but annual certification fees and costs increase

Engineering Contradiction:
Improvekey validity guaranteeVSAvoidcost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent segments the certificate issuance process into different pathways: recognized CAs issue certificates for server certificates with full validation, internal CAs issue certificates for Registration Authorities, and users issue self-signed certificates for individual use. This segmentation allows individual users to obtain valid certificates at minimal cost through the non-hierarchical user IGCP without needing to pay annual fees to recognized CAs, while still maintaining key validity through the hierarchical trust framework.

Inventive Principle:
Principle #1Segmentation

4Productivity

If a non-hierarchical user-centric model is used for individuals, then costs are reduced and scalability improved, but security and trust mechanisms become more complex

Engineering Contradiction:
ImprovescalabilityVSAvoidtrust mechanism complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements a nested structure where the non-hierarchical user IGCP is contained within the broader hierarchical PKI framework. Users issue self-signed certificates that can be validated by any entity in the hierarchical system through the chain of trust to root CAs. This nesting allows the simplicity of non-hierarchical user certificates to coexist with the security of the hierarchical framework, with the hierarchical layer providing the trust mechanisms that simplify user-side operations.

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentEP2689552B1Non-hierarchical infrastructure for managing twin-security keys of physical persons or of elements (igcp/pki).
Publication Date: 2016.08.17 NTX RES

AI summary

The invention relates to a non-hierarchical infrastructure for managing twin-security keys of physical persons or of elements comprising a public key and a private key with a public key certificate, said structure not comprising any certification authority distinct from the physical persons or elements, said structure comprising at least one registering authority and its electronic notary server. There is provided at least one registering authority and its electronic notary server for a circle of trust. The registering authority comprises local registering agencies. The local registering agency establishes, after face-to-face verification of the identity of the physical person or of the identification of the element, a public key certificate, and a "public key ownership certificate", which does not contain the public key of the person or of the element but the print thereof, and which is transmitted in a secure manner to the associated electronic notary server which stores it in a secure manner. The public key ownership certificate is signed with the private key of the physical person or of the element, or else encrypted with the private key of the physical person or of the element according to an atypical use of this key in order to render it opaque with the exception of its serial number. The public key ownership certificate can be requested online on the electronic notary server to verify the authenticity of the corresponding public key certificate and the authenticity of its public key. Application to citizens, consumers and professionals and beyond this to other elements, living or otherwise, requiring secure digital exchanges.