Post-Quantum Authentication Using Trusted Third Party Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing post-quantum authentication methods using hybrid certificates increase memory usage, processing time, and power consumption, and require user devices to support both legacy and quantum-safe cryptographic protocols, making them inefficient for devices with limited resources.
Innovation Solution
A method for post-quantum resistant authentication that uses a legacy certificate and a quantum-safe cryptography certificate, where a trusted third party verifies the binding and validity of the quantum-safe certificate using an identifier from the legacy certificate, allowing user devices to authenticate service providers without performing extensive calculations or supporting quantum-safe protocols.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If hybrid certificates are used for post-quantum authentication, then quantum-safe security is improved, but certificate size increases significantly
Solution Approach 1:
The patent extracts the quantum-safe verification process from the user device and places it on a remote server. The user device only stores and verifies a small digital signature, while the server handles the computationally intensive and space-consuming quantum-safe certificate verification, thus reducing local storage requirements while maintaining quantum-safe security
Solution Approach 2:
The patent introduces a remote server as an intermediary between the user device and the quantum-safe certificate authority. This intermediary handles the complex quantum-safe verification operations, allowing the user device to remain simple with minimal storage requirements while still benefiting from quantum-safe authentication
2Reliability
If hybrid certificates are used for post-quantum authentication, then quantum-safe security is improved, but processing time increases
Solution Approach 1:
The patent extracts the time-consuming quantum-safe verification operations from the user device and relocates them to a remote server with greater computational resources, thereby reducing the verification time experienced by the user device while maintaining quantum-safe security guarantees
3Reliability
If hybrid certificates are used for post-quantum authentication, then quantum-safe security is improved, but power consumption increases
Solution Approach 1:
The patent extracts the energy-intensive quantum-safe cryptographic operations from the user device and performs them on a remote server, thereby significantly reducing the power consumption of the user device while maintaining quantum-safe security through server-side verification
4Reliability
If hybrid certificates are used for post-quantum authentication, then quantum-safe security is improved, but device complexity increases
Solution Approach 1:
The patent introduces a remote server as an intermediary that handles all quantum-safe cryptographic protocol operations, allowing the user device to remain simple and not require implementation of complex quantum-safe protocols, thus reducing device complexity while maintaining quantum-safe security
Solution Approach 2:
The patent extracts the requirement for quantum-safe protocol implementation from the user device and places it entirely on the remote server, thereby simplifying the user device architecture while maintaining quantum-safe security through server-side protocol handling
Data Source
AI summary
Provided is a method for post-quantum resistant authentication of a service provider device to a user device, using a legacy certificate of said service provider device and a quantum safe cryptography (QSC) certificate of said service provider device. The method includes verifying by a trusted third party device, using said identifier of the legacy certificate comprised in the QSC certificate, a binding of said QSC certificate to the legacy certificate of the service provider device, and verifying a validity of said QSC certificate by said trusted third party device. The binding and validity have been successfully verified by the trusted third party device, authentication of the service provider device to said user device, using said legacy certificate of the service provider device from which can be obtained said identifier comprised in the QSC certificate whose validity has been verified.


