Public Key Sequence Authentication via Hash Chain Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing public key cryptography (PKC) methods are insecure when non-authentic parties provide compromised or outdated public keys, leading to potential unauthorized access and authentication issues.
Innovation Solution
A system and method for securely transmitting and authenticating a sequence of public keys using a computing unit to generate data sets that establish a secure relationship between keys, allowing for automated and efficient key replacement without manual intervention, using hash functions and signature values to verify key authenticity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If public keys are transmitted through manual processes or multiple communication channels, then security can be maintained through human verification, but the process becomes complex and inefficient
Solution Approach 1:
The patent introduces a certification authority (CA) as an intermediary that issues digital certificates containing public keys. This mediator enables automated secure key distribution by providing a trusted third party that vouches for the authenticity of public keys, eliminating the need for manual verification processes while maintaining security through cryptographic signatures.
Solution Approach 2:
The patent implements a feedback mechanism where receiving systems can verify the authenticity of public keys through cryptographic validation of digital certificates. This automated feedback loop allows systems to confirm key authenticity without human intervention, resolving the contradiction between security and process simplicity.
2Reliability
If public keys are updated frequently to maintain security, then security against breaking PKC is improved, but the overhead of transmitting multiple keys increases
Solution Approach 1:
The patent segments the public key information into structured digital certificates that contain the public key along with metadata such as issuer information, validity period, and cryptographic signatures. This segmentation allows for efficient transmission and verification, reducing overhead while enabling frequent updates through individual certificate replacement rather than transmitting entire key sets.
Solution Approach 2:
The patent employs preliminary action by having certification authorities pre-sign public keys with digital signatures before distribution. This pre-validation allows receiving systems to automatically verify key authenticity without requiring additional communication overhead, enabling secure frequent key updates with minimal data transmission.
3Reliability
If manual activities are used to provide public keys, then security can be verified by authorized persons, but productivity and efficiency are reduced
Solution Approach 1:
The patent enables self-service through automated cryptographic verification mechanisms where receiving systems independently validate the authenticity of public keys using digital signatures and certificate validation algorithms. This eliminates the need for manual verification by authorized persons while maintaining security, dramatically improving productivity and key transmission efficiency.
Solution Approach 2:
The patent replaces manual mechanical verification processes with automated cryptographic mechanisms. Digital signatures and certificate validation algorithms substitute human verification activities, enabling high-speed automated key distribution while maintaining or enhancing security through mathematical proof of authenticity.
Data Source
AI summary
A provider system is disclosed for providing a sequence of public keys to a receiver system, wherein each public key of the sequence is related to a private key and is applicable for a public key cryptography procedure. The provider system can include a computing unit and a sending unit. The computing unit can be configured to generate the sequence of public keys and related keys and compute a plurality of data sets, where a data set of the plurality of data sets includes a public key and a proof value. The proof values can result from applying a hash function to a following data set that includes a further public key following in the sequence. The sending unit can be configured to provide the plurality of data to a receiver system.


