Quantum PKI Certificate Chains With Classical Validation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing Public Key Infrastructure (PKI) systems face challenges in ensuring the security and validity of certificates due to the potential for counterfeit certificates and the lack of robust cryptographic methods to validate certificate chains.
Innovation Solution
Implementing a Public Key Infrastructure using Quantum Computers (PKIQC) where certificates are signed with digital signature algorithms running on Quantum Computers (QCs), ensuring that only the CA's private keys are used with specialized hardware, and relying parties validate these certificates using classical computers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If quantum computers are used to generate digital signatures for certificates, then the security and trustworthiness of PKI certificates is enhanced, but the device complexity and cost increase
Solution Approach 1:
The system segments the PKI functionality by designating specific quantum computers as Certificate Authorities (Q-CAs) that perform only signature generation, while classical computers perform validation. This separation allows quantum hardware to be specialized for cryptographic key generation without requiring every node in the PKI to have quantum capabilities, thereby reducing overall system complexity while maintaining enhanced security.
Solution Approach 2:
The patent introduces quantum computers as intermediary devices that perform the trusted signature generation function. These Q-CAs act as mediators between the classical relying parties and the cryptographic operations, providing a bridge where quantum security is applied only where most needed (signature generation) while classical systems handle the rest (validation and communication).
2Reliability
If quantum computers are used for certificate signature generation, then unauthorized signature generation is prevented, but the loss of time for certificate validation increases
Solution Approach 1:
The system uses public keys as copies that can be freely distributed and stored on classical computers. These public key copies enable relying parties to perform fast validation operations without needing access to the quantum computers or the private keys. The public key acts as a verifiable copy that confirms the signature's authenticity while allowing rapid validation on classical hardware.
Solution Approach 2:
The quantum computers perform the computationally intensive signature generation operation in advance during certificate issuance. By completing this preliminary action with quantum algorithms (which can efficiently generate signatures using quantum random number generation and modular exponentiation), the subsequent validation operations on classical computers can proceed much faster, as they only need to verify the signature against the pre-extracted public key without re-performing the complex generation process.
Data Source
AI summary
The present disclosure is directed to systems, methods, and non-transitory computer-readable media for generating a first signature on a first certificate of the plurality of certificates using a first digital signature generation algorithm based on a first private key. The first signature is validated by a relying party device using a first public key in certificate chain validation. The first public key and the first private key form a first public/private key pair. A second signature is generated on a second certificate of the plurality of certificates using a second digital signature generation algorithm based on a second private key. The second signature is validated by the relying party device using a second public key in the certificate chain validation. The second public key and the second private key form a second public/private key pair. The relying party device uses a third public key in the second certificate to verify a third signature on signed data. The relying party device includes a classical computer having at least one processor that processes bits.


