Quantum PKI Certificate Chains With Classical Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Public Key Infrastructure (PKI) systems face challenges in ensuring the security and validity of certificates due to the potential for counterfeit certificates and the lack of robust cryptographic methods to validate certificate chains.

Innovation Solution

Implementing a Public Key Infrastructure using Quantum Computers (PKIQC) where certificates are signed with digital signature algorithms running on Quantum Computers (QCs), ensuring that only the CA's private keys are used with specialized hardware, and relying parties validate these certificates using classical computers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If quantum computers are used to generate digital signatures for certificates, then the security and trustworthiness of PKI certificates is enhanced, but the device complexity and cost increase

Engineering Contradiction:
Improvesecurity and trustworthiness of PKI certificatesVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the PKI functionality by designating specific quantum computers as Certificate Authorities (Q-CAs) that perform only signature generation, while classical computers perform validation. This separation allows quantum hardware to be specialized for cryptographic key generation without requiring every node in the PKI to have quantum capabilities, thereby reducing overall system complexity while maintaining enhanced security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces quantum computers as intermediary devices that perform the trusted signature generation function. These Q-CAs act as mediators between the classical relying parties and the cryptographic operations, providing a bridge where quantum security is applied only where most needed (signature generation) while classical systems handle the rest (validation and communication).

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If quantum computers are used for certificate signature generation, then unauthorized signature generation is prevented, but the loss of time for certificate validation increases

Engineering Contradiction:
Improveprevention of unauthorized signature generationVSAvoidtime for certificate validation
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system uses public keys as copies that can be freely distributed and stored on classical computers. These public key copies enable relying parties to perform fast validation operations without needing access to the quantum computers or the private keys. The public key acts as a verifiable copy that confirms the signature's authenticity while allowing rapid validation on classical hardware.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The quantum computers perform the computationally intensive signature generation operation in advance during certificate issuance. By completing this preliminary action with quantum algorithms (which can efficiently generate signatures using quantum random number generation and modular exponentiation), the subsequent validation operations on classical computers can proceed much faster, as they only need to verify the signature against the pre-extracted public key without re-performing the complex generation process.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20260012337A1Public key infrastructure using quantum computers (PKIQC)
Publication Date: 2026.01.08 WELLS FARGO BANK NA
  • US20260012337A1 patent drawing
  • US20260012337A1 patent drawing
  • US20260012337A1 patent drawing

AI summary

The present disclosure is directed to systems, methods, and non-transitory computer-readable media for generating a first signature on a first certificate of the plurality of certificates using a first digital signature generation algorithm based on a first private key. The first signature is validated by a relying party device using a first public key in certificate chain validation. The first public key and the first private key form a first public/private key pair. A second signature is generated on a second certificate of the plurality of certificates using a second digital signature generation algorithm based on a second private key. The second signature is validated by the relying party device using a second public key in the certificate chain validation. The second public key and the second private key form a second public/private key pair. The relying party device uses a third public key in the second certificate to verify a third signature on signed data. The relying party device includes a classical computer having at least one processor that processes bits.