Quantum-Signed PKI Certificates for Counterfeit Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Public Key Infrastructure (PKI) systems face challenges in ensuring the security and trustworthiness of certificates due to the potential for counterfeit certificates, as traditional cryptographic methods can be vulnerable to attacks, especially with the advent of quantum computing capabilities.

Innovation Solution

Implementing a Public Key Infrastructure using Quantum Computers (PKIQC) where certificates are signed with digital signature algorithms run on Quantum Computers (QCs), ensuring that only the Certificate Authority (CA) with access to the private keys can generate certificates, and relying parties use classical computers for verification, thereby enhancing security and trust.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional cryptographic methods are used in PKI systems, then ease of operation is maintained, but security and reliability are compromised due to vulnerability to quantum computing attacks

Engineering Contradiction:
Improvesecurity of certificatesVSAvoidcomplexity of cryptographic operations
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces traditional classical cryptographic mechanisms with quantum cryptographic mechanisms. Specifically, it uses quantum key distribution (QKD) to generate and distribute cryptographic keys, and quantum digital signatures to sign certificates. This substitution leverages quantum mechanical principles (such as superposition and entanglement) to achieve security that is fundamentally resistant to both classical and quantum computational attacks, thereby improving reliability without significantly increasing operational complexity for end users.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If quantum computers are used to sign certificates, then reliability and security are improved, but device complexity increases

Engineering Contradiction:
Improvetrustworthiness of certificatesVSAvoidcomplexity of signature generation system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the PKI system into distinct quantum and classical components. The quantum computer is dedicated solely to performing quantum digital signature operations (signing certificates), while classical computers handle certificate verification, storage, and distribution. This segmentation allows the complex quantum functionality to be isolated to a specialized device, reducing the complexity burden on the overall system and allowing each component to be optimized independently.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces quantum-generated cryptographic keys and quantum digital signatures as intermediary elements between the quantum computer and the classical PKI infrastructure. These quantum cryptographic artifacts serve as mediators that bridge the quantum and classical domains, allowing the quantum computer to enhance security without requiring classical computers to perform complex quantum operations. The intermediary quantum cryptographic protocols enable secure interaction between systems of different computational paradigms.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If quantum digital signature algorithms are implemented, then security against counterfeit certificates is improved, but productivity and processing speed may be reduced

Engineering Contradiction:
Improveprotection against counterfeit certificatesVSAvoidcertificate verification speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements preliminary action by pre-distributing quantum-generated public keys and quantum digital signature verification algorithms to all relying parties before they are needed for verification. The quantum computer pre-generates cryptographic key pairs and distributes the public keys through secure quantum channels. This preliminary setup ensures that when certificate verification is needed, relying parties already have the necessary quantum cryptographic materials cached and ready, minimizing real-time processing delays and improving verification speed.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12438707B2Public key infrastructure using quantum computers (PKIQC)
Publication Date: 2025.10.07 WELLS FARGO BANK NA
  • US12438707B2 patent drawing
  • US12438707B2 patent drawing
  • US12438707B2 patent drawing

AI summary

The present disclosure is directed to systems, methods, and non-transitory computer-readable media for generating a first signature on a first certificate of the plurality of certificates using a first digital signature generation algorithm based on a first private key. The first signature is validated by a relying party device using a first public key in certificate chain validation. The first public key and the first private key form a first public/private key pair. A second signature is generated on a second certificate of the plurality of certificates using a second digital signature generation algorithm based on a second private key. The second signature is validated by the relying party device using a second public key in the certificate chain validation. The second public key and the second private key form a second public/private key pair. The relying party device uses a third public key in the second certificate to verify a third signature on signed data. The relying party device includes a classical computer having at least one processor that processes bits.