Secure Cryptographic Key Exchange via Electronic Certificate Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for exchanging cryptographic keys between a computer system and an electronic entity, such as a microcircuit card, require physical delivery and rely on network security systems, which are impractical and compromise security by involving third-party organizations.

Innovation Solution

A method involving the electronic entity sending a certificate associating an identifier with a public key, allowing secure data exchange using the secret key stored in the entity, without relying on network security systems, by encrypting or signing data with the public key and verifying the association to ensure key authenticity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic keys are exchanged physically by sending the electronic entity, then security is maintained, but practicality and ease of operation deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoidpracticality
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces the mechanical/physical delivery system with an electronic/digital system. Instead of physically transporting the electronic entity containing cryptographic keys, the invention uses electronic certificate exchange and cryptographic protocols to securely transmit key information remotely, substituting physical mechanics with electronic information processing while maintaining security through mathematical cryptography rather than physical security measures

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces certificates as an intermediary element in the key exchange process. The certificate acts as a trusted mediator that binds the electronic entity's identifier to its public key through a signature mechanism, enabling secure remote exchange without direct physical contact or reliance on network security systems, thus resolving the contradiction between physical security and remote convenience

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If network security systems are used for remote communication, then ease of operation improves, but security deteriorates due to third-party involvement

Engineering Contradiction:
Improveremote communication capabilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the security verification function from the network security system and implements it independently within the electronic entity and the exchanging parties. By using self-contained cryptographic verification through certificates and digital signatures, the invention removes dependence on third-party network security infrastructure, allowing remote communication convenience while maintaining autonomous security control without external intermediaries

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent enables the electronic entity and computer system to perform their own security verification independently. Each party uses the certificate and cryptographic signatures to self-verify the authenticity and integrity of exchanged data without requiring external security services, thus achieving both remote communication ease and security independence from third parties

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP2166728B1Verfahren zum Austausch von Daten, beispielsweise von kryptographischen Schlüsseln, zwischen einem Informationssystem und einer elektronischen Einheit, wie beispielsweise einer Mikrochip-Karte
Publication Date: 2020.12.02 IDEMIA FRANCE SAS
  • EP2166728B1 patent drawingFigure 1~2
  • EP2166728B1 patent drawingFigure 3~4
  • EP2166728B1 patent drawingFigure 5~6

AI summary

The method involves sending a certificate (CASD-CERT) associating an identifier of an electronic entity, with a public key (CASD-PK) associated with a secret key (CASD-SK) stored in the entity, from the entity towards a computer system. The association of the identifier with the public key is verified by the computer system, using the certificate. Data i.e. cryptographic keys (K1, K2, K3), are exchanged between an electronic entity application remote from a security domain, and the computer system, where the data are encoded using the public key or signed by the domain using the stored key.