Seed-Based Quantum-Safe Key Generation for Constrained Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Constrained devices face challenges in efficiently storing larger private keys required by quantum-safe algorithms due to limited memory and resource constraints, making existing asymmetric and symmetric algorithms ineffective against quantum computing threats.

Innovation Solution

Storing seeds for private keys in constrained devices and generating the keys on demand using associated logic, rather than storing the keys themselves, to reduce resource usage and enhance security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If private keys for quantum-safe algorithms are stored in constrained devices, then security is improved, but memory usage and resource consumption increase significantly

Engineering Contradiction:
ImprovesecurityVSAvoidmemory usage
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts the essential cryptographic material (seeds) from the full private key, storing only the seeds in the constrained device. The full private key is generated on-demand from these seeds when needed for cryptographic operations, eliminating the need to store large quantum-safe private keys while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent performs preliminary generation of cryptographic seeds during device provisioning or initialization, storing these compact seeds in the constrained device. This preliminary action enables subsequent on-demand generation of full private keys without requiring large storage capacity, resolving the memory constraint issue.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If private keys for quantum-safe algorithms are stored in constrained devices, then quantum-safe cryptography is enabled, but device resources and battery life are reduced

Engineering Contradiction:
Improvequantum-safe cryptography supportVSAvoidbattery life
Core Design Contradiction:
Adaptability or versatilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts and stores only the essential seed material rather than full private keys, dramatically reducing the computational burden of key management operations in constrained devices. This extraction approach enables quantum-safe cryptography while minimizing energy consumption during key generation and management.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent performs seed generation and storage as a preliminary action during device initialization, eliminating the need for frequent large-scale cryptographic operations that would consume battery power. This allows the device to maintain quantum-safe cryptography capability with minimal ongoing energy expenditure.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If existing asymmetric algorithms (RSA, ECC) are used in constrained devices, then current security standards are met, but security against quantum computing threats is compromised

Engineering Contradiction:
Improvecompatibility with existing algorithmsVSAvoidsecurity against quantum threats
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent changes the cryptographic parameter paradigm by using seed-based key generation for quantum-safe algorithms instead of traditional large private keys. This parameter change allows constrained devices to adopt quantum-resistant cryptography while maintaining operational simplicity through the use of compact seeds that can be stored and managed efficiently.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12452037B2Generating private keys for quantum-safe algorithms on constrained devices
Publication Date: 2025.10.21 DIGICERT INC
  • US12452037B2 patent drawing
  • US12452037B2 patent drawing

AI summary

A constrained device includes a processor; and memory storing program code that is configured to cause the processor to, responsive to a requirement for a private key for a function, perform operations on a plurality of seeds to obtain the private key; store the private key in the memory; and utilize the private key for the function. The program code is further configured to cause the processor to, subsequent to the function, remove the private key from the memory. The private key is for a quantum-safe algorithm. Advantageously, the present disclosure supports longer private keys for the quantum-safe algorithm, relative to existing algorithms, with limited resources in the constrained device.