Shared Private Key for Multi-Protocol Certificate Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Communication networks face challenges in secure communication across multiple protocols due to incompatible certificate formats, leading to a high need for secure memory to store multiple private keys, increasing costs and complexity.

Innovation Solution

A method where a participant uses a shared public key to generate certificates in different formats, allowing the same private key to be used across various protocols, reducing the need for separate private keys and memory requirements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a participant uses separate private keys for each certificate format to enable communication via multiple protocols, then compatibility with different protocols is improved, but the memory requirement for secure storage of private keys increases

Engineering Contradiction:
Improvecompatibility with different protocolsVSAvoidmemory requirement for private keys
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The patent merges multiple private keys into a single shared private key that can be used to generate certificates in different formats. Instead of storing separate private keys for each protocol, the system stores one shared private key that serves all certificate formats, thereby reducing memory requirements while maintaining protocol compatibility.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The shared private key serves multiple functions across different certificate formats and protocols. A single private key can generate certificates in various formats (e.g., ETSI TS 103 097, X.509) and can be used for cryptographic operations in multiple protocols, making the system universal rather than protocol-specific.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple private keys are stored in secure memory to support pseudonymous communication across different protocols, then security and protocol support are improved, but the costs for secure memory increase

Engineering Contradiction:
ImprovesecurityVSAvoidcosts for secure memory
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent combines multiple protocol-specific private keys into a single shared private key that maintains security across all protocols. This merging reduces the quantity of cryptographic material that must be stored in expensive secure memory while preserving the security requirements through the use of a single, well-protected key.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The shared private key provides universal security support across multiple protocols and certificate formats, eliminating the need for separate secure storage for each key. This multi-functionality reduces the total secure memory requirements and associated costs while maintaining the same security level.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If separate private keys are used for each certificate format, then protocol-specific security requirements are met, but the complexity of key management increases

Engineering Contradiction:
Improveprotocol-specific securityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the management of multiple private keys into the management of a single shared private key. This reduces key management complexity by eliminating the need to generate, store, and manage separate keys for each protocol, while still meeting protocol-specific security requirements through the shared key's cryptographic operations.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The shared private key provides universal support for multiple protocols and certificate formats, simplifying key management operations. A single key can be used for key generation, signing, and decryption across different protocols, reducing the operational complexity compared to managing multiple separate keys.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10050793B2Reduction of memory requirement for cryptographic keys
Publication Date: 2018.08.14 ROBERT BOSCH GMBH
  • US10050793B2 patent drawing
  • US10050793B2 patent drawing
  • US10050793B2 patent drawing

AI summary

For communication of a first participant with at least one additional participant in a communication system via multiple protocols, the protocols using at least two different certificate formats, the first participant uses different certificates with the respective certificate formats for the communication via the different protocols, the different certificates being based on a shared public key. The first participant holds a shared associated private key for the different certificates. Provision of the certificates for the first participant includes generating the public key and the associated private key, signing the public key for provision of the first certificate, and signing the public key for provision of the second certificate.