Identifier-Based Signcryption Across Trusted Authorities
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current identifier-based signcryption schemes are inadequate for scenarios where the message sender and receiver belong to different trusted-authority domains, as they often require separate identity-based signature and encryption schemes, which can compromise security against chosen ciphertext attacks.
Innovation Solution
An identifier-based signcryption method using bilinear maps, where a first party associated with a first identifier string signcrypts data intended for a second party associated with a second identifier string, both parties being linked to different trusted authorities with distinct public and private keys, employing a process that combines signing and encryption using common master elements and derived public keys to ensure security against chosen ciphertext attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If separate identity-based signature and encryption schemes are used for different trusted-authority domains, then domain independence is achieved, but security against chosen ciphertext attacks is compromised
Solution Approach 1:
The patent merges signature and encryption into a unified signcryption scheme that operates across different trusted-authority domains. The signcryption algorithm integrates the signature generation and encryption processes, allowing messages to be simultaneously signed and encrypted using identifiers from different domains, thereby achieving both domain independence and security against chosen ciphertext attacks.
Solution Approach 2:
The signcryption scheme provides universal functionality by enabling a single algorithm to perform both signing and encryption operations across multiple trusted-authority domains. The scheme uses bilinear maps to create a multi-functional cryptographic primitive that can handle identifiers from different domains while maintaining security properties, eliminating the need for separate signature and encryption schemes.
2Adaptability or versatility
If identifier-based signcryption is implemented for different trusted-authority domains, then cross-domain communication is enabled, but computational complexity increases
Solution Approach 1:
The patent combines signature and encryption operations into a single signcryption algorithm, reducing the number of separate computational steps required. By integrating these functions, the scheme enables cross-domain communication while minimizing computational overhead compared to executing separate signature and encryption algorithms.
Solution Approach 2:
The scheme utilizes bilinear map parameters and pairing-based cryptography to optimize computational efficiency. By carefully selecting and managing cryptographic parameters such as the bilinear map groups and pairing operations, the patent achieves cross-domain signcryption with reduced computational complexity compared to traditional approaches.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
This approach provides a secure signcryption method suitable for different trusted-authority domains, ensuring the integrity and authenticity of messages while preventing chosen ciphertext attacks, and is more efficient than previous solutions.
Implementation Method 1
there exists a non-degenerate computable bilinear map p, for example, a Tate pairing or Weil pairing
Data Source
AI summary
Identifier-based signcryption methods and apparatus are disclosed both for signing and encrypting data, and for decrypting and verifying data. The signcryption methods use computable bilinear mappings and can be based, for example, on Weil or Tate pairings. A message sender associated with a first trusted authority carries out integrated signing/encryption processes to send a signed, encrypted message to an intended recipient associated with a second trusted authority. The recipient then carries out integrated decryption/verification processes to recover the original message and verify its origin.


