Single Key Generating Multiple ECQV Certificates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing implicit certificate systems, such as ECQV, face limitations in generating multiple certificates from a single public key across different certificate authorities, leading to increased registration costs and inefficiencies in provisioning credentials for secure digital communication systems.

Innovation Solution

A method and system that allow a single private key to generate multiple public key pairs by making multiple requests to various certificate authorities, using an initial registered public key or an existing implicit certificate to obtain multiple ECQV-based credentials, thereby reducing registration costs and enabling multiple private keys to be derived from a single key.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If a single public key is used to request credentials from multiple certificate authorities, then registration costs are reduced and provisioning efficiency is improved, but the ability to obtain unique certificates from different CAs is compromised

Engineering Contradiction:
Improvecredential provisioning efficiencyVSAvoidcertificate uniqueness across CAs
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent segments the credential provisioning process by allowing a single public key to be used independently with multiple certificate authorities. Each CA processes the request independently and issues a unique certificate, dividing the overall credential distribution task across multiple authoritative sources without requiring the public key to be segmented or modified.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The public key serves multiple functions by being usable across different certificate authority domains. Instead of requiring separate public keys for each CA, the same public key can universally request credentials from any number of CAs, each of which independently validates and issues certificates based on their own policies.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If multiple public key pairs are generated from a single private key, then credential diversity across domains is improved, but key management complexity increases

Engineering Contradiction:
Improvecredential diversityVSAvoidkey management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges multiple public key pairs into a single private key structure. Instead of managing separate private keys for each public key pair, the system combines them such that one private key can derive or access multiple corresponding public keys, simplifying the key management infrastructure while maintaining credential diversity across different certificate authority domains.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP2673915B2Using a single certificate request to generate credentials with multiple ECQV certificates
Publication Date: 2021.11.24 BLACKBERRY LTD
  • EP2673915B2 patent drawingFigure 1
  • EP2673915B2 patent drawingFigure 2
  • EP2673915B2 patent drawingFigure 3

AI summary

A method and apparatus are disclosed for using a single credential request (e.g., registered public key or ECQV certificate) to obtain a plurality of credentials in a secure digital communication system having a plurality of trusted certificate authority CA entities and one or more subscriber entities A. In this way, entity A can be provisioned onto multiple PKI networks by leveraging a single registered public key or implicit certificate as a credential request to one or more CA entities to obtain additional credentials, where each additional credential can be used to derive additional public key-private key pairs for the entity A.