Subscriber ID-Based Public Key Certificate Generation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional public key cryptography requires public key certificates to be issued by a third-party certification authority, which is inconvenient and costly.
Innovation Solution
A communication device and method that generates and verifies public key certificates using subscriber identification information associated with user identification information, allowing direct verification and management of public key certificates between communication devices without relying on a third-party authority.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If public key certificates are issued by a third-party certification authority, then security and trust are ensured, but the complexity and cost of the system increase
Solution Approach 1:
The patent extracts the certification authority function from the traditional PKI system and relocates it to the communication devices themselves. Each device generates and verifies certificates using its own subscriber identification information, eliminating the need for external CAs and reducing system complexity while maintaining security through mutual authentication based on extracted identification data
Solution Approach 2:
Communication devices perform self-certification by generating public key certificates using their own subscriber identification information stored in secure elements. Each device acts as its own certification authority, verifying partners through mutual authentication without requiring external services, thereby simplifying the system architecture while ensuring security
2Reliability
If public key certificates are issued by a third-party certification authority, then certificate validity is guaranteed, but the time and cost for certificate exchange increase
Solution Approach 1:
Subscriber identification information is pre-stored in secure elements during device manufacturing or initial setup. This preliminary preparation enables devices to immediately generate and verify certificates using their own identification data without requiring real-time communication with external CAs, significantly reducing certificate exchange time while maintaining validity through secure pre-stored credentials
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A communication device includes: a first subscriber identification unit that stores first subscriber identification unit identification information associated with user identification information; and a communication unit that communicates with another communication device, the other communication device comprising a second subscriber identification unit that stores second subscriber identification unit identification information associated with user identification information. The first subscriber identification unit includes: a key memory unit that records a pair of a public key certificate and a secret key, the pair being shared with the second subscriber identification unit; a public key certificate generation unit that generates, using the secret key recorded in the key memory unit, a "first public key certificate comprising the first subscriber identification unit identification information or the user identification information associated with the first subscriber identification unit identification information"; and a secret key memory unit that records a secret key paired with the first public key certificate generated by the public key certificate generation unit, and the communication unit transmits, to the other communication device, the first public key certificate generated by the public key certificate generation unit.