Subscriber ID-Based Public Key Certificate Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional public key cryptography requires public key certificates to be issued by a third-party certification authority, which is inconvenient and costly.

Innovation Solution

A communication device and method that generates and verifies public key certificates using subscriber identification information associated with user identification information, allowing direct verification and management of public key certificates between communication devices without relying on a third-party authority.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If public key certificates are issued by a third-party certification authority, then security and trust are ensured, but the complexity and cost of the system increase

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the certification authority function from the traditional PKI system and relocates it to the communication devices themselves. Each device generates and verifies certificates using its own subscriber identification information, eliminating the need for external CAs and reducing system complexity while maintaining security through mutual authentication based on extracted identification data

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Communication devices perform self-certification by generating public key certificates using their own subscriber identification information stored in secure elements. Each device acts as its own certification authority, verifying partners through mutual authentication without requiring external services, thereby simplifying the system architecture while ensuring security

Inventive Principle:
Principle #25Self-service

2Reliability

If public key certificates are issued by a third-party certification authority, then certificate validity is guaranteed, but the time and cost for certificate exchange increase

Engineering Contradiction:
Improvecertificate validityVSAvoidcertificate exchange time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Subscriber identification information is pre-stored in secure elements during device manufacturing or initial setup. This preliminary preparation enables devices to immediately generate and verify certificates using their own identification data without requiring real-time communication with external CAs, significantly reducing certificate exchange time while maintaining validity through secure pre-stored credentials

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3367607B1Communication device, communication method and computer program
Publication Date: 2021.08.25 KDDI CORP
  • EP3367607B1 patent drawingFigure 1
  • EP3367607B1 patent drawingFigure 2
  • EP3367607B1 patent drawingFigure 3

AI summary

A communication device includes: a first subscriber identification unit that stores first subscriber identification unit identification information associated with user identification information; and a communication unit that communicates with another communication device, the other communication device comprising a second subscriber identification unit that stores second subscriber identification unit identification information associated with user identification information. The first subscriber identification unit includes: a key memory unit that records a pair of a public key certificate and a secret key, the pair being shared with the second subscriber identification unit; a public key certificate generation unit that generates, using the secret key recorded in the key memory unit, a "first public key certificate comprising the first subscriber identification unit identification information or the user identification information associated with the first subscriber identification unit identification information"; and a secret key memory unit that records a secret key paired with the first public key certificate generated by the public key certificate generation unit, and the communication unit transmits, to the other communication device, the first public key certificate generated by the public key certificate generation unit.