Implicit certificate scheme
Abstract
A method of generating a public key in a secure digital communication system, having at least one trusted entity CA and subscriber entities A. For each entity A, the trusted entity selects a unique identity distinguishing the entity A. The trusted entity then generates a public key reconstruction public data of the entity A by mathematically combining public values obtained from respective private values of the trusted entity and the entity A. The unique identity and public key reconstruction public data of the entity A serve as A's implicit certificate. The trusted entity combines the implicit certificate information with a mathematical function to derive an entity information ƒ and generates a value k A by binding with ƒ with private values of the trusted entity. The trusted entity transmits the value k A to the entity to permit A to generate a private key from k A , A's private value and A's implicit certificate. The entity A's public key information may be reconstructed from public information, and A's implicit certificate.
Claims
exact text as granted — not AI-modified1 . A computer implemented method of a trusted entity CA facilitating generation of a public key by a correspondent A in an electronic data communication using implicit certificates, said method comprising the steps of: a cryptographic unit of said trusted CA selecting a unique identity I A distinguishing said correspondent A; said cryptographic unit generating public key reconstruction public data γ A for said correspondent A by mathematically combining a private value of said trusted entity CA and information made public by said trusted entity CA to obtain a pair (I A , γ A ) serving as an implicit certificate for said correspondent A; said cryptographic unit generating a private key a for said correspondent A using said implicit certificate and said private value of said trusted entity CA such that said public key is computable by combining said data γ A and said private key a, wherein generating said private key a comprises generating a value ƒ being a function of said pair (I A , γ A ) including a hash of said pair (I A , γ A ), and evaluating said private key a from an equation comprising ƒ and said private value of said trusted entity CA; and said cryptographic unit providing a signature (I A , a, γ A ) to said correspondent A over a secure channel of said data communication system.
Join the waitlist — get patent alerts
Track US2014229730A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.