Certificate-based encryption implemented with multiple encryption schemes
Inventors
Eldefrawy, Karim • Genise, Nicholas • Kshirsagar, Rutuja
Assignees
Interested in licensing this patent?
MTEC can help explore whether this patent might be available for licensing for your application.
Abstract
An encryption module and the decryption module cooperate with an identity-based key generator of users in a communication system in order to use an identity-based and certificate-based construction using two or more encryption schemes. An encrypted message is communicated between users of the communication system such that the encrypted message received by the device of the user needs keys from each of the two or more encryption schemes to be able to decrypt the encrypted message. The validation module cooperates with a limited-time of validity certificate issued from a certificate authority platform to decrypt the encrypted message via the limited-time of validity certificate. The validation module allows the decryption module to decrypt the encrypted message with the limited-time of validity certificate corresponding to an identity of the user when the user is determined to be actually validated for a period of time specified for the limited-time of validity certificate. The certificate authority platform grants the users validation.
Core Innovation
The invention relates to a quantum-safe certificate-based encryption architecture in which an encryption module on a device of a first user encrypts a message, and a decryption module and a validation module cooperate with an identity-based key generator of users in a communication system. The architecture uses an identity-based and certificate-based construction using two or more encryption schemes with an encrypted message communicated between users, and the encrypted message received by the device of the first user needs keys from each of the two or more encryption schemes to be able to decrypt the encrypted message.
A limited-time of validity certificate issued from a certificate authority platform is used to enable decryption via the limited-time of validity certificate. The validation module allows the decryption module to decrypt the encrypted message with the limited-time of validity certificate, corresponding to an identity of the first user, when the first user is verified to be within a period of time specified for the limited-time of validity certificate. The limited-time of validity certificate indicates a secret key of an identity-based encryption scheme tied to the identity of the first user and is referenced to confirm both the identity and the current time period of validity.
Variants describe ciphertext combinations that include identity-based ciphertext together with one or more additional encryption schemes, including nesting, layering, masking-related concatenated ciphertext components, and symmetric-key AES encrypted-message structures paired with identity-encrypted and optionally public-key-encrypted encrypted AES key components. The certificate authority platform cannot decrypt the messages communicated between users because it does not receive the secret key from the non-identity-based encryption scheme(s), and the algorithms of the encryption module, decryption module, and validation module are implemented in hardware electronic components and/or software stored in one or more non-transitory machine-readable mediums executed by one or more processors.
Claims Coverage
The provided excerpt includes three independent claims: an apparatus claim, a method claim, and system and medium-based claims. Across these claims, the core coverage centers on an identity-based and certificate-based construction using two or more encryption schemes where decryption requires keys from each scheme, combined with time-bounded validation using a limited-time of validity certificate that ties an identity to an identity-based secret key.
Identity-based and certificate-based construction using two or more encryption schemes with key-dependent decryption
The encryption module and the decryption module cooperate with an identity-based key generator of users in a communication system to use an identity-based and certificate-based construction using two or more encryption schemes with an encrypted message communicated between users such that the encrypted message received by the device of the first user needs keys from each of the two or more encryption schemes to be able to decrypt the encrypted message.
Time-bounded limited-time of validity certificate for enabling identity-tied decryption
The validation module cooperates with a limited-time of validity certificate issued from a certificate authority platform to decrypt the encrypted message via the limited-time of validity certificate, and the validation module allows the decryption module to decrypt the encrypted message with the limited-time of validity certificate, corresponding to an identity of the first user, when the first user is verified to be within a period of time specified for the limited-time of validity certificate.
Certificate ties identity-based secret key and validates identity plus current validity window
The limited-time of validity certificate is configured to indicate a secret key of an identity-based encryption scheme tied to the identity of the first user, and the validation module references the limited-time of validity certificate to confirm the identity of the first user tied to the secret key and that a current time period of validity for the limited-time of validity certificate is within a time period indicated by the limited-time of validity certificate.
Hardware and/or non-transitory machine-readable medium implementation
Algorithms of the encryption module, the decryption module, and the validation module are implemented in hardware electronic components, in software stored in one or more non-transitory machine-readable mediums to be executed by one or more processors, and any combination of both.
Second encryption scheme key isolation from certificate authority platform
A plurality of instances of public-secret key pair generators, each resident on its own device of the users of the communication system, implement a second encryption scheme, and an instance of a secret key generated by each public-secret key pair generator is not sent or otherwise communicated to the certificate authority platform so that the certificate authority platform does not have any ability to decrypt the messages communicated between the users of the communication system, where the second encryption scheme is independent from and different than the identity-based encryption scheme.
The independent claims collectively require an identity-based and certificate-based construction with two or more encryption schemes, where decryption needs keys from each scheme; a limited-time of validity certificate issued by a certificate authority platform that indicates an identity-tied secret key for an identity-based encryption scheme; validation that confirms the user identity binding and that a current validity time period is within the certificate’s time period; and system-level separation where the certificate authority platform cannot decrypt messages because secret keys for the non-identity-based scheme are not communicated to it, with implementations in hardware and/or non-transitory machine-readable media.
Stated Advantages
Not explicitly described in patent.
Documented Applications
Not explicitly described in patent.
Interested in licensing this patent?