CA2290952A1

Auto-recoverable auto-certifiable cryptosystems

Abstract

A method is provided for an escrow cryptosystem that is overhead-free, does not require a cryptographic tamper-proof hardware implementation (i.e., can be done in software), is publicly verifiable, and cannot be used subliminally to enable a shadow public key system. A shadow public key system is an unescrowed public key system that is publicly displayed in a covert fashion. The cryptosystem is overhead free since there is no additional protocol interaction between the user who generates his or her own key, and the certification authority or the escrow authorities (11, 12, 13) , in comparison to what is required to submit the public key itself in regular certified public key systems.

CA2290952A1, drawing sheet 1
Sheet 1 of 18

Term

Term ended

Projected expiry passed 21 May 2018, 8.3 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

9 claims: 8 independent, 1 dependent

  1. 1
    CA 02290952 1999-11-23 WO 98/54864 PCT/US98/10392 -37What we claim is:1. A method and apparatus comprising a cryptosystem which can be used for generating, verifying, using, and recovering cryptographic keys. Said method and apparatus is comprised of a subset of the following steps: (1) establishing a set of system parameters;
  2. 2
    (2) having the escrow authorities generate cryptographic keys and having said escrow authorities publish escrow authorities public keys;
  3. 3
    (3) having each certification authority publish unique certification authority parameters;
  4. 4
    (4) having each user generate a public/private key pair based on said system parameters using a specified user algorithm;
  5. 5
    (5) having each user generate a proof which is a proof-transcript claiming that said user’s public/private key pair was generated using said specified user algorithm and that said user's private key is recoverable by the escrow authorities;
  6. 6
    (6) having a certification authority employ verification to check that said proof is valid;
  7. 7
    (7) having a certification authority certify said user's public key and make a corresponding certificate available to the public only if proof is valid;
  8. 8
    (8) having users employ users keys and certificates in use of said cryptosystem;
  9. 9
    (9) having the escrow authorities recover the private key or information enciphered under said private key's corresponding public key, of a user when given proper authorization to do so. 2 . A method and apparatus as in Claim 1 wherein the escrow authorities are a multitude of entities and where:each entity publishes a public key;CA 02290952 1999-11-23 WO 98/54864 PCT/ÜS98/1O392 -38user key generation and recovery of user's private information can be performed using the keys of a subset of said multitude of entities. 3. A method and apparatus as in Claim 1 where parts of said proof and verification are conducted interactively between said user and said certification authority. 4. A method and apparatus as in Claim 1 wherein said user's certificate is comprised of a signature of a certification authority on a record comprising of at least a string associated with said user, and said user's public key. 5. A method and apparatus as in Claim 1 wherein said user's certificate is comprised of a signature of a certification authority on a record comprising of at least a string associated with said user, and a modification of said user's public key. 6. A method and apparatus as in Claim 1 wherein said use of said cryptosystem comprises the employment of said public/private key pairs and said certificates in said cryptosystem for the performance of any subset of the following: public key encryption/decryption, signing and digital signature verification, key exchanges, and identification protocols. 7. A method and apparatus as in Claim 1 where said user's private key or information encrypted under the public key corresponding to said user's private key is recovered in order to monitor communication of user's suspected of criminal activity while protecting the privacy of other users. CA 02290952 1999-11-23 WO 98/54864 PCT/US98/10392 8. A method and apparatus as in Claim 1 where said proper authorization is a court order given to the escrow authorities on behalf of a government agency or a court order recognized by a group of governments or agencies corresponding to a group of governments. 9. A method and apparatus as in Claim 1 wich the further step of: characterizing the user's activities as unlawful if the escrow authorities are unable to monitor the user’s communications . 10. A method and apparatus as in Claim 1 where the functionality of at least one of the escrow authorities, the user, and a certification authority, in at least one of the steps is implemented in hardware. 11. A method and apparatus as in Claim 1 where use of said user’s public key is for the encryption of files. 12 . A method and apparatus as in Claim 1 whereby the key recovery is of information between two users, user 1 and user 2, where the first subset of said escrow authorities recovers the private key or information enciphered under the public key corresponding to user l's said private key, and another subset recovers the private key or information enciphered under the public key corresponding to user 2's said private key. 13. A method and apparatus as in Claim 1 where said proof includes a transcript which is a zero-knowledge proof of knowledge of said user's private key. 14. A method and apparatus as in Claim 1 where said proof includes a transcript claiming that the escrow CA 02290952 1999-11-23 WO 98/54864 PCT/US98/10392 -40authorities are capable of recovering the private key of said user or information encrypted under said private key. 15. A method and apparatus as in Claim 1 where proper authorization is generated by following a proper process within said user's organization. 16. A method and apparatus as in Claim 1 which can be used for generating, using, verifying, and recovering cryptographic keys wherein said set of system parameters includes at least three domains Fl, F2, and F3 such that Fl is the exponent domain of F2, and F2 is the exponent domain of F3. 17. A method and apparatus as in Claim 1 which can be used for generating, using, verifying, and recovering cryptographic keys wherein said set of system parameters includes at least three domains 2r, 2q, and p such that p = 2q+l = 4r+3, where p, q, and r are prime. 18. A method and apparatus as in Claim 1 where said user's key is y, where y equals g raised to the x power modulo p, where g is a generator modulo the prime p;x is said user’s private information. 19. A method and apparatus as in Claim 1 where said user's key is based on a number n where only said user knows the factorization of n into prime numbers. 20. A method and apparatus as in Claim 1 where said user's key is a homomorphic function. 21. A method and apparatus as in Claim 1 where said proof includes encryptions using said escrow authorities public keys. CA 02290952 1999-11-23 WO 98/54864 PCI7US98/10392 22. A method and apparatus as in Claim 13 where said zero-knowledge proof of knowledge of said user's private key employs trapdoor one-way functions to generate encrypted values. 23. A method and apparatus as in Claim 14 where said transcript claiming that the escrow authorities are capable of recovering the private key of said users or information encrypted under said private key employs trapdoor one-way functions to generate encrypted values. 24. A method and apparatus as in Claim 1 where said user generates a public/private key pair based on system parameters which include said escrow authorities public keys . (2) , 25. A method and apparatus as in Claim 1 where steps (5) , (6), (9) are added to already existing steps (1) , (3) . (4) , (7) , (8) which by themselves are typical steps in an existing apparatus comprising a public key infrastructure. 26. A method and apparatus as in Claim 1 where the escrow authority recovers the private key or information enciphered under said private key's corresponding public key with the further help of the certification authority. 27. A method and apparatus as in Claim 1 with the additional steps of having a user generate a private/public pair constituting a signature key which is different from the public/private key pair of step (4) , and having a certification authority certify said public portion of said signature key. CA 02290952 1999-11-23 WO 98/54864 PCT/US98/10392 28. A method and apparatus as in claim 27 where use of said cryptosystem is for electronic mail with assured delivery. 29. A method and apparatus as in Claim 1 where the escrow authorities public key and public keys generated by users are from different key domains. 30. A method and apparatus as in Claim 1 where the escrow authorities are a multitude of elements with an extended step (2) where the escrow authorities are organized in a hierarchy where each element is able to open keys in its sub-hierarchy. 31. A method and apparatus as in Claim 1 where the escrow authorities are a multitude of elements and where said user in step (5) generates a proof that said user's private key is recoverable by a subset of escrow authorities . 32. A method and apparatus as in Claim 30 where user in step (5) generates a proof that said user's private key is recoverable by a subset of escrow authorities.