Nova Patents
CA2846987C

Identity-based encryption system

Abstract

A system is provided that uses identity-based encryption to support secure communications. Messages from a sender to a receiver may be encrypted using the receiver's identity and public parameters that have been generated by a private key generator associated with the receiver. The private key generator associated with the receiver generates a private key for the receiver. The encrypted message may be decrypted by the receiver using the receiver's private key. The system may have multiple private key generators, each with a separate set of public parameters. Directory services may be used to provide a sender that is associated with one private key generator with appropriate public parameters to use when encrypting messages for a receiver that is associated with a different private key generator. A certification authority may be used to sign directory entries for the directory service. A clearinghouse may be used to avoid duplicative directory entries.

CA2846987C, drawing sheet 1
Sheet 1 of 12

Term

Term ended

Expired 12 November 2023, 2.9 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

4 claims: 4 independent, 0 dependent

  1. 1
    CA 02846987 2014-03-18 53075-1E CLAIMS:1. A method for using identity-based encryption to support encrypted communications in a system in which users at user equipment communicate over a communications network, wherein the system has a plurality of private key generators each of which generates private keys for a group of associated users, wherein each user's private key may be used by that user to decrypt messages for the user that have been encrypted using the user's identity and public parameters, and wherein the system includes a global private key generator having associated global public parameters, comprising: allowing a sender associated with at least one of the private key generators to use user equipment to encrypt a message for a receiver associated with at least one different one of the private key generators using the global public parameters and the receiver's identity.
  2. 2
    The method defined in claim 1 further comprising allowing the sender to use the user equipment to encrypt the message for the receiver when the user equipment is not connected to the communications network.
  3. 3
    The method defined in claim 1 further comprising allowing the sender to send the encrypted message to the receiver, wherein the message includes the public parameters of the private key generator associated with the sender.
  4. 4
    The method defined in claim 1 further comprising:allowing the sender to send the encrypted message to the receiver, wherein the encrypted message includes a request for the public parameters of the different one of the private key generators that is associated with the receiver;and using user equipment of the receiver to automatically respond to the encrypted message by providing the public parameters of the different one of the private key generators that is associated with the receiver for the sender.