EP1540875A1

Certificate-based encryption and public key infrastructure

Abstract

This record has no abstract on file.

Term

Term ended

Projected expiry passed 28 August 2023, 3.1 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

116 claims: 13 independent, 103 dependent

  1. 1
    Claims of equivalent WO 2004021638 A1 CLAIMS I claim:1. A method of sending a digital message between a sender and a recipient in a public-key encryption scheme comprising the sender, the recipient and an authorizer wherein the digital message is encrypted by the sender and decrypted by the recipient, the method comprising: (a) generating a recipient public key/ recipient private key pair;wherein the recipient private key is a secret of the recipient;(b) generating a recipient encryption key;(c) selecting a key generation secret that is a secret of the authorizer;(d) generating a recipient decryption key using at least the key generation secret and the recipient encryption key, wherein a key formed from the recipient decryption key and a key formed from the recipient encryption key are a public key/ private key pair;(e) encrypting the digital message using at least the recipient public key and the recipient encryption key to create an encrypted digital message;and (f) decrypting the encrypted digital message using at least the recipient private key and the recipient decryption key.
  2. 18
    A method of sending a digital message between a sender and a recipient in a public-key encryption scheme comprising the sender, the recipient and a plurality of authorizers, the plurality of authorizers including at least a root authorizer and n lower-level authorizers in a hierarchy between the root authorizer and the recipient, wherein n > 1 , the method comprising:(a) generating a recipient public key/ private key pair for the recipient;wherein the recipient private key is a secret of the recipient;(b) generating a recipient encryption key using identity information of at least one of the recipient's ancestors;(c) selecting a root key generation secret that is a secret of the root authorizer;(d) generating a root key generation parameter based on the root key generation secret;(e) generating a recipient decryption key such that the recipient decryption key is related to the recipient encryption key, the root key generation secret and the associated root key generation parameter;(f) encrypting the digital message using the recipient public key and a recipient encryption key to create an encrypted digital message, wherein a key formed from the recipient decryption key and a key formed from the recipient encryption key are a public key/ private key pair;and (h) decrypting the encoded digital message to recover the digital message using at least the recipient private key and the recipient decryption key.
  3. 27
    A method of generating a decryption key for an entity in an encryption system including a plurality of authorizers, the plurality of authorizers including at least a root authorizer and n lower-level authorizers in the hierarchy between the root authorizer and the entity, wherein n > 1 , the method comprising:generating a root key generation secret that is known to the root authorizer;generating a root key generation parameter based on the root key generation secret;generating a lower-level key generation secret for each of the n lower- level authorizers, wherein each lower-level key generation secret is known to its associated lower-level authorizer;generating a lower-level key generation parameter for each of the n lower-level authorizers, wherein each lower-level key generation parameter is generated using at least the lower-level key generation secret for its associated lower-level authorizer;establishing a decryption key generation schedule defining a validity period for a decryption key for the entity;generating the decryption key for the entity such that the decryption key is related to at least the root key generation secret and one or more of the lower-level key generation secrets;and providing the decryption key to the entity.
  4. 29
    A method of generating a decryption key for a recipient z in an encryption system, wherein the recipient z is π+1 levels below a root authorizer in the hierarchy, and wherein the recipient is associated with a recipient ID-tuple (IDπ, . . . , ID z(π+1) ) that includes identity information ID z(n +i) associated with the recipient and identity information ID Z/ - associated with each of n lower-level authorizers in the hierarchy between the root authorizer and the recipient, the method comprising:generating a first cyclic group G-i of elements and a second cyclic group G 2 of elements;selecting a function e capable of generating an element of the second cyclic group G 2 from two elements of the first cyclic group G-i;selecting a root generator P 0 of the first cyclic group G-i;selecting a random root key generation secret So associated with and known to the root authorizer;generating a root key generation parameter Q 0 = s 0 Po;selecting a first function capable of generating an element of the first cyclic group G-i from a first string of binary digits;selecting a second function H 2 capable of generating a second string of binary digits from an element of the second cyclic group G 2 ;generating a element P zι for each of the n lower-level authorizers, wherein P z/ = Hι(ID 1 , . . . , ID 2;) for 1 < i < n;selecting a lower-level key generation secret s z , for each of the n lower- level authorizers, wherein each lower-level key generation secret s z;is known to its associated lower-level authorizer;generating a lower-level secret element S zι for each of the n lower-level authorizers, wherein S z/ Qo, generating a lower-level key generation parameter Q 2/ for each of the n lower-level authorizers, wherein Q z;= S ZI PQ for 1 < / < n;generating a recipient element P Z ( π +i ) = rVι(ID 2 ι, . . . , ID 2(n) , lnf (n+1 ) associated with the recipient, wherein P 2(n+ i) is an element of the first cyclic group G- \ and wherein lnf (n+ i ) is a string of binary digits ;and generating a recipient decryption key s m+ χ = S + s m P zn+\ = E H ^,- 1 ^ associated with the recipient.
  5. 36
    A method of encrypting and decrypting a digital message M communicated between a sender y and a recipient z in a hierarchical certificate-based encryption system, wherein the recipient z is n+1 levels below a root authorizer in the hierarchy, and wherein the recipient is associated with a recipient ID-tuple (ID 2 ι, . . . , ID 2(n+ i ) ) that includes identity information ID z(n+ i ) associated with the recipient and identity information ID z/ associated with each of n lower-level authorizers in the hierarchy between the root authorizer and the recipient, the method comprising:generating a recipient public key/ private key pair for the recipient;wherein the recipient private key is known to the recipient;generating a first cyclic group G-i of elements and a second cyclic group G 2 of elements;selecting a function e capable of generating an element of the second cyclic group G 2 from two elements of the first cyclic group G-i;selecting a root generator Po of the first cyclic group i;selecting a random root key generation secret s 0 associated with and known to the root authorizer;generating a root key generation parameter Q 0 = s 0 Po;selecting a first function H-i capable of generating an element of the first cyclic group i from a first string of binary digits;selecting a second function H 2 capable of generating a second string of binary digits from an element of the second cyclic group G 2 ;generating an element P z , for each of the n lower-level CAs, wherein P 2/ = H 1 (ID 1 , . . . , ID 2 ,) for 1 < i < n;selecting a lower-level key generation secret s z/ for each of the n lower- level authorizers, wherein each lower-level key generation secret s z/ is known to its associated lower-level authorizer;generating a lower-level secret element S z;- for each of the n lower-level authorizers, wherein S z , = S 2 ( / .-i) + s 2 ( / ..i)P 2;for 1 < i < n, wherein Szo= Qo', generating a lower-level key generation parameter Q zι for each of the n lower-level authorizers, wherein Q z;= s zl P 0 for 1 < i < n;generating a recipient element P 2(n+ i) = Hι(IDπ, . . . , ID Z( „), lnf( n +i)) associated with the recipient, wherein P Z ( n+ i) is an element of the first cyclic group Ϊ and wherein lnf( n+ i ) is a string of binary digits;generating a recipient secret element S z( „ +1) = S m + s zn P ∑ , + = ∑^ ^, ) ^-, associated with the recipient, wherein lnf ( n+i ) comprises a validity period for the recipient secret element;encoding the digital message to generate a ciphertext using at least the recipient public key, the root encryption parameter Q 0 and lnf( n+ ι>," and decoding the ciphertext C to recover the digital message M using at least the recipient private key, the lower-level key generation parameters Q z and the recipient secret element S Z ( n +i).
  6. 68
    A method of sending a digital message between a sender and a recipient in a public key encryption scheme comprising the sender, the recipient and a plurality of n authorizers, wherein n > 1 and wherein the recipient can decode the digital message only if the recipient possesses authorization from the authorizers, the method comprising:generating a recipient public key/ private key pair for the recipient;wherein the recipient private key is a secret of the recipient;generating a secret key s, ( 1 < i < n) for each of the authorizers, wherein each key secret key is known to its associated authorizer;generating a public key for each of the authorizers, wherein each public key is generated using at least the secret key for its associated authorizer;generating a signature for each of the authorizers by signing a string of binary digits M, with the secret key of that authorizer;encrypting the digital message to form a ciphertext using at least the recipient's public key, the strings of binary digits M, signed by the authorizers, and the public keys of the authorizers;and decrypting the ciphertext using at least the recipient's private key and the signatures generated by the authorizers.
  7. 77
    A method of sending a digital message between a sender and a recipient in a public key encryption scheme comprising the sender, the recipient and a plurality of authorizers including at least a root authorizer and n lower-level authorizers in the hierarchy between the root authorizer and the recipient, wherein n > 1 and wherein the recipient can decrypt the digital message only if the recipient possesses authorization from the authorizers, the method comprising:generating a recipient public key/ private key pair for the recipient, wherein the recipient private key is a secret of the recipient;generating a secret key s,- for the root authorizer and each of the lower level authorizers, wherein each key secret key is known to its associated authorizer;generating a public key for the root authorizer and each of the authorizers, wherein each public key is generated using at least the secret key for its associated authorizer;certifying documents each comprising the public key of each of the lower level authorizers to generate a signature, wherein the document comprising the public key of each lower level authorizer is certified by the authorizer above it in the hierarchy;certifying a document comprising the recipient public key, wherein the document is certified by the authorizer immediately above the recipient in the hierarchy;encrypting the digital message to form a ciphertext using at least the recipient's public key and the public keys of the authorizers and the document;and decrypting the ciphertext using at least the recipient's private key and the signatures generated by the authorizers.
  8. 86
    A method of encrypting and decrypting a digital message between a sender and a recipient in a public-key encryption scheme comprising the sender, the recipient and an authorizer wherein the digital message is encrypted by the sender and decrypted by the recipient, the method comprising:(a) generating a recipient public key/ recipient private key pair;wherein the recipient private key is a secret of the recipient;(b) selecting a key generation secret known to the authorizer;(c) generating a recipient decryption key associated with time period i, wherein the recipient decryption key associated with time period i is related to the key generation secret, and wherein recipient decryption keys associated with time periods earlier than i, but not the recipient decryption keys associated with time periods later than i, can be generated from the recipient decryption key associated with time period i;(d) encrypting the digital message to form a ciphertext using at least the recipient public key, the time period parameter associated with time period i or a time period parameter associated with an earlier time period, and a recipient encryption key to create an encrypted digital message;and (e) decrypting the ciphertext using at least the recipient private key and the recipient decryption key associated with time period i.
  9. 88
    A method of sending a digital message between a sender and a recipient in a public-key encryption scheme comprising the sender, a plurality of clients including the recipient, and an authorizer, wherein the digital message is encrypted by the sender and decrypted by the recipient, the method comprising:(a) generating a recipient public key/ recipient private key pair for the recipient;wherein the recipient private key is a secret of the recipient;(b) generating a unique binary string associating the recipient with a leaf node in a B-tree;(c) generating an unique binary string associated with each ancestor node of the recipient leaf node;(d) generating an encryption key for the recipient leaf node and for each of the ancestor nodes for the recipient leaf node, wherein the encryption key for each node is associated with at least the binary string associated with that node;(e) generating a master secret known to the authorizer;(f) generating a recipient decryption key associated with an ancestor node of the recipient leaf node, wherein the ancestor node is not an ancestor of a leaf node associated with a client not authorized by the authorizer, wherein the recipient decryption key is associated with at least the binary string associated with that node and the master secret, and wherein the recipient decryption key associated with an ancestor node of the recipient leaf node forms a private key/ public key pair with the encryption key associated with the ancestor node of the recipient leaf node;(g) encrypting the digital message to create an encrypted digital message using at least the recipient public key, and the encryption keys associated with the recipient leaf node and ancestor nodes of the recipient leaf node;and (h) decrypting the encrypted digital message using at least the recipient private key and the recipient decryption key associated with an ancestor node of the recipient leaf node.
  10. 103
    A method of sending a digital message between a sender and a recipient in a public-key encryption scheme comprising the sender, a plurality of clients including the recipient, and an authorizer, wherein the digital message is encrypted by the sender and decrypted by the recipient, the method comprising:(a) generating a recipient public key/ recipient private key pair for the recipient;wherein the recipient private key is a secret of the recipient;(b) generating a binary string associated with the root node of the B- tree, wherein this binary string is related to a validity period parameter defining a validity period for a decryption key for a node providing cover for the recipient leaf node;(c) generating a unique binary string associating the recipient with a leaf node in a B-tree;(c) generating an unique binary string associated with each ancestor node of the recipient leaf node with the exception of the root node, wherein this binary string is associated with the position of its associated node in the B-tree;(d) generating an encryption key for the recipient leaf node and for each of the ancestor nodes for the recipient leaf node, wherein the encryption key for each node is associated with at least the binary string associated with that node;(e) generating a first master secret and a second master secret known to the authorizer;(f) generating a decryption key for the node providing cover for the recipient leaf node, wherein the node providing cover for the recipient leaf node is not an ancestor node of a leaf node of a recipient not authorized to decrypt a message, wherein this decryption key is related to the first master secret, the second master secret x, and the binary strings associated with the node providing cover for the recipient leaf node and ancestor nodes of the node providing cover for the recipient leaf node and wherein the decryption key forms a private key/ public key pair with the encryption key associated with the node providing cover for the recipient leaf node;(g) encrypting the digital message to create an encrypted digital message using at least the recipient public key, and the encryption keys associated with the recipient leaf node and ancestor nodes of the recipient leaf node;and (h) decrypting the encrypted digital message using at least the recipient private key and the decryption key associated with the node providing cover for the for the recipient leaf node.
  11. 106
    The method claim 103, wherein the binary string associating the recipient with a leaf node in a B-tree is generated by a method comprising:choosing a binary string associated with a child of the root node of the B-tree;generating a binary string associated with each ancestor node of the recipient leaf node except for the root node and the child of the root node, wherein the binary string associated with, each ancestor node of the recipient leaf node except for the root node and the child of the root node is generated using at least the binary string associated with the parent of that node;and generating a binary string associated with recipient leaf node, wherein the binary string associated with the recipient leaf node is generated using at least the binary string of the parent of that node.
  12. 107
    The method claim 103, wherein the binary string associating the recipient with a leaf node in a B-tree is generated by a method comprising:choosing the binary string associated with each recipient leaf node;generating the binary string for the ancestor nodes of the recipient leaf node, with the exception of the root node, wherein the binary string for each ancestor node of the recipient leaf node, with the exception of the root node, is generated using at least the binary strings associated with the child nodes of that node.
  13. 108
    The method claim 103, wherein the nodes in the B-tree are associated with points on an elliptic curve or abelian variety.