WO9854864A2

Auto-recoverable auto-certifiable cryptosystems

Abstract

A method is provided for an escrow cryptosystem that is overhead-free, does not require a cryptographic tamper-proof hardware implementation (i.e., can be done in software), is publicly verifiable, and cannot be used subliminally to enable a shadow public key system. A shadow public key system is an unescrowed public key system that is publicly displayed in a covert fashion. The keys generated by the method are auto-recoverable and auto-certifiable (abbrev. ARC). The ARC Cryptosystem is based on a key generation mechanism that outputs a public/private key pair, and a certificate of proof that the key was generated according to the algorithm. Each generated public/private key pair can be verified efficient ly to be escrowed properly by anyone. The verification procedure does not use the private key. Hence, the general public has an efficient way of making sure that any given individual's private key is escrowed properly, and the trusted authorities will be able to access the private key if needed. Since the verification can be performed by anyone, there is no need for a special trusted entity, known in the art as a "trusted third party". The cryptosystem is overhead free since there is no additional protocol interact ion between the user who generates his or her own key, and the certification authority or the escrow authorities, in comparison to what is required to submit the public key itself in regular certified public key systems. Furthermore, the system is designed so that its internals can be made publicly scrutinizable (e.g., it can be distributed in source code form). This differs from any schemes which require that the escrowing device be tamper-proof hardware.

WO9854864A2, drawing sheet 1
Sheet 1 of 5

Term

No projected expiry on record.

  1. Priority and filed
  2. Published
  3. Today

32 claims: 1 independent, 31 dependent

  1. 1
    What we claim is:1. A method and apparatus comprising a crypto- system which can be used for generating, verifying, using, and recovering cryptographic keys. Said method and appara- tus is comprised of a subset of the following steps: (1) establishing a set of system parameters;(2) having the escrow authorities generate crypto- graphic keys and having said escrow authorities publish escrow authorities public keys;(3) having each certification authority publish unique certification authority parameters;(4) having each user generate a public/private key pair based on said system parameters using a speci- fied user algorithm;(5) having each user generate a proof which is a proof -transcript claiming that said user's public/private key pair was generated using said specified user algorithm and that said user ' s private key is recoverable by the escrow authorities;(6) having a certification authority employ verifica- tion to check that said proof is valid;(7) having a certification authority certify said user's public key and uiake a corresponding certif- icate available to the public only if proof is valid;(8) having users employ users keys and certificates in use of said cryptosystem;(9) having the escrow authorities recover the private key or information enciphered under said private key's corresponding public key, of a user when given proper authorization to do so.
  2. 2
    A method and apparatus as in Claim 1 wherein the escrow authorities are a multitude of entities and where:each entity publishes a public key;user key generation and recovery of user's private information can be performed using the keys of a subset of said multitude of entities.
  3. 3
    A method and apparatus as in Claim 1 where parts of said proof and verification are conducted interactively between said user and said certification authority.
  4. 4
    A method and apparatus as in Claim 1 wherein said user's certificate is comprised of a signature of a certification authority on a record comprising of at least a string associated with said user, and said user's public key.
  5. 5
    A method and apparatus as in Claim 1 wherein said user's certificate is comprised of a signature of a certification authority on a record comprising of at least a string associated with said user, and a modification of said user's public key.
  6. 6
    A method and apparatus as in Claim 1 wherein said use of said cryptosystem comprises the employment of said public/private key pairs and said certificates in said cryptosystem for the performance of any subset of the following:public key encryption/decryption, signing and digital signature verification, key exchanges, and identi- fication protocols.
  7. 7
    A method and apparatus as in Claim 1 where said user's private key or information encrypted under the public key corresponding to said user's private key is recovered in order to monitor communication of user's suspected of criminal activity while protecting the privacy of other users .
  8. 8
    A method and apparatus as in Claim 1 where said proper authorization is a court order given to the escrow authorities on behalf of a government agency or a court order recognized by a group of governments or agencies corresponding to a group of governments.
  9. 9
    A method and apparatus as in Claim 1 with the further step of :characterizing the user's activities as unlawful if the escrow authorities are unable to monitor the user's communications.
  10. 10
    A method and apparatus as in Claim 1 where the functionality of at least one of the escrow authorities, the user, and a certification authority, in at least one of the steps is implemented in hardware.
  11. 11
    A method and apparatus as in Claim 1 where use of said user's public key is for the encryption of files.
  12. 12
    A method and apparatus as in Claim 1 whereby the key recovery is of information between two users, user 1 and user 2, where the first subset of said escrow authori- ties recovers the private key or information enciphered under the public key corresponding to user l's said private key, and another subset recovers the private key or infor- mation enciphered under the public key corresponding to user 2's said private key.
  13. 13
    A method and apparatus as in Claim 1 where said proof includes a transcript which is a zero-knowledge proof of knowledge of said user's private key.
  14. 14
    A method and apparatus as in Claim 1 where said proof includes a transcript claiming that the escrow authorities are capable of recovering the private key of said user or information encrypted under said private key.
  15. 15
    A method and apparatus as in Claim 1 where proper authorization is generated by following a proper process within said user's organization.
  16. 16
    A method and apparatus as in Claim 1 which can be used for generating, using, verifying, and recovering cryptographic keys wherein said set of system parameters includes at least three domains FI, F2 , and F3 such that FI is the exponent domain of F2 , and F2 is the exponent domain of F3.
  17. 17
    A method and apparatus as in Claim 1 which can be used for generating, using, verifying, and recovering cryptographic keys wherein said set of system parameters includes at least three domains 2r, 2q, and p such that p = 2q+l = 4r+3, where p, q, and r are prime.
  18. 18
    A method and apparatus as in Claim 1 where said user's key is y, where y equals g raised to the x power modulo p, where g is a generator modulo the prime p;x is said user's private information.
  19. 19
    A method and apparatus as in Claim 1 where said user's key is based on a number n where only said user knows the factorization of n into prime numbers.
  20. 20
    A method and apparatus as in Claim 1 where said user's key is a homomorphic function.
  21. 21
    A method and apparatus as in Claim 1 where said proof includes encryptions using said escrow authorities public keys .
  22. 22
    A method and apparatus as in Claim 13 where said zero-knowledge proof of knowledge of said user's private key employs trapdoor one-way functions to generate en- crypted values .
  23. 23
    A method and apparatus as in Claim 14 where said transcript claiming that the escrow authorities are capable of recovering the private key of said users or information encrypted under said private key employs trapdoor one-way functions to generate encrypted values.
  24. 24
    A method and apparatus as in Claim 1 where said user generates a public/private key pair based on system parameters which include said escrow authorities public keys .
  25. 25
    A method and apparatus as in Claim 1 where steps (2) , (5) , (6) , (9) are added to already existing steps (1), (3), (4), (7), (8) which by themselves are typical steps in an existing apparatus comprising a public key infrastructure.
  26. 26
    A method and apparatus as in Claim 1 where the escrow authority recovers the private key or information enciphered under said private key's corresponding public key with the further help of the certification authority.
  27. 27
    A method and apparatus as in Claim 1 with the additional steps of having a user generate a private/public pair constituting a signature key which is different from the public/private key pair of step (4) , and having a certification authority certify said public portion of said signature key.
  28. 29
    A method and apparatus as in Claim 1 where the escrow authorities public key and public keys generated by users are from different key domains.
  29. 30
    A method and apparatus as in Claim 1 where the escrow authorities are a multitude of elements with an extended step (2) where the escrow authorities are orga- nized in a hierarchy where each element is able to open keys in its sub-hierarchy.
  30. 31
    A method and apparatus as in Claim 1 where the escrow authorities are a multitude of elements and where said user in step (5) generates a proof that said user's private key is recoverable by a subset of escrow authori- ties.
  31. 32
    A method and apparatus as in Claim 30 where user in step (5) generates a proof that said user's private key is recoverable by a subset of escrow authorities.
Independent claims31