IP Library › Granted Patent US 12,634,130
Granted Patent B2
US 12,634,130 · App. 18/208,627 · Granted May 19, 2026

Certificate-based encryption implemented with multiple encryption schemes

Inventors: Karim Eldefrawy (Santa Monica, CA); Nicholas Genise (Austin, TX); Rutuja Kshirsagar (Blacksburg, VA)
Assignee: SRI International
H04L9/14H04L63/045H04L9/0847
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,634,130
App. No.
18/208,627
Granted
May 19, 2026
Kind
B2
Abstract

An encryption module and the decryption module cooperate with an identity-based key generator of users in a communication system in order to use an identity-based and certificate-based construction using two or more encryption schemes. An encrypted message is communicated between users of the communication system such that the encrypted message received by the device of the user needs keys from each of the two or more encryption schemes to be able to decrypt the encrypted message. The validation module cooperates with a limited-time of validity certificate issued from a certificate authority platform to decrypt the encrypted message via the limited-time of validity certificate. The validation module allows the decryption module to decrypt the encrypted message with the limited-time of validity certificate corresponding to an identity of the user when the user is determined to be actually validated for a period of time specified for the limited-time of validity certificate. The certificate authority platform grants the users validation.

Claims (95)

1 . A certificate-based encryption apparatus, comprising:

an encryption module on a device of a first user configured to encrypt a message;

a decryption module on the device of the first user;

a validation module on the device of the first user;

where the encryption module and the decryption module are configured to cooperate with an identity-based key generator of users in a communication system in order to use an identity-based and certificate-based construction using two or more encryption schemes with an encrypted message communicated between users of the communication system such that the encrypted message received by the device of the first user needs keys from each of the two or more encryption schemes to be able to decrypt the encrypted message;

where the validation module is configured to cooperate with a limited-time of validity certificate issued from a certificate authority platform to decrypt the encrypted message via the limited-time of validity certificate, where the validation module is further configured to allow the decryption module to decrypt the encrypted message with the limited-time of validity certificate, corresponding to an identity of the first user, when the first user is verified to be within a period of time specified for the limited-time of validity certificate;

where the limited-time of validity certificate is configured to indicate a secret key of an identity-based encryption scheme tied to the identity of the first user:

where the validation module is further configured to reference the limited-time of validity certificate to confirm i) the identity of the first user tied to the secret key of the identity-based encryption scheme and ii) a current time period of validity for the limited- time of validity certificate is within a time period indicated by the limited-time of validity certificate; and

where algorithms of the encryption module, the decryption module, and the validation module are implemented in hardware electronic components, in software stored in one or more non-transitory machine-readable mediums to be executed by one or more processors, and any combination of both.

2 . The certificate-based encryption apparatus of claim 1 , where the encryption module is configured to create ciphertext, where the encryption module is configured to use an identity-based encryption scheme to encrypt the message with an identity-based encryption algorithm to produce encrypted data; and then, the encryption module is configured to perform another operation on the encrypted data such that the encryption module uses a second encryption scheme to apply a second encryption algorithm to encrypt the encrypted data in order to create the ciphertext of the encrypted message that can be transmitted onto the communication system.

3 . The certificate-based encryption apparatus of claim 2 ,

where the second encryption scheme is a public key encryption scheme and the second encryption algorithm is a public key encryption algorithm; and

where the decryption module of the device of the first user is configured to process the ciphertext of the encrypted message sent by a device of another user;

where the decryption module of the device of the first user is configured to apply a public key decryption algorithm to decrypt the ciphertext sent over the communication system to produce an intermediate decryption result, and then the decryption module is configured to perform another operation where the decryption module is configured to use the secret key of the identity-based encryption scheme to decrypt the resultant product of the encrypted message decrypted from the public key encryption scheme, in order to produce an unencrypted version of the message.

4 . The certificate-based encryption apparatus of claim 1 , where the encryption module is configured to create ciphertext, where the encryption module is configured i) to use an identity-based encryption scheme to encrypt the message with the identity-based encryption algorithm to produce the encrypted message, and then the encryption module is configured ii) to execute another operation to sample a mask value and perform a mathematical operation with the mask value on the encrypted message from the identity-based encryption scheme to produce the encrypted message as modified by the mask value;

where the encryption module is configured to apply an encryption algorithm from a second encryption scheme to the mask value to produce an intermediate encrypted result of the mask value; and

where the encryption module is configured to concatenate i) the intermediate encrypted result of the mask value from the second encryption scheme with ii) the encrypted message as modified by the mask value, to create the ciphertext that can be transmitted onto the communication system.

5 . The certificate-based encryption apparatus of claim 4 ,

where the two or more encryption schemes at least include a public key encryption scheme and the identity-based encryption scheme;

where the decryption module of the device of the first user is configured to process multiple components of ciphertext sent by a device of another user, where one component indicates the mask value itself encrypted with the public key encryption scheme, and a second component indicates the encrypted message as modified by the mask value;

where the decryption module is configured to apply a public key decryption algorithm and use a secret key of the public key encryption scheme to decrypt the intermediate encrypted result of the mask value, where the decryption module of the device of the first user is configured to undo the mathematical operation of the mask value applied to the encrypted message with the identity-based encryption scheme to produce an intermediate decrypted result of the encrypted message; and

where next the decryption module is configured to apply an identity-based decryption algorithm and use the secret key of the identity-based key encryption scheme to decrypt the encrypted message in order to produce an unencrypted version of the message.

6 . The certificate-based encryption apparatus of claim 1 ,

where the certificate authority platform is configured to grant the users validation and has the identity-based key generator,

where the certificate authority platform and the identity-based key generator are configured to act as a certificate authority that grant users of the communication system validation;

where the validation module is configured to cooperate with the limited-time of validity certificate from the certificate authority platform to decrypt the message, where the identity-based key generator is configured to use an identity-based encryption scheme to produce i) a published key to encrypt items and ii) the limited-time of validity certificate corresponding to the first user's identity; and

where the limited-time of validity certificate is configured i) to contain a secret key tied to the identity of the first user and ii) to validate the first user's right to decrypt the encrypted message, where the identity-based key generator and the validity module are configured to cooperate through the limited-time of validity certificate to designate that the first user can legitimately use the secret key of the identity-based encryption scheme to decrypt the encrypted message by the validity module checking that the limited-time of validity certificate is valid for its specified period of time for that first user.

7 . The certificate-based encryption apparatus of claim 1 , where the encryption module is configured to create ciphertext, where the encryption module is configured to encrypt the encrypted message with a symmetric key encryption algorithm from a symmetric key encryption scheme to produce the encrypted message, which is then coupled with the limited-time of validity certificate indicating when the first user can decrypt messages implemented with the secret key of an identity-based encryption scheme;

where the encryption module is configured to then perform another operation to sample a random symmetric cryptosystem key that was used to encrypt the message, and then to encrypt the random symmetric cryptosystem key with, at least, the identity- based encryption scheme; and

where the encryption module is configured to append the encryption of the symmetric cryptosystem key to the encrypted message to create the ciphertext that can be sent onto the communication system.

8 . The certificate-based encryption apparatus of claim 7 ,

where the symmetric key encryption scheme is an AES and the random symmetric cryptosystem key is an AES key;

where the decryption module is configured to process multiple components of the ciphertext, where one component is the encrypted message and a second component is an intermediate encrypted result of the AES key used to encrypt the message, appended onto the encrypted message, sent by a device of a second user;

where the decryption module is configured to i) use the secret key tied to the identity of the first user from the identity-based encryption scheme and ii) apply an identity-based decryption algorithm from the identity-based encryption scheme to decrypt the intermediate encrypted result of the AES key used to encrypt the message; and

where the decryption module is configured to then use the AES key and an AES decryption algorithm to decrypt the encrypted message.

9 . The certificate-based encryption apparatus of claim 1 ,

where the limited-time of validity certificate is configured to contain the secret key tied to the identity of the first user and the time period of when the first user is validated;

where the decryption module, the validation module, and the limited-time of validity certificate are configured to cooperate to require the need for the keys from each of the two or more encryption schemes to be able to decrypt the encrypted message, in order to make each identity-based and certificate-based construction using the two or more encryption schemes safe from an attack from a quantum computer; and

where the validation module is further configured to check to determine whether the limited-time of validity certificate is still valid, and if it is, the validation module is configured to supply the secret key of the identity-based encryption scheme to the decryption module.

10 . The certificate-based encryption apparatus of claim 1 , wherein the two or more encryption schemes that are implemented are individually quantum safe; and thus, a result of combining these two or more encryption schemes with the limited-time of validity certificate results in the certificate-based encryption apparatus being quantum safe.

11 . A method for a certificate-based encryption system, comprising:

configuring an encryption module on a device of a first user encrypt a message;

configuring the encryption module and a decryption module to cooperate with an identity-based key generator of users in a communication system in order to use an identity-based and certificate-based construction using two or more encryption schemes with an encrypted message communicated between users of the communication system such that the encrypted message received by the device of the first user needs keys from each of the two or more encryption schemes to be able to decrypt the encrypted message;

configuring a validation module on the device of the first user to cooperate with a limited-time of validity certificate issued from a certificate authority platform to decrypt the encrypted message via the limited-time of validity certificate, where the validation module is further configured to allow the decryption module to decrypt the encrypted message with the limited-time of validity certificate, corresponding to an identity of the first user, when the first user is determined to be actually validated for a period of time specified for the limited-time of validity certificate;

configuring the limited-time of validity certificate to indicate a secret key of an identity-based encryption scheme tied to an identity of the first user; and

configuring the validation module to reference the limited-time of validity certificate to confirm i) the identity of the first user tied to the secret key of the identity- based encryption scheme and ii) a current time period of validity for the limited-time of validity certificate is within a time period indicated by the limited-time of validity certificate.

12 . The method for the certificate-based encryption system of claim 11 , further comprising:

configuring the encryption module to create ciphertext, where the encryption module is configured to use an identity-based encryption scheme to encrypt the message with an identity-based encryption algorithm to produce encrypted data; and

then, the encryption module is configured to perform another operation on the encrypted data such that the encryption module uses a second encryption scheme to apply a second encryption algorithm to encrypt the encrypted data in order to create the ciphertext of the encrypted message that can be transmitted onto the communication system.

13 . The method for the certificate-based encryption system of claim 12 , further comprising:

where the second encryption scheme is a public key encryption scheme and the second encryption algorithm is a public key encryption algorithm; and

configuring the decryption module of the device of the first user to process the ciphertext of the encrypted message sent by a device of another user;

configuring the decryption module of the device of the first user to apply a public key decryption algorithm to decrypt the ciphertext sent over the communication system to produce an intermediate decryption result, and then the decryption module to perform another operation where the decryption module uses the secret key of the identity-based encryption scheme to decrypt the resultant product of the encrypted message decrypted from the public key encryption scheme, in order to produce an unencrypted version of the message.

14 . The method for the certificate-based encryption system of claim 11 , further comprising:

configuring the encryption module to create ciphertext, where the encryption module is configured i) to use an identity-based encryption scheme to encrypt the message with an identity-based encryption algorithm to produce the encrypted message, and then ii) to execute another operation to sample a mask value and to perform a mathematical operation with the mask value on the encrypted message from the identity-based encryption scheme to produce the encrypted message as modified by the mask value;

configuring the encryption module to apply an encryption algorithm from a second encryption scheme to the mask value to produce an intermediate encrypted result of the mask value; and

configuring the encryption module to concatenate i) the intermediate encrypted result of the mask value from the second encryption scheme with ii) the encrypted the message as modified by the mask value, to create the ciphertext that can be transmitted onto the communication system.

15 . The method for the certificate-based encryption system of claim 14 , further comprising:

where the two or more encryption schemes at least include a public key encryption scheme and the identity-based encryption scheme; and

configuring the decryption module of the device of the first user to process multiple components of ciphertext sent by a device of another user, where one component indicates the mask value itself encrypted with the public key encryption scheme, and a second component indicates the encrypted message as modified by the mask value;

configuring the decryption module to apply a public key decryption algorithm and use a secret key of the public key encryption scheme to decrypt the intermediate encrypted result of the mask value, where the decryption module of the device of the first user is configured to undo the mathematical operation of the mask value applied to the encrypted message with the identity-based encryption scheme to produce a result of merely the encrypted message; and

configuring the decryption module to apply an identity-based decryption algorithm and use the secret key of the identity-based key encryption scheme to decrypt the encrypted message in order to produce an unencrypted version of the message.

16 . The method for the certificate-based encryption system of claim 11 , further comprising:

configuring the certificate authority platform to grant the users validation and has the identity-based key generator;

configuring the certificate authority platform and the identity-based key generator to act as a certificate authority that grant users of the communication system validation;

configuring the validation module to cooperate with the limited-time of validity certificate from the certificate authority platform to decrypt the message, where the identity-based key generator is configured to use an identity-based encryption scheme to produce i) a published key to encrypt items and ii) the limited-time of validity certificate corresponding to the first user's identity; and

configuring the limited-time of validity certificate i) to contain a secret key tied to the identity of the first user and ii) to validate the first user's right to decrypt the encrypted message, where the identity-based key generator and the validity module are configured to cooperate through the limited-time of validity certificate to designate that the first user can legitimately use the secret key of the identity-based encryption scheme to decrypt the encrypted message by the validity module checking that the limited-time of validity certificate is valid for its specified period of time for that first user.

17 . The method for the certificate-based encryption system of claim 11 , further comprising:

configuring the encryption module to create ciphertext, where the encryption module is configured to encrypt the encrypted message with a symmetric key encryption algorithm from a symmetric key encryption scheme to produce the encrypted message, which is then coupled with the limited-time of validity certificate indicating when the first user can decrypt messages implemented with the secret key of an identity-based encryption scheme;

configuring the encryption module to then perform another operation to sample a random symmetric cryptosystem key that was used to encrypt the message, and then to encrypt the random symmetric cryptosystem key with, at least, the identity-based encryption scheme; and

configuring the encryption module to append the encryption of the symmetric cryptosystem key to the encrypted message to create the ciphertext that can be sent onto the communication system.

18 . The method for the certificate-based encryption system of claim 17 , further comprising:

where the symmetric key encryption scheme is an AES and the random symmetric cryptosystem key is an AES key;

configuring the decryption module to process multiple components of the ciphertext, where one component is the encrypted message and a second component is an intermediate encrypted result of the AES key used to encrypt the message, appended onto the encrypted message, sent by a device of a second user;

configuring the decryption module to i) use the secret key tied to the identity of the first user from the identity-based encryption scheme and ii) apply an identity- based decryption algorithm from the identity-based encryption scheme to decrypt the intermediate encrypted result of the AES key used to encrypt the message; and

configuring the decryption module is configured to then use the AES key and an AES decryption algorithm to decrypt the encrypted message.

19 . The method for the certificate-based encryption system of claim 11 , further comprising:

configuring the limited-time of validity certificate to contain the secret key tied to the identity of the first user and the time period of when the first user is validated;

configuring the decryption module, the validation module, and the limited-time of validity certificate to cooperate to require the need for the keys from each of the two or more encryption schemes to be able to decrypt the encrypted message, in order to make each identity-based and certificate-based construction using the two or more encryption schemes safe from being hacked by an attack from a quantum computer; and

configuring the validation module to check to determine whether the limited-time of validity certificate is still valid, and when so, the validation module is configured to supply the secret key of the identity-based encryption scheme to the decryption module.

20 . The method for the certificate-based encryption system of claim 11 , further comprising:

using the two or more encryption schemes that are individually quantum safe; and thus, as a result of combining these two or more encryption schemes with the limited-time of validity certificate that results in the certificate-based encryption system being quantum safe.

21 . A non-transitory computer-readable medium including executable instructions that, when executed with one or more processors, cause a computing device to perform operations as follows, comprising:

causing an encryption module and a decryption module to cooperate with an identity-based key generator of users in a communication system in order to use an identity-based and certificate-based construction using two or more encryption schemes with an encrypted message communicated between users of the communication system such that the encrypted message received by the device of a first user needs keys from each of the two or more encryption schemes to be able to decrypt the encrypted message;

causing a validation module on the device of the first user to cooperate with a limited-time of validity certificate issued from a certificate authority platform to decrypt the encrypted message via the limited-time of validity certificate, where the validation module is further configured to allow the decryption module to decrypt the encrypted message with the limited-time of validity certificate, corresponding to an identity of the first user, when the first user is determined to be actually validated for a period of time specified for the limited-time of validity certificate; and

causing the limited-time of validity certificate to indicate a secret key of an identity-based encryption scheme tied to an identity of the first user;

causing the validation module to reference the limited-time of validity certificate to confirm i) the identity of the first user tied the secret key of the identity-based encryption scheme and ii) a current time period of validity for the limited-time of validity certificate is within a time period indicated by the limited-time of validity certificate; and

causing the certificate authority platform to grant the first user's validation and use the identity-based key generator.

22 . A system, comprising:

a certificate authority platform including an identity-based key generator configured to grant users of a communication system validation to decrypt messages via a limited-time of validity certificate corresponding to that particular user's identity issued from the certificate authority platform,

where a validation module on each device of each user of the communication system is configured to allow a decryption module on a device of that user to decrypt an encrypted message with the limited-time of validity certificate when that user is validated during that time period, where the limited-time of validity certificate is configured to indicate a secret key of an identity-based encryption scheme tied to an identity of the first user; where the validation module is further configured to reference the limited-time of validity certificate to confirm i) the identity of the first user tied to the secret key of the identity-based encryption scheme and ii) a current time period of validity for the limited-time of validity certificate is within a time period indicated by the limited-time of validity certificate,

where the identity-based key generator uses an identity-based encryption scheme, where the identity-based key generator and the validation module are configured to cooperate to designate that the particular user can legitimately use an identity-based key in the limited-time of validity certificate to unencrypt during its designated time period; and thus, the identity-based key generator is configured to act as the certificate authority that grants a first user validation, where the identity-based key generator is configured to cooperate with the certificate authority platform to send each validated user the limited-time of validity certificate corresponding to that particular user's identity and the time period when that certificate is valid, where a formerly valid limited-time of validity certificate becomes invalidated after the designated time period and a formerly valid user becomes invalidated after the designated time period,

a plurality of instances of public-secret key pair generators, each resident on its own device of the users of the communication system, where the public-secret key pair generators are configured to implement a second encryption scheme, where an encryption module of the device of the first user is configured to apply aspects of both encryption schemes to ciphertext, including messages, communicated between the devices of the users of the communication system, where an instance of a secret key generated by each public-secret key pair generator is not sent or in any other way communicated to the certificate authority platform so that the certificate authority platform does not have any ability to decrypt the messages communicated between the users of the communication system, where the second encryption scheme is independent from and different than the identity-based encryption scheme,

where the validation module is configured to check whether the first user's device is valid to decrypt the encrypted message with the limited-time of validity certificate when they are validated for that time period; and

where algorithms of the identity-based key generator, the encryption module, the decryption module, the public-secret key pair generators, and the validation module are implemented in hardware electronic components, in software stored in one or more non-transitory machine-readable mediums to be executed by one or more processors, and any combination of both.

Continuity (2)
Provisional Application 63123652 · Dec 10, 2020
Related Publication 20250086321A1 · Mar 13, 2025
References Cited (11)
US 7961879B1 · Spies · 2011 [cited by examiner]
US 20050084100A1 · Spies · 2005 [cited by examiner]
US 20050246533A1 · Gentry · 2005 [cited by examiner]
US 20080148047A1 · Appenzeller · 2008 [cited by examiner]
US 20090307497A1 · Appenzeller · 2009 [cited by applicant]
US 20100257358A1 · Grajek · 2010 [cited by examiner]
US 20190156051A1 · Beier et al. · 2019 [cited by applicant]
US 20200259647A1 · Goncalves · 2020 [cited by examiner]
US 20210218561A1 · Kim · 2021 [cited by examiner]
WO 2020242614A1 · 2020 [cited by applicant]
International Search Report and Written Opinion, PCT/US2021/55759 ISA:US, Jan. 25, 2022, 21 pp. [cited by applicant]