IP Library Granted Patent US 9,154,494
Granted Patent B2
US 9,154,494 · App. 13/856,915 · Granted Oct 6, 2015

Self-signed implicit certificates

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,154,494
App. No.
13/856,915
Granted
Oct 6, 2015
Kind
B2
Abstract

There are disclosed systems and methods for creating a self-signed implicit certificate. In one embodiment, the self-signed implicit certificate is generated and operated upon using transformations of a nature similar to the transformations used in the ECQV protocol. In such a system, a root CA or other computing device avoids having to generate an explicit self-signed certificate by instead generating a self-signed implicit certificate.

Claims (37)

1. A method of generating a first and a second private key and establishing a first and a second self-signed implicit certificate that can be operated on to obtain a first and a second corresponding public key, said method being performed by a computing device in a cryptographic system based on an underlying group of order n, said computing device having a cryptographic unit, said method comprising:

said computing device obtaining a long-term private key and a corresponding public-key reconstruction value;

said computing device obtaining a first and a second data;

said computing device operating on said public-key reconstruction value and said first data to obtain said first self-signed implicit certificate;

said computing device operating on said public-key reconstruction value and said second data to obtain said second self-signed implicit certificate;

said computing device operating on said long-term private key and said first self-signed implicit certificate to obtain said first private key; and

said computing device operating on said long-term private key and said second self-signed implicit certificate to obtain said second private key.

2. The method of claim 1 , wherein said computing device is a certification authority device that issues certificates in said cryptographic system, said first and said second data are first and second certificate data, said first and said second private key are respectively a first and a second root private key, and said first and said second public key are respectively a first and a second root public key.

3. The method of claim 2 , wherein said operating on said public-key reconstruction value and said first certificate data to obtain said first self-signed implicit certificate comprises concatenating information derived from said public-key reconstruction value with said first certificate data.

4. The method of claim 3 , wherein said information derived from said public-key reconstruction value is a compressed version of said public-key reconstruction value.

5. The method of claim 2 , wherein said first root private key is an integer of form k CA root =er CA +r (mod n), and wherein r CA is said long-term private key, e is an integer derived using a hash of said self-signed implicit certificate, and r is an integer.

6. The method of claim 5 wherein said integer r is either 0, 1, or r CA .

7. The method of claim 2 wherein said first certificate data includes validity information corresponding to said first self-signed implicit certificate.

8. The method of claim 2 further comprising said certification authority device incorporating time-sensitive information into said first certificate data, and said certification authority device updating said first self-signed implicit certificate on a periodic basis according to said time-sensitive information.

9. The method of claim 1 wherein said first public key corresponds to a first security domain and said second public key corresponds to a second security domain.

10. A device for generating a first and a second private key and establishing a first and a second self-signed implicit certificate that can be operated on to obtain a first and a second corresponding public key, said device comprising a processor coupled to memory, said processor configured to:

obtain a long-term private key and a corresponding public-key reconstruction value;

obtain a first and a second data;

operate on said public-key reconstruction value and said first data to obtain said first self-signed implicit certificate;

operate on said public-key reconstruction value and said second data to obtain said second self-signed implicit certificate;

operate on said long-term private key and said first self-signed implicit certificate to obtain said first private key; and

operate on said long-term private key and said second self-signed implicit certificate to obtain said second private key.

11. The non-transitory computer readable medium of claim 10 for use in a certification authority device that issues certificates in a cryptographic system, said first and said second data are first and second certificate data, said first and said second private key are respectively a first and a second root private key, and said first and said second public key are respectively a first and a second root public key.

12. The non-transitory computer readable medium of claim 11 , wherein said operating on said public-key reconstruction value and said first certificate data to obtain said first self-signed implicit certificate comprises concatenating information derived from said public-key reconstruction value with said first certificate data.

13. The non-transitory computer readable medium of claim 12 , wherein said information derived from said public-key reconstruction value is a compressed version of said public-key reconstruction value.

14. The non-transitory computer readable medium of claim 11 , wherein said first root private key is an integer of form k CA root =er CA +r (mod n), and wherein r CA is said long-term private key, e is an integer derived using a hash of said self-signed implicit certificate, and r is an integer.

15. The non-transitory computer readable medium of claim 14 , wherein said integer r is either 0, 1, or r CA .

16. The non-transitory computer readable medium of claim 11 , wherein said first certificate data includes validity information corresponding to said first self-signed implicit certificate.

17. The non-transitory computer readable medium of claim 11 , further comprising said certification authority device incorporating time-sensitive information into said first certificate data, and said certification authority device updating said first self-signed implicit certificate on a periodic basis according to said time-sensitive information.

18. A non-transitory computer readable medium for generating a first and a second private key and establishing a first and a second self-signed implicit certificate that can be operated on to obtain a first and a second corresponding public key, said non-transitory computer readable medium having stored thereon computer readable instructions for:

obtaining a long-term private key and a corresponding public-key reconstruction value;

obtaining a first and a second data;

operating on said public-key reconstruction value and said first data to obtain said first self-signed implicit certificate;

operating on said public-key reconstruction value and said second data to obtain said second self-signed implicit certificate;

operating on said long-term private key and said first self-signed implicit certificate to obtain said first private key; and

operating on said long-term private key and said second self-signed implicit certificate to obtain said second private key.

19. The non-transitory computer readable medium of claim 18 , wherein said first public key corresponds to a first security domain and said second public key corresponds to a second security domain.

Assignments (9)
CORRECTIVE ASSIGNMENT TO CORRECT THE ADDED PATENT NUMBER TO REMOVE PATENT NO. 8,873,407 AT PREVIOUSLY RECORDED ON REEL 64066 FRAME 1. ASSIGNOR(S) HEREBY CONFIRMS THE NUNC PRO TUNC ASSIGNMENT EFFECTIVE DATE MARCH 20, 2023. Recorded Feb 2, 2026
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 074921/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT 12817157 APPLICATION NUMBER PREVIOUSLY RECORDED AT REEL: 064015 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 5, 2023
From: OT PATENT ESCROW, LLC
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064807/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE COVER SHEET AT PAGE 50 TO REMOVE 12817157 PREVIOUSLY RECORDED ON REEL 063471 FRAME 0474. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 5, 2023
From: BLACKBERRY LIMITED
To: OT PATENT ESCROW, LLC
Reel/Frame 064806/0669 →
NUNC PRO TUNC ASSIGNMENT Recorded Jun 19, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064066/0001 →
NUNC PRO TUNC ASSIGNMENT Recorded Jun 16, 2023
From: OT PATENT ESCROW, LLC
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064015/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 27, 2023
From: BLACKBERRY LIMITED
To: OT PATENT ESCROW, LLC
Reel/Frame 063471/0474 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 2, 2019
From: CERTICOM CORP.
To: BLACKBERRY LIMITED
Reel/Frame 050610/0937 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 5, 2014
From: STRUIK, MARINUS
To: CERTICOM CORP.
Reel/Frame 033673/0893 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 14, 2013
From: CAMPAGNA, MATTHEW JOHN
To: CERTICOM CORP.
Reel/Frame 030412/0776 →