Attribute Certificate Key Binding for Cross-PKI Trust

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional symmetric key distribution mechanisms using asymmetric techniques face challenges in establishing trust relationships between Key Distribution Hosts (KDH) and Key Receiving Devices (KRD), particularly when they have certificates from different Certificate Authorities (CAs), and lack online revocation services, leading to insecure key management.

Innovation Solution

The use of attribute certificates and whitelists to establish a secure binding between KDH and KRD, allowing KRDs to verify their authorization for key distribution, enabling secure key distribution even when CAs are not in the same Public Key Infrastructure (PKI) domain, and managing key bindings without relying on online Certificate Revocation Lists (CRL) or Online Certificate Status Protocol (OCSP).

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional symmetric key distribution mechanisms use certificates from the same PKI domain, then trust relationship is established, but adaptability to different PKI domains is restricted

Engineering Contradiction:
Improvetrust relationshipVSAvoidPKI domain compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a binding attribute certificate as an intermediary that mediates between KRD and KDH from different PKI domains. This certificate binds the KRD's identity to the authorized KDH identity, enabling trust establishment without requiring both parties to share the same root CA, thus resolving the contradiction between reliability and adaptability

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The trust verification process is segmented into two independent parts: validation of KRD certificate by its own PKI domain and validation of binding attribute certificate by KDH. This segmentation allows each PKI domain to operate independently while still establishing mutual trust, enabling cross-domain key distribution

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If KDH manages multiple public key certificates for multiple KRDs, then key distribution to different manufacturers is enabled, but device complexity increases

Engineering Contradiction:
Improvemulti-manufacturer supportVSAvoidcertificate management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent extracts the binding relationship information from the traditional certificate validation process and places it in a separate binding attribute certificate. This allows KDH to manage a simplified whitelist of authorized KRD identities rather than maintaining complex certificate validation chains for each KRD, reducing certificate management complexity while supporting multiple manufacturers

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The binding attribute certificate serves multiple functions: it acts as authorization proof, binds KRD to specific KDH, and enables cross-PKI domain trust. This single mechanism replaces the need for KDH to manage separate certificate validation logic for different KRD manufacturers, simplifying overall system complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If online revocation services are not available, then local operation is enabled, but certificate security validation is weakened

Engineering Contradiction:
Improvelocal operationVSAvoidcertificate validation
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent performs preliminary validation of the binding attribute certificate during the key distribution initialization phase. By validating the certificate's authenticity and the KRD's inclusion in the authorized whitelist before key distribution begins, the system ensures security without requiring ongoing online revocation checks, enabling secure local operation

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20240333477A1Key management using attribute certificates (KXAC)
Publication Date: 2024.10.03 WELLS FARGO BANK NA
  • US20240333477A1 patent drawing
  • US20240333477A1 patent drawing
  • US20240333477A1 patent drawing

AI summary

The present disclosure is directed to systems, methods, and non-transitory computer-readable media including providing an attribute certificate to a Key Receiving Device (KRD). The attribute certificate indicates that the KRD is bound to a Key Dsitribution Host (KDH) for key distribution. A whitelist is provided to the KDH. The whitelist includes a list of at least one KRD bound to the KDH.