Authentication System Dynamic CRL Management for Limited Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication systems for home electric appliances and controllers do not effectively prevent unauthorized connections due to limitations in certificate revocation list (CRL) management, particularly when device storage capacity is limited, leading to potential unauthorized access.
Innovation Solution
An authentication system that dynamically manages CRLs by transmitting only necessary CRLs to devices with limited storage capacity, ensuring that only authorized controllers are connected by verifying certificate identifiers against the CRL, and allowing devices with ample storage to hold all CRLs for comprehensive authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If all devices hold complete CRLs for comprehensive authentication, then security is improved, but devices with limited storage capacity cannot store all CRLs
Solution Approach 1:
The patent segments the CRL distribution system into two tiers: devices with sufficient storage capacity store complete CRLs locally, while devices with limited storage capacity receive CRL information through peer-to-peer transmission from other devices. This segmentation allows the system to maintain comprehensive authentication security without requiring all devices to have large storage capacities.
Solution Approach 2:
The patent introduces intermediary devices (devices with larger storage capacity) that act as CRL repositories for the network. These intermediary devices store complete CRLs and provide CRL information to devices with limited storage capacity upon request, enabling small devices to perform authentication without storing all CRLs themselves.
2Measurement precision
If CRLs are transmitted to all devices, then authentication accuracy is improved, but network bandwidth and transmission time are increased
Solution Approach 1:
The patent extracts the CRL transmission function from the traditional centralized distribution model and implements selective peer-to-peer transmission. Instead of transmitting CRLs to all devices universally, the system extracts and transmits CRL information only to devices that need it and are unable to store complete CRLs, thereby reducing unnecessary network traffic and transmission time.
Solution Approach 2:
The patent applies partial action by transmitting CRL information selectively rather than universally. Devices with limited storage capacity receive only the necessary CRL data through peer-to-peer transmission, while devices with sufficient storage capacity obtain complete CRLs through normal channels, optimizing the balance between authentication accuracy and transmission efficiency.
3Quantity of substance
If devices with limited storage do not receive CRLs, then storage requirements are reduced, but unauthorized connections cannot be detected
Solution Approach 1:
The patent implements a feedback mechanism where devices with limited storage capacity can request and receive CRL information from peer devices when needed for authentication. This feedback loop ensures that even though small devices don't store complete CRLs permanently, they can obtain necessary CRL data on-demand to detect unauthorized connections, maintaining security without requiring large storage capacity.
Data Source
AI summary
Upon receiving a new CRL, a device with a large storage capacity in an authentication system detects another device connected to a controller to which this device is connecting, and determines whether or not to transmit the new CRL depending on the magnitude of the storage capacity of the device that has been detected.


