Centralized Validation Service for Cryptographic Asset Uniqueness

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The expansion of wireless communication technologies like 5G increases the risk of device cloning and duplicate security credential generation across multiple manufacturers, necessitating a system to detect and prevent the use of duplicated cryptographic assets.

Innovation Solution

A system and method that utilizes a validation service to receive and evaluate cryptographic assets, determining their evaluation state using a database of public keys and implementing a disposition policy to prevent the use of duplicated keys and digital certificates, ensuring unique security credentials across devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If devices are provisioned with digital certificates in manufacturing facilities by multiple unrelated entities, then device production and deployment are facilitated, but the risk of duplicative public/private keys increases

Engineering Contradiction:
Improvedevice productionVSAvoidsecurity credential uniqueness
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The system performs preliminary validation of cryptographic assets before device deployment by checking public keys against a centralized database to detect duplicates in advance, preventing compromised devices from being deployed to the network

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

A centralized validation service acts as an intermediary between multiple manufacturing entities and the network, coordinating security credential verification across different manufacturers to ensure global uniqueness of cryptographic assets

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a centralized validation service checks all cryptographic assets across multiple manufacturers, then duplicate key detection is improved, but system complexity increases

Engineering Contradiction:
Improveduplicate key detectionVSAvoidvalidation system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The centralized validation service provides multiple functions including cryptographic asset validation, duplicate detection, disposition policy enforcement, and database management within a single system, eliminating the need for separate systems at each manufacturing entity

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If cryptographic assets are validated before device deployment, then security against cloning is improved, but deployment time increases

Engineering Contradiction:
Improvesecurity against cloningVSAvoiddeployment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Validation of cryptographic assets is performed in advance during the manufacturing process rather than at deployment time, allowing pre-validation of devices and reducing delays during actual network deployment

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The validation service automatically performs duplicate detection and disposition policy enforcement without requiring manual intervention, streamlining the validation process and reducing time overhead

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11601290B2Centralized database with provisions to prevent PKI key and security certificate duplication
Publication Date: 2023.03.07 ARRIS ENTERPRISES LLC
  • US11601290B2 patent drawing
  • US11601290B2 patent drawing
  • US11601290B2 patent drawing

AI summary

A system and method for preventing use of invalid digital certificates is disclosed. The method comprises receiving, in a validation service from a requesting entity, a cryptographic asset and a request to evaluate the cryptographic asset, the cryptographic asset uniquely assigned to one of the plurality of devices by an associated one of the commercially distinct entities, the request comprising the cryptographic asset, determining an evaluation state of the cryptographic asset at least in part from a database derived from a plurality of public keys currently assigned to the plurality of devices and previously received by the validation service, determining a disposition of the cryptographic asset according to a disposition policy associated with the determined evaluation state and the device and effecting the determined disposition of the cryptographic asset.