Digital Certificate Nullification via Overwrite Transfer

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing digital certificate systems face challenges in preventing normal digital certificates or keys from leaking out and increasing process loads for communications apparatuses dealing with unsuitable counterparts, particularly in scenarios where certificates need to be nullified.

Innovation Solution

A method and apparatus for nullifying digital certificates by transferring a certificate for nullification to the communications counterpart when determining that a normal certificate is to be nullified, which prevents leakage and reduces process loads by overwriting the normal certificate with a nullifying certificate.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a normal digital certificate is stored in a communications apparatus for authentication, then the apparatus can perform secure authentication with counterparts, but the certificate may leak out or be accessed by unauthorized parties

Engineering Contradiction:
Improveauthentication securityVSAvoidcertificate leakage
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the digital certificate into two parts: a public key portion and a private key portion. The private key is stored in a secure element (tamper-resistant storage) within the communications apparatus, while the public key is stored in a general storage area. This segmentation ensures that the sensitive private key is protected from unauthorized access while still enabling authentication functionality.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a certificate management server as an intermediary that handles certificate issuance, renewal, and revocation. The server acts as a trusted third party that manages the certificate lifecycle, allowing the communications apparatus to authenticate counterparts without exposing its private key. The server mediates all certificate-related operations, preventing direct access to sensitive credentials.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the communications apparatus processes authentication requests from all counterparts, then it can maintain secure communications, but the process load increases when dealing with unsuitable or revoked certificates

Engineering Contradiction:
Improveauthentication verificationVSAvoidprocess load
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements preliminary action by having the certificate management server pre-validate certificates before they are used for authentication. The server maintains a revocation list and validates certificates against this list before issuing authentication tokens. This preliminary validation prevents the communications apparatus from wasting processing power on already-revoked or invalid certificates, reducing the process load during actual authentication operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms where the certificate management server provides real-time information about certificate validity status to the communications apparatus. When a certificate is revoked or updated, the server notifies the apparatus, allowing it to immediately stop processing authentication requests with invalid certificates. This feedback loop prevents unnecessary processing of unsuitable counterparts.

Inventive Principle:
Principle #23Feedback

3Duration of action of stationary object

If the digital certificate remains valid until its expiration date, then it can be used for continuous authentication, but it cannot be nullified when security issues arise or contracts are dissolved

Engineering Contradiction:
Improvecertificate validity periodVSAvoidcertificate nullification capability
Core Design Contradiction:
Duration of action of stationary objectVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic certificate management where the validity period of a digital certificate is not fixed but can be adjusted in real-time. The certificate management server can revoke, renew, or extend certificates based on changing security requirements or contract status. This dynamic approach allows the system to adapt certificate validity to current needs, enabling nullification when security issues arise while maintaining continuous validity when appropriate.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The certificate management server acts as an intermediary that controls the certificate lifecycle. It maintains the authority to nullify certificates at any time before their natural expiration by adding them to a revocation list. This intermediary control mechanism separates the certificate's inherent validity period from its actual usability, allowing the system to enforce nullification when security issues or contract dissolutions occur.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If a new digital certificate is issued to replace a nullified one, then authentication can continue, but the process becomes complex and time-consuming

Engineering Contradiction:
Improveauthentication continuityVSAvoidcertificate replacement time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-generating and storing backup or alternative authentication credentials in the secure element. When a certificate needs to be nullified or renewed, the system can immediately switch to using pre-prepared alternative credentials, avoiding the need for time-consuming new certificate issuance processes. This preliminary preparation ensures authentication continuity while minimizing replacement time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent ensures continuity of useful action by implementing seamless certificate renewal and replacement mechanisms. The certificate management server can issue new certificates without interrupting ongoing authentication operations, and the communications apparatus can transparently switch between different valid certificates. This continuous operation maintains authentication reliability while minimizing the time and complexity of certificate replacement.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS7634654B2Method of nullifying digital certificate, apparatus for nullifying digital certificate, and system, program, and recoring medium for nullifying digital certificate
Publication Date: 2009.12.15 RICOH CO LTD
  • US7634654B2 patent drawing
  • US7634654B2 patent drawing
  • US7634654B2 patent drawing

AI summary

A method of nullifying digital certificates for nullifying, by means of a communications apparatus, a digital certificate for use by a communications counterpart of the communications apparatus in authenticating includes the step of causing the communications apparatus to transfer to the communications counterpart, when determining based on a normal certificate being a valid digital certificate received from the communications counterpart or information received via a communications path based on the normal certificate that the normal certificate is to be nullified, a certificate for nullifying being a digital certificate for nullifying.