Digital Certificate Nullification via Overwrite Transfer
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing digital certificate systems face challenges in preventing normal digital certificates or keys from leaking out and increasing process loads for communications apparatuses dealing with unsuitable counterparts, particularly in scenarios where certificates need to be nullified.
Innovation Solution
A method and apparatus for nullifying digital certificates by transferring a certificate for nullification to the communications counterpart when determining that a normal certificate is to be nullified, which prevents leakage and reduces process loads by overwriting the normal certificate with a nullifying certificate.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a normal digital certificate is stored in a communications apparatus for authentication, then the apparatus can perform secure authentication with counterparts, but the certificate may leak out or be accessed by unauthorized parties
Solution Approach 1:
The patent segments the digital certificate into two parts: a public key portion and a private key portion. The private key is stored in a secure element (tamper-resistant storage) within the communications apparatus, while the public key is stored in a general storage area. This segmentation ensures that the sensitive private key is protected from unauthorized access while still enabling authentication functionality.
Solution Approach 2:
The patent introduces a certificate management server as an intermediary that handles certificate issuance, renewal, and revocation. The server acts as a trusted third party that manages the certificate lifecycle, allowing the communications apparatus to authenticate counterparts without exposing its private key. The server mediates all certificate-related operations, preventing direct access to sensitive credentials.
2Reliability
If the communications apparatus processes authentication requests from all counterparts, then it can maintain secure communications, but the process load increases when dealing with unsuitable or revoked certificates
Solution Approach 1:
The patent implements preliminary action by having the certificate management server pre-validate certificates before they are used for authentication. The server maintains a revocation list and validates certificates against this list before issuing authentication tokens. This preliminary validation prevents the communications apparatus from wasting processing power on already-revoked or invalid certificates, reducing the process load during actual authentication operations.
Solution Approach 2:
The patent implements feedback mechanisms where the certificate management server provides real-time information about certificate validity status to the communications apparatus. When a certificate is revoked or updated, the server notifies the apparatus, allowing it to immediately stop processing authentication requests with invalid certificates. This feedback loop prevents unnecessary processing of unsuitable counterparts.
3Duration of action of stationary object
If the digital certificate remains valid until its expiration date, then it can be used for continuous authentication, but it cannot be nullified when security issues arise or contracts are dissolved
Solution Approach 1:
The patent implements dynamic certificate management where the validity period of a digital certificate is not fixed but can be adjusted in real-time. The certificate management server can revoke, renew, or extend certificates based on changing security requirements or contract status. This dynamic approach allows the system to adapt certificate validity to current needs, enabling nullification when security issues arise while maintaining continuous validity when appropriate.
Solution Approach 2:
The certificate management server acts as an intermediary that controls the certificate lifecycle. It maintains the authority to nullify certificates at any time before their natural expiration by adding them to a revocation list. This intermediary control mechanism separates the certificate's inherent validity period from its actual usability, allowing the system to enforce nullification when security issues or contract dissolutions occur.
4Reliability
If a new digital certificate is issued to replace a nullified one, then authentication can continue, but the process becomes complex and time-consuming
Solution Approach 1:
The patent implements preliminary action by pre-generating and storing backup or alternative authentication credentials in the secure element. When a certificate needs to be nullified or renewed, the system can immediately switch to using pre-prepared alternative credentials, avoiding the need for time-consuming new certificate issuance processes. This preliminary preparation ensures authentication continuity while minimizing replacement time.
Solution Approach 2:
The patent ensures continuity of useful action by implementing seamless certificate renewal and replacement mechanisms. The certificate management server can issue new certificates without interrupting ongoing authentication operations, and the communications apparatus can transparently switch between different valid certificates. This continuous operation maintains authentication reliability while minimizing the time and complexity of certificate replacement.
Data Source
AI summary
A method of nullifying digital certificates for nullifying, by means of a communications apparatus, a digital certificate for use by a communications counterpart of the communications apparatus in authenticating includes the step of causing the communications apparatus to transfer to the communications counterpart, when determining based on a normal certificate being a valid digital certificate received from the communications counterpart or information received via a communications path based on the normal certificate that the normal certificate is to be nullified, a certificate for nullifying being a digital certificate for nullifying.


