Certificate Authority Selection Unit for PKI Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large public key infrastructure (PKI) systems face challenges in efficiently routing Certificate Service Requests (CSRs) to the appropriate Certificate Authority (CA) across multiple administrative domains and CAs, which hinders the efficient management of digital certificates.

Innovation Solution

A method and system that utilize a certificate authority selection unit to receive CSRs, select the appropriate administrative domain based on an identifier, retrieve the end-entity's security profile, and determine the corresponding CA to process the request, thereby simplifying certificate enrollment, revocation, and renewal processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a large PKI system includes multiple administrative domains and certificate authorities to service diverse user communities, then the system's adaptability and coverage are improved, but the complexity of routing certificate service requests to the appropriate CA increases

Engineering Contradiction:
Improvesystem coverageVSAvoidrouting complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a registration authority (RA) as an intermediary component that mediates between end entities and multiple certificate authorities (CAs). The RA receives certificate service requests, determines the appropriate CA based on policies and parameters, and routes requests accordingly. This intermediary simplifies the routing complexity by centralizing the decision-making logic at the RA level, allowing the system to maintain high adaptability across multiple administrative domains without proportionally increasing overall routing complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Manufacturing precision

If manual administrative control is used to manage certificate requests across multiple domains, then policy enforcement precision is improved, but the operational time and processing speed deteriorate

Engineering Contradiction:
Improvepolicy enforcement precisionVSAvoidoperational time
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-configuring policy parameters, administrative domain definitions, and CA selection criteria in a database before certificate service requests are received. The registration authority queries these pre-established policies and automatically applies them to determine the appropriate CA for each request. This eliminates the need for manual administrative intervention during certificate processing, maintaining precise policy enforcement while dramatically reducing operational time and enabling automated high-speed processing.

Inventive Principle:
Principle #10Preliminary action

3Device complexity

If a centralized certificate authority handles all certificate service requests, then system complexity is reduced, but the adaptability to serve multiple administrative domains with different policies deteriorates

Engineering Contradiction:
Improvesystem complexityVSAvoiddomain adaptability
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent segments the certificate authority functionality into multiple independent CAs, each serving specific administrative domains or policy requirements. Instead of one centralized CA handling all requests, the system divides CA responsibilities across multiple specialized authorities. The registration authority acts as a coordinator that segments the decision-making process, selecting the appropriate CA based on the request parameters and policies. This segmentation maintains relatively simple individual CA operations while achieving high domain adaptability through the coordinated multi-CA architecture.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP2517398B1Method and system for selecting a certificate authority
Publication Date: 2015.01.21 MOTOROLA SOLUTIONS INC
  • EP2517398B1 patent drawingFigure 1
  • EP2517398B1 patent drawingFigure 2
  • EP2517398B1 patent drawingFigure 3

AI summary

A certificate authority selection unit implements a method for selecting one of a plurality of certificate authorities servicing a plurality of administrative domains in a communication system. The method includes: receiving (202), from an end-entity via an interface, a certificate service request associated with an identifier; selecting (204), based on the identifier, one of the plurality of administrative domains in the communication system, wherein the plurality of administrative domains are serviced by a plurality of certificate authorities; retrieving (206) a security profile for the end-entity; and selecting (218), based on the security profile for the end-entity, one of the plurality of certificate authorities to process the certificate service request.