Certificate Enrolment Trust Verification via Management Network Elements
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing certificate management frameworks, such as the 3GPP CEMAF, lack a secure protocol for certificate application and management, necessitating a solution for secure certificate enrolment and management.
Innovation Solution
A communication method is introduced that involves a certificate enrolment network element verifying a certificate application network element through a management network element, using locally recorded information to establish trust and issue certificates only to trusted elements, thereby enhancing security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a certificate management framework is established without a secure verification protocol, then the framework can be implemented with basic functionality, but security protection over certificate enrolment cannot be ensured
Solution Approach 1:
The patent introduces a management network element as an intermediary between the certificate enrolment network element and the certificate application network element. This mediator verifies the trustworthiness of application network elements by checking locally recorded information (such as authorization attributes or digital signatures) before allowing certificate enrolment. The intermediary approach ensures security without requiring complex direct verification protocols between all parties.
2Reliability
If network elements issue certificates without verifying trustworthiness, then certificate issuance is fast and simple, but untrusted elements can obtain certificates causing security risks
Solution Approach 1:
The management network element performs preliminary verification of trustworthiness by checking locally recorded information (authorization attributes, digital signatures, or other credentials) before the certificate enrolment process begins. This preliminary action filters out untrusted elements early, preventing them from obtaining certificates. The verification uses pre-stored local data rather than real-time complex authentication, reducing time overhead while ensuring reliability.
3Reliability
If the verification process requires additional information configuration, then comprehensive verification can be performed, but system setup becomes complex and time-consuming
Solution Approach 1:
The management network element performs self-service verification by using locally recorded information that is already stored in its database or memory. The system leverages its own pre-configured data (authorization attributes, digital signatures, or other credentials) to verify trustworthiness without requiring additional external information configuration or complex setup procedures. This self-service approach ensures complete verification while simplifying system deployment.
Data Source
AI summary
Before a certificate application network element sends a certificate application message to a certificate enrolment network element to apply for a certificate on behalf of a first network element, initial trust is established between the certificate application network element and the certificate enrolment network element. Specifically, a management network element needs to assist in establishing the initial trust between the certificate application network element and the certificate enrolment network element. Therefore, the certificate enrolment network element issues the certificate to the first network element when determining that the certificate application network element is a trusted network element.


