Certificate Enrolment Trust Verification via Management Network Elements

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing certificate management frameworks, such as the 3GPP CEMAF, lack a secure protocol for certificate application and management, necessitating a solution for secure certificate enrolment and management.

Innovation Solution

A communication method is introduced that involves a certificate enrolment network element verifying a certificate application network element through a management network element, using locally recorded information to establish trust and issue certificates only to trusted elements, thereby enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a certificate management framework is established without a secure verification protocol, then the framework can be implemented with basic functionality, but security protection over certificate enrolment cannot be ensured

Engineering Contradiction:
Improvesecurity protectionVSAvoidprotocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a management network element as an intermediary between the certificate enrolment network element and the certificate application network element. This mediator verifies the trustworthiness of application network elements by checking locally recorded information (such as authorization attributes or digital signatures) before allowing certificate enrolment. The intermediary approach ensures security without requiring complex direct verification protocols between all parties.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If network elements issue certificates without verifying trustworthiness, then certificate issuance is fast and simple, but untrusted elements can obtain certificates causing security risks

Engineering Contradiction:
Improvetrust verificationVSAvoidverification time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The management network element performs preliminary verification of trustworthiness by checking locally recorded information (authorization attributes, digital signatures, or other credentials) before the certificate enrolment process begins. This preliminary action filters out untrusted elements early, preventing them from obtaining certificates. The verification uses pre-stored local data rather than real-time complex authentication, reducing time overhead while ensuring reliability.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If the verification process requires additional information configuration, then comprehensive verification can be performed, but system setup becomes complex and time-consuming

Engineering Contradiction:
Improveverification completenessVSAvoidsystem setup ease
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The management network element performs self-service verification by using locally recorded information that is already stored in its database or memory. The system leverages its own pre-configured data (authorization attributes, digital signatures, or other credentials) to verify trustworthiness without requiring additional external information configuration or complex setup procedures. This self-service approach ensures complete verification while simplifying system deployment.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250279901A1Communication method and communication apparatus
Publication Date: 2025.09.04 HUAWEI TECH CO LTD
  • US20250279901A1 patent drawing
  • US20250279901A1 patent drawing
  • US20250279901A1 patent drawing

AI summary

Before a certificate application network element sends a certificate application message to a certificate enrolment network element to apply for a certificate on behalf of a first network element, initial trust is established between the certificate application network element and the certificate enrolment network element. Specifically, a management network element needs to assist in establishing the initial trust between the certificate application network element and the certificate enrolment network element. Therefore, the certificate enrolment network element issues the certificate to the first network element when determining that the certificate application network element is a trusted network element.