Electronic Device Certificate Verification and Exception List Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need to verify the validity of certificates stored in electronic devices during the release stage, ensuring that only valid certificates are used for authentication.

Innovation Solution

A method and device for verifying certificates stored in electronic devices, which involves extracting certificates from files, transmitting verification requests to a certificate issuing agency, determining validity based on responses, and managing certificates through exception lists.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If certificate verification is performed during release stage, then security and reliability are improved, but device complexity and processing time increase

Engineering Contradiction:
Improvecertificate validityVSAvoidverification process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent performs certificate verification during the release stage before the device is deployed to production environments. This preliminary action ensures that only valid certificates are installed in the device, preventing security issues later without requiring complex runtime verification mechanisms.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an exception list as an intermediary mechanism to manage certificates that may have expired or are no longer valid according to standard verification rules. This exception list allows flexible management of certificate validity without requiring complex real-time verification of every certificate, thus balancing reliability with reduced processing complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If all certificates are verified against issuing agency, then authentication security is improved, but processing time and energy consumption increase

Engineering Contradiction:
Improveauthentication securityVSAvoidverification time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent extracts and stores certificate validity information in an exception list during the release stage. This extracted information is then used for quick reference during authentication operations, avoiding the need to contact the certificate issuing agency for every authentication request. This significantly reduces processing time while maintaining security through the initial comprehensive verification.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent performs comprehensive certificate verification against the issuing agency during the release stage before deployment. This preliminary verification establishes a trusted baseline of valid certificates, eliminating the need for repeated time-consuming verification operations during production use, thus reducing ongoing processing time and energy consumption.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If expired certificates are managed through exception list, then flexibility in certificate management is improved, but risk of using invalid certificates increases

Engineering Contradiction:
Improvecertificate management flexibilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements a feedback mechanism where the exception list is continuously updated and managed based on verification results from the certificate issuing agency. This feedback loop ensures that certificates in the exception list are properly tracked and managed, reducing security risks while maintaining the flexibility to handle edge cases where expired certificates may still be valid under specific conditions.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20250184159A1Electronic device and operation method for authentication
Publication Date: 2025.06.05 SAMSUNG ELECTRONICS CO LTD
  • US20250184159A1 patent drawing
  • US20250184159A1 patent drawing
  • US20250184159A1 patent drawing

AI summary

A method includes extracting a certificate from a file stored in an electronic device, transmitting a verification request for the certificate to a certificate issuing agency based on identifying that the certificate is a new certificate, determining whether a validity period of the certificate expires, based on a response from the certificate issuing agency indicating that the certificate is valid, determining whether the certificate is included in an exception list based on determining that the validity period of the certificate expires, and storing the certificate in the electronic device based on determining that the certificate is included in the exception list, where the exception list includes at least one certificate.