Electronic Device Certificate Verification and Exception List Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is a need to verify the validity of certificates stored in electronic devices during the release stage, ensuring that only valid certificates are used for authentication.
Innovation Solution
A method and device for verifying certificates stored in electronic devices, which involves extracting certificates from files, transmitting verification requests to a certificate issuing agency, determining validity based on responses, and managing certificates through exception lists.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If certificate verification is performed during release stage, then security and reliability are improved, but device complexity and processing time increase
Solution Approach 1:
The patent performs certificate verification during the release stage before the device is deployed to production environments. This preliminary action ensures that only valid certificates are installed in the device, preventing security issues later without requiring complex runtime verification mechanisms.
Solution Approach 2:
The patent introduces an exception list as an intermediary mechanism to manage certificates that may have expired or are no longer valid according to standard verification rules. This exception list allows flexible management of certificate validity without requiring complex real-time verification of every certificate, thus balancing reliability with reduced processing complexity.
2Reliability
If all certificates are verified against issuing agency, then authentication security is improved, but processing time and energy consumption increase
Solution Approach 1:
The patent extracts and stores certificate validity information in an exception list during the release stage. This extracted information is then used for quick reference during authentication operations, avoiding the need to contact the certificate issuing agency for every authentication request. This significantly reduces processing time while maintaining security through the initial comprehensive verification.
Solution Approach 2:
The patent performs comprehensive certificate verification against the issuing agency during the release stage before deployment. This preliminary verification establishes a trusted baseline of valid certificates, eliminating the need for repeated time-consuming verification operations during production use, thus reducing ongoing processing time and energy consumption.
3Adaptability or versatility
If expired certificates are managed through exception list, then flexibility in certificate management is improved, but risk of using invalid certificates increases
Solution Approach 1:
The patent implements a feedback mechanism where the exception list is continuously updated and managed based on verification results from the certificate issuing agency. This feedback loop ensures that certificates in the exception list are properly tracked and managed, reducing security risks while maintaining the flexibility to handle edge cases where expired certificates may still be valid under specific conditions.
Data Source
AI summary
A method includes extracting a certificate from a file stored in an electronic device, transmitting a verification request for the certificate to a certificate issuing agency based on identifying that the certificate is a new certificate, determining whether a validity period of the certificate expires, based on a response from the certificate issuing agency indicating that the certificate is valid, determining whether the certificate is included in an exception list based on determining that the validity period of the certificate expires, and storing the certificate in the electronic device based on determining that the certificate is included in the exception list, where the exception list includes at least one certificate.


