Digital Certificate Field Transformation for Secure Authorization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing PKI-based communication systems face challenges in enhancing security after the key management protocol has been standardized, particularly when proprietary algorithms are introduced, as modifying the protocol is impractical and may require changes to the standard, which is time-consuming and difficult.

Innovation Solution

Transforming one or more fields in digital certificates with a proprietary or confidential algorithm, such as encrypting subject name attributes or the certificate signature, to ensure that unauthorized parties must implement the algorithm to validate the authenticity of the sender, thereby strengthening security without altering the standardized key management protocol.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If proprietary algorithms are introduced to enhance security after standardization, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the certificate validation process into two distinct parts: standard validation (handled by all devices per existing protocols) and proprietary algorithm validation (applied selectively to enhance security). This segmentation allows the system to incorporate proprietary security measures without requiring all devices to implement complex proprietary algorithms, thus improving security while limiting the increase in device complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies proprietary algorithms partially rather than universally. Specifically, proprietary transformations are applied to certain certificate fields (such as subject name attributes or signature fields) while leaving other fields in standard format. This partial application provides enhanced security where needed while maintaining compatibility and reducing the overall complexity burden on devices.

Inventive Principle:
Principle #16Partial or excessive action

2Reliability

If proprietary algorithms are introduced to enhance security, then security is improved, but compatibility with existing standards deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidcompatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments certificate fields into standard fields and proprietary fields. Standard fields maintain existing formats for compatibility, while proprietary fields apply transformations only where needed for security enhancement. This segmentation ensures that existing standards-compliant devices can still process standard fields, while enhanced security is provided through proprietary fields.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent uses standard certificate structures and formats as intermediaries between proprietary security mechanisms and existing standardized systems. By maintaining standard field formats and using standard validation processes for non-proprietary fields, the system acts as an intermediary that allows proprietary algorithms to enhance security without breaking compatibility with existing standards-based infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If proprietary algorithms are introduced to enhance security, then enforcement mechanisms are improved, but ease of operation deteriorates

Engineering Contradiction:
Improveenforcement mechanismsVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies proprietary algorithms partially to specific certificate fields rather than requiring complete proprietary implementation. Devices only need to implement proprietary validation for the specific transformed fields (such as subject name or signature fields) while using standard validation for other fields, reducing the operational burden while maintaining enhanced security enforcement.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent enables receiving devices to automatically detect whether certificate fields have been transformed using proprietary algorithms and apply appropriate validation methods. The system self-adapts by checking for proprietary transformations and applying the corresponding validation logic without requiring manual configuration, thus maintaining ease of operation while enforcing enhanced security.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8321663B2Enhanced authorization process using digital signatures
Publication Date: 2012.11.27 GOOGLE TECHNOLOGY HOLDINGS LLC
  • US8321663B2 patent drawing
  • US8321663B2 patent drawing
  • US8321663B2 patent drawing

AI summary

A method is provided for enhancing security of a communication session between first and second endpoints which employs a key management protocol. The method includes sending a first message to a first end point over a communications network requesting a secure communication session therewith. The message includes an identity of a second end point requesting the authenticated communication session. A digital certificate is received from the first endpoint over the communications network. The digital certificate is issued by a certifying source verifying information contained in the digital certificate. The digital certificate includes a plurality of fields, one or more of which are transformed in accordance with a transformation algorithm. A reverse transform is applied to the one or more transformed fields to obtain the one or more fields. The digital certificate is validated and a second message is sent to the first endpoint indicating that validation is complete.