Digital Certificate Filtering for ITS Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing digital certificate management systems in Intelligent Transportation Systems (ITS) face challenges with storage and connectivity limitations, particularly in mobile networks where cars and roadside units may not always have constant internet access, leading to inefficiencies in distributing and verifying certificate revocation lists.

Innovation Solution

A system and method for filtering digital certificates within ITS networks, where a certificate authority maintains a validity list and filters it based on geographic attributes, transmitting only relevant certificates to nodes within specific areas, reducing the burden on resource-restricted end-nodes by using helper-nodes to update and distribute filtered revocation lists.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the complete digital certificate validity list is distributed to all network nodes, then certificate verification reliability is improved, but storage requirements and network traffic increase significantly

Engineering Contradiction:
Improvecertificate verification reliabilityVSAvoidstorage requirements
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent applies local quality by filtering the certificate validity list according to geographic location. Each network node receives a customized validity list containing only certificates relevant to its specific geographic area, rather than distributing the complete global validity list to all nodes. This reduces storage requirements at each node while maintaining verification reliability for local communications.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent segments the complete validity list into multiple geographic regions. The certificate authority divides the validity list based on geographic attributes, creating separate validity list segments for different areas. Each network node receives only the segment corresponding to its location, reducing overall storage burden across the network while preserving complete coverage for verification purposes.

Inventive Principle:
Principle #1Segmentation

2Reliability

If the complete digital certificate validity list is transmitted to all network nodes, then certificate verification completeness is improved, but network traffic and bandwidth consumption increase

Engineering Contradiction:
Improvecertificate verification completenessVSAvoidnetwork traffic
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent transmits only the locally relevant portion of the validity list to each network node based on its geographic location. This eliminates the need to transmit the complete validity list across the entire network, significantly reducing network traffic and bandwidth consumption while ensuring each node receives sufficient information for verifying certificates within its service area.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent extracts and transmits only the necessary subset of the validity list corresponding to each node's geographic area. Rather than transmitting the complete validity list, the system extracts and sends only the relevant certificates for each location, reducing network traffic while maintaining verification completeness for local operations.

Inventive Principle:
Principle #2Taking out (Extraction)

3Quantity of substance

If filtered validity lists are maintained for different geographic areas, then storage efficiency is improved, but system complexity increases due to filtering management

Engineering Contradiction:
Improvestorage efficiencyVSAvoidfiltering management complexity
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent introduces a certificate authority as an intermediary that performs the filtering operation. The certificate authority maintains the complete validity list and automatically filters it based on geographic attributes before transmission to network nodes. This centralizes the filtering management complexity at the certificate authority rather than distributing it across all network nodes, simplifying the overall system architecture while maintaining storage efficiency.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent performs filtering in advance before transmitting validity lists to network nodes. The certificate authority pre-processes the complete validity list, filters it according to geographic attributes, and prepares customized validity lists for different areas before distribution. This preliminary filtering action eliminates the need for network nodes to perform complex filtering operations, reducing their computational burden and simplifying system operation.

Inventive Principle:
Principle #10Preliminary action

4Measurement precision

If network nodes store complete validity lists, then certificate verification accuracy is improved, but processing overhead and memory usage increase

Engineering Contradiction:
Improvecertificate verification accuracyVSAvoidmemory usage
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent stores only the locally relevant portion of the validity list at each network node based on its geographic location. Each node maintains a customized validity list containing certificates applicable to its area, rather than storing the complete global validity list. This reduces memory usage at each node while preserving verification accuracy for certificates within the node's operational scope.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP2942921B1System and method for filtering digital certificates
Publication Date: 2020.06.10 NXP BV
  • EP2942921B1 patent drawingFigure 1
  • EP2942921B1 patent drawingFigure 2
  • EP2942921B1 patent drawingFigure 3

AI summary

One example discloses a system for filtering digital certificates within a communications network, comprising: a first set of network-nodes, having a first attribute and a respective first set of digital certificates; a second set of network-nodes, having a second attribute and a respective second set of digital certificates; and a digital certificate authority, having a digital certificate validity list which includes the first and second sets of digital certificates; wherein the certificate authority filters the validity list based on the first attribute and transmits the filtered validity list to the first set of network nodes. Another example discloses a method for filtering digital certificates, comprising: maintaining a digital certificate validity list; identifying a set of network-nodes, having an attribute; filtering the validity list based on the attribute; and transmitting the filtered validity list to the set of network-nodes.