Certificate Holding Authentication for Expired Network Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication systems degrade user convenience when access rights are uniformly invalidated after a validity term expires, lacking a simple method to ensure security while maintaining user convenience.
Innovation Solution
An authentication system that includes a hardware processor and a certificate issuing server, which allows the storage of previously valid certificates for reconnection when identical certificates are presented, subject to additional conditions, thereby permitting network access without immediate certificate reissuance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If access rights are uniformly invalidated after expiration of the validity term, then security is ensured, but user convenience is degraded
Solution Approach 1:
The authentication server performs preliminary verification by checking the certificate holding part for previously valid certificates before completely invalidating access. This preliminary action allows the system to maintain security while preserving user convenience for legitimate users whose certificates have expired but were previously validated.
Solution Approach 2:
The system changes the authentication parameter from a binary valid/invalid state to a multi-state verification process that includes checking the certificate holding part. This parameter change enables differentiated treatment: completely invalidating unauthorized access while allowing renewed access for users with previously valid certificates, thus resolving the contradiction between security and user convenience.
2Reliability
If certificates are strictly validated with expiration checks, then security is maintained, but administrative complexity increases due to frequent reissuance requirements
Solution Approach 1:
The authentication server performs preliminary verification by checking the certificate holding part for previously valid certificates before completely invalidating access. This preliminary action allows the system to maintain security while preserving user convenience for legitimate users whose certificates have expired but were previously validated.
Solution Approach 2:
The system creates a functional copy of the certificate validation process by checking the certificate holding part, which stores previously valid certificates. This copying mechanism allows the system to verify user identity without requiring immediate reissuance of certificates, thereby reducing administrative complexity while maintaining security through the stored certificate verification.
3Reliability
If uniform certificate invalidation is implemented, then security is ensured, but time loss increases due to required reauthentication
Solution Approach 1:
The authentication server performs preliminary verification by checking the certificate holding part for previously valid certificates before completely invalidating access. This preliminary action allows the system to maintain security while preserving user convenience for legitimate users whose certificates have expired but were previously validated.
Solution Approach 2:
The system maintains continuity of useful action by allowing users with previously valid certificates (stored in the certificate holding part) to continue accessing the second network without immediate reauthentication. This continuous access for legitimate users reduces time loss while security is maintained through the preliminary verification process.
Data Source
AI summary
An authentication system includes: an information processing apparatus; a hardware processor that is connected to the apparatus via a first network and determines propriety of connection to a second network; and a certificate issuing server that is connected to the hardware processor via the second network and issues a certificate including a valid period and permitting the apparatus to connect to the second network, wherein the hardware processor includes a certificate holding part that holds a certificate with which connection has been permitted in a past, verifies a certificate transmitted from the apparatus and determines propriety of connection to the second network, verifies a valid period of a certificate transmitted from the apparatus, permits connection to the second network when the certificate is valid, determines, when the certificate is invalid, whether an identical certificate is held, and permits connection to the second network based on a determination result.


