Certificate Format Interoperability via Supplementary Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cryptographic systems face challenges in providing interoperability across different networks due to the need for all levels of the trusted hierarchy to process and generate certificates conforming to specific formats, which can be burdensome, especially when alternative standards are used in specialized areas.

Innovation Solution

A method is provided where a certificate is issued by a Certificate Authority (CA) in a first specified format, incorporating supplementary information to enable transformation and usage in a second specified format, allowing communication across different protocols, such as X.509 and Elliptic Curve Qu-Vanstone (ECQV), without requiring all levels to process and generate certificates according to the second format.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If all levels of the trusted hierarchy process and generate certificates conforming to specific formats, then interoperability across different networks is achieved, but the system complexity and processing burden increase significantly

Engineering Contradiction:
ImproveinteroperabilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a format conversion mechanism that acts as an intermediary between different certificate formats. The CA generates certificates in a first format (e.g., X.509) while incorporating supplementary information that enables transformation to a second format (e.g., ECQV). This intermediary conversion layer allows interoperability without requiring all system levels to support multiple formats natively, thus reducing system complexity while maintaining versatility.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The certificate structure is segmented into core certificate data and supplementary information. The core certificate maintains the first specified format for broad compatibility, while the supplementary information section contains format-specific data that enables transformation to alternative formats. This segmentation allows the system to maintain simple, standardized certificates while providing access to multiple formats through the supplementary data.

Inventive Principle:
Principle #1Segmentation

2Loss of energy

If alternative certificate formats are used in specialized areas, then bandwidth efficiency is improved, but the requirement for all levels to process multiple formats increases burden

Engineering Contradiction:
Improvebandwidth efficiencyVSAvoidprocessing burden
Core Design Contradiction:
Loss of energyVSEase of operation

Solution Approach 1:

The CA performs preliminary action by pre-computing and embedding supplementary information in the certificate during the certificate generation phase. This supplementary information contains the necessary data to transform the certificate to alternative formats like ECQV that offer bandwidth efficiency. By preparing this conversion data in advance, the system enables bandwidth-efficient communication without requiring real-time format conversion or multiple processing capabilities at each level.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent effectively creates a copy of the certificate data in a different format through the supplementary information. The supplementary information contains replicated or transformed certificate data that can be used directly in bandwidth-efficient protocols. This copying approach allows the system to use alternative formats where needed without requiring the entire certificate hierarchy to process multiple formats, reducing the processing burden while maintaining bandwidth efficiency.

Inventive Principle:
Principle #26Copying

3Adaptability or versatility

If certificates incorporate supplementary information for format transformation, then interoperability between different cryptographic protocols is enabled, but the certificate size and information processing requirements increase

Engineering Contradiction:
Improveprotocol interoperabilityVSAvoidcertificate size
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The patent applies local quality by making the certificate structure non-uniform: the core certificate data maintains standard, compact formatting for broad compatibility, while only specific supplementary information sections are expanded to include format transformation data. This localized expansion of information only where needed enables protocol interoperability without uniformly increasing the entire certificate structure, thus minimizing the overall size increase while achieving versatility.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP2302834B1System and method for providing credentials
Publication Date: 2017.12.13 BLACKBERRY LTD
  • EP2302834B1 patent drawingFigure 1
  • EP2302834B1 patent drawingFigure 2
  • EP2302834B1 patent drawingFigure 3~4

AI summary

A method and system is operable to provide credentials by generating a first credential that conforms to a first specified format. A second credential conforming to a second specified format is included in the first credential so that the second credential may be distributed through the cryptosystem using the first specified format. The credential may be a digital certificate.