Digital Certificate Transfer with Rescue Mechanism

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing digital certificate systems face challenges in securely updating public-key certificates across multiple communications apparatuses, particularly due to issues with certificate corruption, expired validity, and the need for secure key length and format changes, which can lead to authentication failures and insecure communication paths.

Innovation Solution

A method for transferring digital certificates using a digital-certificate transferring apparatus that employs a common certificate for initial authentication and a normal certificate with identifying information, allowing for the secure delivery of new certificates to communications apparatuses, including support for new key lengths and formats, using a rescue certificate mechanism to maintain communication security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a digital certificate system is implemented for secure communication, then authentication security is improved, but certificate management complexity increases due to updates, corruptions, and expirations

Engineering Contradiction:
Improveauthentication securityVSAvoidcertificate management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the certificate management process into distinct segments: common certificates for initial authentication, normal certificates for subsequent secure communication, and rescue certificates for recovery. This segmentation allows each certificate type to serve a specific purpose, simplifying the overall management complexity while maintaining security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary action by pre-distributing rescue certificates to communications apparatuses before they are needed. When certificate corruption or expiration occurs, the rescue certificate is already available for immediate use, eliminating the need for complex real-time certificate recovery procedures.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If certificate updates are performed across multiple apparatuses, then security is maintained, but communication interruptions occur during the update process

Engineering Contradiction:
Improvesecurity maintenanceVSAvoidcommunication interruption time
Core Design Contradiction:
ReliabilityVSDuration of action of moving object

Solution Approach 1:

The patent applies preliminary action by distributing new normal certificates and rescue certificates to apparatuses in advance before the actual certificate update is required. This allows the authentication system to be prepared and ready, minimizing communication interruptions when updates are actually performed.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The rescue certificate acts as an intermediary that bridges the gap during certificate transitions. It allows apparatuses to maintain authentication capability while normal certificates are being updated, preventing communication interruptions during the transition period.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of repair

If rescue certificate mechanism is implemented, then certificate recovery is improved, but system complexity increases

Engineering Contradiction:
Improvecertificate recoveryVSAvoidsystem complexity
Core Design Contradiction:
Ease of repairVSDevice complexity

Solution Approach 1:

The patent implements self-service by enabling apparatuses to automatically use their pre-distributed rescue certificates when authentication fails due to normal certificate corruption or expiration. The system autonomously recovers without requiring complex external intervention or manual configuration, simplifying the recovery process despite the added mechanism.

Inventive Principle:
Principle #25Self-service

4Adaptability or versatility

If multiple certificate types are used, then authentication flexibility is improved, but processing time increases

Engineering Contradiction:
Improveauthentication flexibilityVSAvoidprocessing time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent applies local quality by assigning specific functions to specific certificate types at specific stages: common certificates for initial authentication, normal certificates for ongoing secure communication, and rescue certificates for recovery scenarios. This localized functional assignment improves authentication flexibility while minimizing processing time by using the most appropriate certificate for each situation.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS7584351B2Method of transferring digital certificate,apparatus for transferring digital certificate, and system, program, and recording medium for transferring digital certificate
Publication Date: 2009.09.01 RICOH CO LTD
  • US7584351B2 patent drawing
  • US7584351B2 patent drawing
  • US7584351B2 patent drawing

AI summary

A method of transferring digital certificates from a digital-certificate transferring apparatus to a communications counterpart. The method includes authenticating the communications counterpart using a common certificate and transferring a normal certificate to the communications counterpart when the authenticating succeeds. The method further includes receiving a first normal certificate at an address from said communications counterpart, and when, it is determined to be necessary, transferring to the communications counterpart a second normal certificate along with the information identifying the communications counterpart and an address corresponding to a second normal certificate. The second normal certificate is of a different type than the first normal certificate.