Digital Certificate Transfer with Rescue Mechanism
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing digital certificate systems face challenges in securely updating public-key certificates across multiple communications apparatuses, particularly due to issues with certificate corruption, expired validity, and the need for secure key length and format changes, which can lead to authentication failures and insecure communication paths.
Innovation Solution
A method for transferring digital certificates using a digital-certificate transferring apparatus that employs a common certificate for initial authentication and a normal certificate with identifying information, allowing for the secure delivery of new certificates to communications apparatuses, including support for new key lengths and formats, using a rescue certificate mechanism to maintain communication security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a digital certificate system is implemented for secure communication, then authentication security is improved, but certificate management complexity increases due to updates, corruptions, and expirations
Solution Approach 1:
The patent divides the certificate management process into distinct segments: common certificates for initial authentication, normal certificates for subsequent secure communication, and rescue certificates for recovery. This segmentation allows each certificate type to serve a specific purpose, simplifying the overall management complexity while maintaining security.
Solution Approach 2:
The patent implements preliminary action by pre-distributing rescue certificates to communications apparatuses before they are needed. When certificate corruption or expiration occurs, the rescue certificate is already available for immediate use, eliminating the need for complex real-time certificate recovery procedures.
2Reliability
If certificate updates are performed across multiple apparatuses, then security is maintained, but communication interruptions occur during the update process
Solution Approach 1:
The patent applies preliminary action by distributing new normal certificates and rescue certificates to apparatuses in advance before the actual certificate update is required. This allows the authentication system to be prepared and ready, minimizing communication interruptions when updates are actually performed.
Solution Approach 2:
The rescue certificate acts as an intermediary that bridges the gap during certificate transitions. It allows apparatuses to maintain authentication capability while normal certificates are being updated, preventing communication interruptions during the transition period.
3Ease of repair
If rescue certificate mechanism is implemented, then certificate recovery is improved, but system complexity increases
Solution Approach 1:
The patent implements self-service by enabling apparatuses to automatically use their pre-distributed rescue certificates when authentication fails due to normal certificate corruption or expiration. The system autonomously recovers without requiring complex external intervention or manual configuration, simplifying the recovery process despite the added mechanism.
4Adaptability or versatility
If multiple certificate types are used, then authentication flexibility is improved, but processing time increases
Solution Approach 1:
The patent applies local quality by assigning specific functions to specific certificate types at specific stages: common certificates for initial authentication, normal certificates for ongoing secure communication, and rescue certificates for recovery scenarios. This localized functional assignment improves authentication flexibility while minimizing processing time by using the most appropriate certificate for each situation.
Data Source
AI summary
A method of transferring digital certificates from a digital-certificate transferring apparatus to a communications counterpart. The method includes authenticating the communications counterpart using a common certificate and transferring a normal certificate to the communications counterpart when the authenticating succeeds. The method further includes receiving a first normal certificate at an address from said communications counterpart, and when, it is determined to be necessary, transferring to the communications counterpart a second normal certificate along with the information identifying the communications counterpart and an address corresponding to a second normal certificate. The second normal certificate is of a different type than the first normal certificate.


