Selective Certificate Revocation via Timestamped Check Codes
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing mechanisms for ensuring authentication, non-repudiation, and integrity of information over time are inadequate, particularly in managing the validity of cryptographic key pairs used for signing payload data.
Innovation Solution
A system comprising a signing server, an archive server, and a validation server that employs asymmetric cryptographic key pairs to calculate and encrypt check codes, with a second check code incorporating a time stamp to enhance security, and allows for the revocation of keys to prevent unauthorized use, ensuring secure distribution and storage of payload data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Duration of action of stationary object
If a cryptographic key pair is used for signing payload data over an extended period, then the system maintains operational continuity and reduces key management overhead, but the risk of key compromise and unauthorized use increases over time
Solution Approach 1:
The patent implements dynamic key management by transitioning from static long-term key usage to dynamic key pairs with defined validity periods. Keys are generated, activated, and revoked based on operational requirements and security policies, allowing the system to adapt key lifecycle management to changing security conditions and operational needs
Solution Approach 2:
The patent establishes preliminary key validation mechanisms by checking whether a key pair is currently activated and valid before accepting signatures. The system proactively manages key lifecycles by setting activation dates and expiration dates, and by providing mechanisms to revoke keys before their natural expiration, preventing unauthorized use before it can occur
2Reliability
If multiple asymmetric key pairs are managed to enhance security through time-stamped signatures, then the authentication reliability improves, but the key management complexity increases
Solution Approach 1:
The patent implements feedback mechanisms in key management by providing status information about key pairs (activated, expired, revoked) to signing servers and validation servers. The system monitors key usage and provides feedback on key validity, enabling automated key lifecycle management and reducing the manual complexity of managing multiple key pairs
Solution Approach 2:
The patent introduces an intermediary key management system that acts as a mediator between signing servers, archive servers, and validation servers. This intermediary manages the lifecycle of key pairs, handles activation and revocation, and provides centralized control, thereby reducing the complexity that would otherwise be distributed across multiple systems
3Object-affected harmful factors
If key revocation mechanisms are implemented to prevent unauthorized use, then the security against compromised keys improves, but the verification process becomes more complex
Solution Approach 1:
The patent performs preliminary validation by checking whether a key pair is currently activated and not revoked before accepting or validating signatures. This preliminary check prevents unauthorized use by compromised keys from being processed, and the activation/expiration dates are pre-configured to automatically enforce key validity periods without requiring complex real-time verification
Data Source
Figure 1
Figure 2
Figure 3~4
AI summary
A signing server (1.1), an archive server (1.2) and a validation server are disclosed. Methods for signing, storing and validating a set of payload data by means of said servers are also disclosed. The methods comprise signing, storing and validating information related to a set of payload data. At the signing server, a check code based on the set of payload data is calculated and encrypted by means of an asymmetric cryptographic key pair (A). The encrypted check code (1.11) is stored at the archive server and associated with a time stamp, which can be used for validation of the set of payload data. The invention is advantageous in that it enables a selective revocation of certificates that have been used for signing the set of payload data.