Certificate System for Verifying Secure Sessions via Multi-Authority Signatures

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing certificate systems rely on single certification authorities, which can become compromised, leading to security vulnerabilities and difficulties in maintaining secure sessions, especially when certificates expire or are revoked.

Innovation Solution

Implementing a system that uses multiple digital signatures and public keys from multiple certification authorities to verify the ownership of an organization's application, allowing for seamless replacement of compromised or expired certificates without interrupting user access, and utilizing certification requirements to identify potential compromised interactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single certification authority is used to verify website ownership, then the certificate system is simple to operate, but the system becomes vulnerable to compromise and cannot maintain secure sessions if the certification authority is compromised

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidcertificate system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the certification authority function into multiple independent certification authorities, each issuing certificates for the same organization application. This segmentation ensures that compromise of one certification authority does not affect the others, maintaining security reliability while distributing the verification function across multiple entities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the parameter of certification authority quantity from one to multiple, transforming the certificate system from a single-point-of-failure architecture to a distributed architecture. This parameter change enables the system to tolerate individual certification authority compromises while maintaining overall security reliability.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If multiple digital signatures and public keys from multiple certification authorities are used, then security is enhanced with additional validation layers, but the device complexity increases

Engineering Contradiction:
Improvesession securityVSAvoidcertificate management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple certificates from different certification authorities into a unified verification process. The user application can verify organization ownership using any valid certificate, combining the security benefits of multiple certification authorities while maintaining a streamlined verification mechanism that does not require complex multi-factor authentication.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a universal certificate verification mechanism that works with certificates from any certification authority. The system is designed to handle multiple certificate types and sources uniformly, enabling the user application to verify organization ownership through any valid certificate without requiring authority-specific verification logic.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If a certificate becomes compromised or expired, then the certification authority can be revoked, but the organization must replace all certificates simultaneously causing service interruption

Engineering Contradiction:
Improvecertificate validityVSAvoidapplication availability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements a dynamic certificate verification system where the user application can adaptively use different certificates from multiple certification authorities. When one certificate becomes compromised or expired, the system dynamically switches to another valid certificate, maintaining application availability without requiring simultaneous replacement of all certificates.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent provides beforehand cushioning by maintaining multiple valid certificates from different certification authorities before any compromise occurs. This preparatory measure ensures that when one certificate becomes invalid, the organization already has backup certificates ready to use, preventing service interruption and maintaining productivity.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

4Reliability

If multiple certificates are used to verify organization application, then the risk of unauthorized access is reduced, but the ease of operation decreases due to additional validation requirements

Engineering Contradiction:
Improveauthorization securityVSAvoiduser access simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service by enabling the user application to automatically verify organization ownership using certificates from multiple certification authorities without requiring user intervention. The system autonomously selects and validates appropriate certificates, maintaining ease of operation while enhancing authorization security through multi-authority verification.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10862892B2Certificate system for verifying authorized and unauthorized secure sessions
Publication Date: 2020.12.08 BANK OF AMERICA CORP
  • US10862892B2 patent drawing
  • US10862892B2 patent drawing
  • US10862892B2 patent drawing

AI summary

Systems, computer products, and methods are described herein for an improved secure certificate system for identifying potential authorized and unauthorized interactions between a web browser and a website. The certificate system utilizes stored certification requirements (e.g., pinned certification requirements, third-party certification requirement system, or the like), and compares the stored certification requirements with received certification requirements. The system may notify the user or prevent the interaction between the web browser and website when the stored certification requirements do not meet the received certification requirements (e.g., a threshold requirement of certificates to validate, validated certificates, or the like). The certificate system allows the interaction between the web browser and website when the stored certification requirements meet the received certification requirements and the website is verified based on the certification requirements. It should be also understood that the certificate system may also be utilized for interactions between dedicated applications.