Certificate System for Verifying Secure Sessions via Multi-Authority Signatures
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing certificate systems rely on single certification authorities, which can become compromised, leading to security vulnerabilities and difficulties in maintaining secure sessions, especially when certificates expire or are revoked.
Innovation Solution
Implementing a system that uses multiple digital signatures and public keys from multiple certification authorities to verify the ownership of an organization's application, allowing for seamless replacement of compromised or expired certificates without interrupting user access, and utilizing certification requirements to identify potential compromised interactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a single certification authority is used to verify website ownership, then the certificate system is simple to operate, but the system becomes vulnerable to compromise and cannot maintain secure sessions if the certification authority is compromised
Solution Approach 1:
The patent segments the certification authority function into multiple independent certification authorities, each issuing certificates for the same organization application. This segmentation ensures that compromise of one certification authority does not affect the others, maintaining security reliability while distributing the verification function across multiple entities.
Solution Approach 2:
The patent changes the parameter of certification authority quantity from one to multiple, transforming the certificate system from a single-point-of-failure architecture to a distributed architecture. This parameter change enables the system to tolerate individual certification authority compromises while maintaining overall security reliability.
2Reliability
If multiple digital signatures and public keys from multiple certification authorities are used, then security is enhanced with additional validation layers, but the device complexity increases
Solution Approach 1:
The patent merges multiple certificates from different certification authorities into a unified verification process. The user application can verify organization ownership using any valid certificate, combining the security benefits of multiple certification authorities while maintaining a streamlined verification mechanism that does not require complex multi-factor authentication.
Solution Approach 2:
The patent creates a universal certificate verification mechanism that works with certificates from any certification authority. The system is designed to handle multiple certificate types and sources uniformly, enabling the user application to verify organization ownership through any valid certificate without requiring authority-specific verification logic.
3Reliability
If a certificate becomes compromised or expired, then the certification authority can be revoked, but the organization must replace all certificates simultaneously causing service interruption
Solution Approach 1:
The patent implements a dynamic certificate verification system where the user application can adaptively use different certificates from multiple certification authorities. When one certificate becomes compromised or expired, the system dynamically switches to another valid certificate, maintaining application availability without requiring simultaneous replacement of all certificates.
Solution Approach 2:
The patent provides beforehand cushioning by maintaining multiple valid certificates from different certification authorities before any compromise occurs. This preparatory measure ensures that when one certificate becomes invalid, the organization already has backup certificates ready to use, preventing service interruption and maintaining productivity.
4Reliability
If multiple certificates are used to verify organization application, then the risk of unauthorized access is reduced, but the ease of operation decreases due to additional validation requirements
Solution Approach 1:
The patent implements self-service by enabling the user application to automatically verify organization ownership using certificates from multiple certification authorities without requiring user intervention. The system autonomously selects and validates appropriate certificates, maintaining ease of operation while enhancing authorization security through multi-authority verification.
Data Source
AI summary
Systems, computer products, and methods are described herein for an improved secure certificate system for identifying potential authorized and unauthorized interactions between a web browser and a website. The certificate system utilizes stored certification requirements (e.g., pinned certification requirements, third-party certification requirement system, or the like), and compares the stored certification requirements with received certification requirements. The system may notify the user or prevent the interaction between the web browser and website when the stored certification requirements do not meet the received certification requirements (e.g., a threshold requirement of certificates to validate, validated certificates, or the like). The certificate system allows the interaction between the web browser and website when the stored certification requirements meet the received certification requirements and the website is verified based on the certification requirements. It should be also understood that the certificate system may also be utilized for interactions between dedicated applications.


