Digital Certificate Validation via Positive Path Lists
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The validation of digital certificates in security protocols, particularly in devices with limited resources and isolated networks, is complex and prone to errors, especially in the Internet of Things and industrial automation systems, due to the need for complete certificate path verification and access to public databases.
Innovation Solution
A method and system for validating digital user certificates using a certificate path positive list, where the checking apparatus verifies the issuer key's traceability to a root certificate, with the list provided by a positive path server, and protected against unauthorized changes using cryptographic functions, allowing efficient validation even on devices with low computing power.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the complete certificate path is sent as part of the message exchange, then the authenticity of the certificate can be verified, but the data transmission volume increases and battery consumption rises
Solution Approach 1:
The patent extracts only the essential verification information (certificate path positive list with issuer key traceability) from the complete certificate path, eliminating unnecessary data transmission while maintaining verification reliability. This allows devices to verify certificates without transmitting or processing the entire certificate chain.
Solution Approach 2:
The patent implements local verification by allowing checking apparatus to validate certificates using locally stored positive lists of valid issuer keys, rather than requiring global certificate path verification. This localizes the verification process to reduce data transmission and energy consumption.
2Adaptability or versatility
If the checker compiles the certificate chain itself, then external database access is reduced, but the device complexity and memory requirements increase
Solution Approach 1:
The patent applies preliminary action by pre-compiling and distributing positive lists of valid issuer keys to checking apparatus before validation is needed. This eliminates the need for devices to dynamically compile certificate chains, reducing computational complexity while maintaining independence from public databases.
Solution Approach 2:
The patent uses simplified, disposable positive lists that can be easily updated and replaced, rather than requiring complex, persistent certificate database structures. This reduces memory requirements and device complexity while maintaining verification capabilities.
3Reliability
If certificate path validation is performed using conventional methods, then security is maintained, but error susceptibility and processing complexity increase
Solution Approach 1:
The patent extracts the critical security element (issuer key traceability to root certificate) from the complex certificate path validation process, maintaining security while eliminating sources of error associated with complete path verification. The positive list approach ensures only pre-validated issuer keys are accepted.
Solution Approach 2:
The patent changes the validation parameter from complete certificate path verification to issuer key presence verification in the positive list. This parameter change maintains security requirements while significantly reducing error susceptibility and processing complexity.
Data Source
AI summary
A method for validating a digital user certificate of a user by a checking device is provided. The user certificate is protected by a digital signature with an issuer key of an issuance location which issues the user certificate. The method has the steps of: receiving the user certificate in the checking device, checking the user certificate using a certificate path positive list with at least one valid certificate path which is provided to the checking device by at least one positive path server, and confirming the validity of the user certificate if the issuer key of the user certificate can be traced back to a root certificate according to one of the valid certificate paths of the certificate path positive list. Also provided is a system, a checking device, a user device, a positive path server, and a computer program product which are designed to carry out the method for validating a digital user certificate.


