Certificate Validity Control via Third-Party Requirement Issuance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing certificate-based authentication methods face challenges in efficiently managing certificate validity and revocation, especially for automation devices with long-term use, as they require significant administrative effort and increase the risk of misuse when issuing certificates with long or unlimited validity.
Innovation Solution
A method where a digital certificate specifies requirements that must be fulfilled by a third subscriber, with the second subscriber verifying the validity condition based on the issuance or absence of these requirements, allowing for flexible and secure authentication by checking the validity condition dynamically.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If certificates are issued with long or unlimited periods of validity, then the administrative effort is reduced and automation devices can be used over long periods, but the risk of misuse increases
Solution Approach 1:
The patent applies dynamics by making certificate validity conditional rather than fixed. The validity condition is dynamically evaluated during authentication by checking whether the third subscriber has issued the required requirement(s). This allows certificates to remain valid indefinitely in principle, but their actual validity is continuously adjusted based on current conditions, resolving the contradiction between long-term usability and misuse prevention.
Solution Approach 2:
The patent introduces a third subscriber as an intermediary who issues requirements that control certificate validity. This intermediary mechanism allows the certificate holder to use the certificate long-term without direct administrative intervention, while the third subscriber can revoke validity by simply not issuing new requirements. This mediator structure resolves the contradiction by separating certificate issuance from validity control.
2Reliability
If certificate revocation is implemented using certificate revocation lists, then certificate validity can be controlled, but the system complexity and distribution overhead increase
Solution Approach 1:
The patent extracts the revocation control function from the certificate itself and places it with the third subscriber who issues requirements. Instead of embedding revocation information in the certificate or maintaining complex revocation lists, the system simply checks whether the third subscriber has issued the required requirement(s). This extraction eliminates the need for complex revocation list distribution while maintaining reliable validity control.
Solution Approach 2:
The authentication system performs self-service by automatically checking the validity condition during the authentication process. The second subscriber automatically determines whether the certificate is valid by checking if the third subscriber has issued the required requirement(s), without needing external revocation list updates or complex validation procedures. This self-service approach reduces system complexity while maintaining reliability.
3Object-affected harmful factors
If certificates are managed with strict validity periods, then misuse can be prevented, but the administrative effort to replace certificates increases
Solution Approach 1:
The patent applies dynamics by transitioning from static validity periods to dynamic validity conditions. Instead of manually replacing certificates when their fixed period expires, the system continuously evaluates whether the third subscriber has issued the required requirement(s). This dynamic approach prevents misuse by stopping validity evaluation when requirements are not met, while eliminating the need for manual certificate replacement administrative work.
Solution Approach 2:
The third subscriber acts as an intermediary who manages the validity condition by issuing or withdrawing requirements. This mediator eliminates the need for certificate holders or administrators to manually track and replace certificates. The third subscriber simply needs to continue issuing requirements for the certificate to remain valid, or stop issuing them for revocation, greatly reducing administrative effort while maintaining misuse prevention.
Data Source
AI summary
A method is disclosed for certificate-based authentication, in which a first subscriber authenticates himself to a second subscriber using a digital certificate associated to the first subscriber. The certificate specifies requirement(s) and the fulfillment of a requirement is ensured by a third subscriber. Within the framework of the authentication by the second subscriber, a validity condition is checked, and the certificate is classified as valid if the validity condition is fulfilled, based on the issue and/or absence of issue of the requirement(s) specified in the certificate by the third subscriber. Requirements may be used to restrict the validity of the certificate. The validity of a certificate can thereby be controlled in a simple and flexible manner without explicitly defining the validity in the certificate. The method can be used for authentication in any technical field, e.g., to authentication subscribers in the form of components of an automation system.

