Automated Certificate Issuance via Registration Authority Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional Public Key Infrastructure (PKI) systems face challenges in efficiently and cost-effectively verifying identities and maintaining accurate certificate revocation lists, requiring significant resources and labor due to complex protocols and high trust requirements, which can be impractical for applications needing lower trust levels.

Innovation Solution

A system and method for efficiently verifying identities and generating digital certificates by incorporating verification information within the certificate signing request, utilizing shared secrets, biometric data, and network properties, processed by a certification authority and registration authority, allowing for secure and automated certificate issuance and revocation management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional PKI systems use complex protocols and high trust requirements to verify identities, then security and reliability are improved, but resource consumption and operational complexity increase significantly

Engineering Contradiction:
Improveidentity verification securityVSAvoidprotocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the identity verification process into distinct components: certificate signing requests containing verification information, automated registration authority processing, and certificate issuance. This segmentation simplifies the overall protocol complexity while maintaining security through structured verification data flow.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an automated registration authority as an intermediary that processes verification information automatically. This intermediary handles the complex verification logic, reducing the burden on end systems and simplifying the protocols they must implement while maintaining high security standards.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If conventional PKI systems employ thorough identity verification procedures, then certificate reliability is improved, but time consumption and operational costs increase

Engineering Contradiction:
Improvecertificate accuracyVSAvoidverification time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent incorporates verification information directly into the certificate signing request before certificate issuance. This preliminary inclusion of verification data allows automated processing without requiring time-consuming post-issuance verification procedures, reducing overall verification time while maintaining accuracy.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables automated self-service verification through the registration authority that automatically processes verification information included in certificate signing requests. This automation eliminates manual verification steps, significantly reducing verification time while maintaining certificate accuracy through systematic processing.

Inventive Principle:
Principle #25Self-service

3Reliability

If conventional PKI systems maintain accurate certificate revocation lists through manual processes, then system security is improved, but resource expenditure and operational complexity increase

Engineering Contradiction:
Improverevocation list accuracyVSAvoidcertificate management efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent replaces manual mechanical processes for maintaining revocation lists with automated electronic processing. The registration authority automatically processes verification information and manages revocation status, eliminating manual intervention while maintaining accuracy and significantly improving operational efficiency.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system implements automated feedback mechanisms where the registration authority continuously processes verification information and updates revocation status accordingly. This feedback loop ensures revocation list accuracy is maintained automatically without manual intervention, improving both reliability and productivity.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP2115932B1Systems and methods for automating certification authority practices
Publication Date: 2019.10.16 TIBCO SOFTWARE INC
  • EP2115932B1 patent drawingFigure 1~2
  • EP2115932B1 patent drawingFigure 3~4

AI summary

Systems and methods for efficiently verifying identities and for generating and signing digital certificates associated with those identities are disclosed. Generation of a digital certificate of an entity may begin by receiving a certificate signing request from the entity at a certification authority, the certificate signing request including verification information. The certificate signing request may be transmitted to a registration authority and the information of the certificate signing request may be processed. Whether to approve the certificate signing request may be determined, based on a result of the processing, and an approval may be granted when the certificate signing request is approved. A certificate associated with the entity may be generated when the approval is received, and the certificate may be transmitted to the entity.