Certificate Revocation List Partitioning for Broadcast Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for delivering certificate revocation lists (CRLs) to one-way client devices over broadcast networks are inefficient, as they consume network resources and can lead to memory issues due to large CRL sizes, often invalidating both compromised and uncompromised device certificates when minimizing CRL size.
Innovation Solution
The CRL is partitioned into sequences with assigned identification numbers, and these sequences are interleaved into a content transport stream, allowing for efficient distribution and detection of updated CRLs without overwhelming memory-constrained devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If CRLs are delivered over IP network as separate communication messages, then CRL distribution is achieved, but network resources are inefficiently used
Solution Approach 1:
The patent combines CRL delivery with digital content delivery by interleaving CRL sequences into content transport streams. This merging eliminates separate CRL communication channels, efficiently utilizing existing network bandwidth for both content and security updates simultaneously.
2Quantity of substance
If CRL size is minimized by revoking only CA certificates, then memory consumption is reduced, but all device certificates issued by that CA are effectively invalidated including uncompromised ones
Solution Approach 1:
The patent segments the CRL into multiple partitions, each containing specific revoked device certificates. This segmentation allows selective revocation of only compromised devices rather than all devices from a CA, maintaining validation accuracy while managing CRL size through structured organization.
Solution Approach 2:
The patent applies local quality by creating targeted CRL partitions that revoke certificates locally at the device level rather than globally at the CA level. Each partition contains only the specific device certificates that need revocation, preserving the validity of other uncompromised certificates.
3Loss of information
If large CRLs are delivered to memory-constrained client devices, then complete revocation information is provided, but client device memory is quickly consumed
Solution Approach 1:
The patent divides the complete CRL into multiple smaller partitions distributed across different content transport streams. Client devices receive and store only the relevant partitions needed for their operations, reducing memory consumption while maintaining access to complete revocation information when needed.
Solution Approach 2:
The patent organizes CRL data across multiple dimensions by creating sequential partitions with identification numbers and distributing them across different content streams. This dimensional organization allows devices to access specific revocation information without loading the entire CRL into memory.
4Ease of operation
If two-way interactive communications are used for CRL delivery, then CRL updates can be requested on-demand, but not all receivers have return channel capability
Solution Approach 1:
The patent implements self-service by embedding CRL partitions within content transport streams that one-way receivers can process autonomously. Devices automatically extract and process CRL information from the content streams without requiring interactive requests or return channels, making the system universally compatible.
Data Source
AI summary
The present invention discloses an apparatus and method for delivering a revocation list over a one-way broadcast network to receivers with limited memory capabilities. In one example, the revocation list is partitioned to form a first certificate revocation list (CRL) sequence if the number of entries in the revocation list exceeds a predetermined value. Individual identification numbers belonging to a first identification number series are subsequently assigned to partitions of the first CRL sequence. Afterwards, the first CRL sequence is interleaved into a first content transport stream.


