Derived Digital Certificate Generation via Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing digital certificates are often long-term and unrestricted, leading to a high risk of misuse and a psychological barrier for users due to the responsibility of secure storage and management, especially for those who rarely engage in electronic transactions.

Innovation Solution

A method to generate a derived, purpose-specific certificate from a first certificate without requiring an eID provider or network connection, allowing users to create application-specific certificates with limited validity and restricted attributes, which reduces the risk of misuse and simplifies security requirements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If long-term and unrestricted digital certificates are issued, then the legal binding character and authentication capability are improved, but the risk of misuse and security burden on users increases

Engineering Contradiction:
Improveauthentication capabilityVSAvoidrisk of misuse
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the certificate functionality by introducing a root certificate that remains secure and immutable, while generating multiple derived certificates for different applications. Each derived certificate is restricted to specific uses and time periods, dividing the overall authentication capability into controlled segments that reduce misuse risk while maintaining reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic certificate generation where derived certificates are created on-demand for specific applications and automatically expire after use or after a defined time period. This dynamic approach allows the system to adapt certificate validity and scope to each specific use case, reducing the risk of long-term misuse while maintaining authentication capability when needed.

Inventive Principle:
Principle #15Dynamics

2Reliability

If long-term and unrestricted digital certificates are issued, then the authentication capability is improved, but the psychological barrier and responsibility burden on users increases

Engineering Contradiction:
Improveauthentication capabilityVSAvoiduser responsibility burden
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent enables users to self-generate derived certificates locally on their devices without requiring interaction with the certification authority for each new certificate. The root certificate stored on the user's device automatically generates derived certificates for specific applications, eliminating the need for users to manually manage multiple certificates and reducing the psychological burden of security responsibility.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent creates derived certificates as restricted copies of the root certificate, where each copy is automatically limited to specific applications and time periods. This copying mechanism allows users to obtain authentication capability for specific purposes without assuming the full security responsibility of managing a comprehensive, long-term certificate.

Inventive Principle:
Principle #26Copying

3Object-affected harmful factors

If application-specific certificates with limited validity are generated, then the risk of misuse is reduced, but the complexity of certificate management increases

Engineering Contradiction:
Improverisk of misuseVSAvoidcertificate management complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent creates a universal root certificate that serves multiple functions: it acts as a secure storage element, an authentication authority, and a template for generating numerous application-specific derived certificates. This multi-functional approach consolidates certificate management complexity into a single root certificate while enabling simplified generation of restricted derived certificates for various applications.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3283999B1Electronic system for producing a certificate
Publication Date: 2020.04.29 BUNDESDRUCKEREI GMBH
  • EP3283999B1 patent drawingFigure 1
  • EP3283999B1 patent drawingFigure 2
  • EP3283999B1 patent drawingFigure 3

AI summary

The invention relates to a method for producing a second certificate (104) derived from a first certificate (103) of a document PKI comprising a first portable device (101) and a second device (102), wherein the first certificate (103) is assigned to a user (100) and includes a first public key (106), to which a first private key (105) is assigned, wherein the first device (101) has a nonvolatile electronic memory (109) having a protected memory area (111), in which at least one identifier (124) and the first private key (105) of the first certificate (103) of the document PKI are stored, wherein access to the protected memory area (111) is possible only via a first processor (112) of the first device (101), and wherein the first device (101) has a first communication interface (118) for communication with the second device (102), wherein the second device (102) has a second communication interface (119) for communication with the first device (101), and wherein the method comprises the following steps: authenticating the user (100) with respect to the first device (101), defining a time (123) for the derived second certificate (104) by means of the second device (102), selecting at least one identifier (124) assigned to the user (100) from the protected memory area (111) of the first device (101) for the derived second certificate (104), defining at least one attribute (125) limiting the usability of the derived second certificate (104) by means of the second device (102), producing a cryptographic key pair for the derived second certificate (104) comprising a second private key (107) and a second public key (108) by means of the first processor (112) of the first device (101), producing a data set (126), comprising the second public key (108) produced, the time (123), the at least one identifier (124) and the at least one limiting attribute (125), creating a signature (127) for the data set (126) with the first private key (105) of the first certificate (103) by means of the first device (101), transmitting the signature (107) from the first device (101) to the second device (102) via the first and second communication interface (118, 119) to provide the derived second certificate (104) in the form of the data set (126) with signature (107) on the second device (102), and transmitting the second private key (107) of the derived second certificate (104) from the first device (101) to the second device (102) via the first and second communication interface (118, 119).