Detecting Compromised Certificate Authorities via Telemetry

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing public key infrastructure (PKI) is architecturally weak and difficult to detect compromised Certificate Authorities (CAs), as evidenced by breaches like DigiNotar, where compromised CAs can issue unauthorized certificates, making it challenging to identify and remediate such issues in a timely manner.

Innovation Solution

A computer-implemented method and system that utilizes a Central Intelligence subsystem to collect and analyze telemetry data from edge devices to detect compromised CAs by building a certificate database, parsing certificates for metadata, and flagging anomalies in certificate usage patterns across geographical regions, allowing for real-time identification and alerting of compromised CAs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a trusted CA issues certificates for high value sites, then the user experience is improved with seamless secure connections, but the system becomes vulnerable to exploitation when the CA is compromised

Engineering Contradiction:
Improveuser experienceVSAvoidexploitation vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements a feedback mechanism where multiple independent observers monitor and report on certificate issuance patterns. When a compromised CA is detected through anomaly analysis of these reports, the system automatically removes the CA from the trusted list, creating a closed-loop feedback system that continuously improves security while maintaining ease of operation for legitimate connections.

Inventive Principle:
Principle #23Feedback

2Reliability

If static lists of trusted root CAs are built into browsers and operating systems, then the reliability of certificate validation is improved, but the time to detect and respond to CA compromise is significantly delayed

Engineering Contradiction:
Improvecertificate validationVSAvoiddetection time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by establishing a distributed network of observers that continuously monitor certificate issuance patterns before a compromise can cause widespread damage. The system proactively detects anomalies in certificate patterns and automatically responds by removing compromised CAs from trusted lists, rather than waiting for traditional detection methods to identify breaches.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If the number of trusted CAs is increased to over 1500 managed by over 50 countries, then the versatility and global adoption of PKI is improved, but the difficulty of detecting compromised CAs increases

Engineering Contradiction:
Improveglobal adoptionVSAvoidcompromise detection
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent segments the monitoring function into multiple independent observers distributed across different locations and organizations. Each observer independently monitors certificate patterns and reports findings, allowing the system to detect compromised CAs anywhere in the global PKI infrastructure without requiring centralized control or reducing the number of trusted CAs.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9686081B2Detecting compromised certificate authority
Publication Date: 2017.06.20 CISCO TECHNOLOGY INC
  • US9686081B2 patent drawing
  • US9686081B2 patent drawing
  • US9686081B2 patent drawing

AI summary

A computer-implemented method is provided to detect a compromised Certificate Authority (CA). Over time reports are received containing data describing certificate authority certificates captured from messages exchanged between clients and servers. These reports may be received by a central computing entity. Metadata and statistics for certificates contained in the reports are stored. It is determined whether a certificate authority has been compromised based on the metadata and statistics.