Digital Certificate Security Channel Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing digital certificate management methods over wireless local area networks transmit messages in plaintext, ensuring only data integrity but not authenticity or confidentiality, leading to insecure data transmission.

Innovation Solution

Establishing a security data channel between digital certificate requesting and issuing devices using an authorization code to generate a security key for encrypting messages, ensuring secure data communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If messages are transmitted in plaintext between digital certificate requesting device and issuing device, then data integrity can be verified, but data authenticity and confidentiality cannot be ensured

Engineering Contradiction:
Improvedata integrity verificationVSAvoiddata authenticity and confidentiality security
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by establishing a security data channel and generating encryption keys before transmitting digital certificate management messages. The requesting device and issuing device negotiate security parameters and set up encrypted communication channels in advance, so that when actual certificate management messages are transmitted, they are already protected by encryption, thus ensuring both integrity and confidentiality from the outset.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the transmission parameter of messages from plaintext to encrypted format. By introducing encryption algorithms and transforming the message format from unencrypted to encrypted, the system maintains data integrity verification while adding layers of protection for authenticity and confidentiality. The message structure includes both the original data and encryption verification elements.

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If messages are transmitted in plaintext over network, then communication simplicity is maintained, but security protection is insufficient

Engineering Contradiction:
Improvecommunication simplicityVSAvoiddata security protection
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary security mechanism between the requesting device and issuing device. A security data channel is established as an intermediate layer that handles encryption and decryption operations. This intermediary layer transparently protects messages during transmission without requiring changes to the underlying communication protocol or increasing operational complexity for the users.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Object-affected harmful factors

If security data channel with encryption is established, then data authenticity and confidentiality are protected, but system complexity increases

Engineering Contradiction:
Improvedata authenticity and confidentialityVSAvoidsecurity channel establishment and message encryption
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent applies self-service by enabling the requesting device and issuing device to autonomously negotiate security parameters and establish encrypted communication channels without requiring external security infrastructure or manual configuration. The devices automatically generate encryption keys, select encryption algorithms, and manage the security data channel setup process, reducing the need for complex external security systems.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11363010B2Method and device for managing digital certificate
Publication Date: 2022.06.14 CHINA IWNCOMM
  • US11363010B2 patent drawing
  • US11363010B2 patent drawing
  • US11363010B2 patent drawing

AI summary

A method and device for managing a digital certificate are provided. A digital certificate requesting device negotiates with a digital certificate issuing device by using an acquired authorization code, to establish a security data channel and generate a security key, and messages can be encrypted with the generated data communication key during a process of message interaction between the digital certificate requesting device and the digital certificate issuing device, thereby effectively increasing the security in data transmission. The method and device are applicable for automatically requesting for, querying, updating, revoking a digital certificate and acquiring a digital certificate revocation list in various scenarios.