Distributed Certificate Authority Trust for Secure Data Parsing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication systems are vulnerable to security breaches when certificate authorities are compromised, as attackers can issue false certificates, leading to unauthorized access and decryption of messages.

Innovation Solution

Implementing a secure proxy service that distributes trust among a set of certificate authorities through secure data parsing, using unique public and private key pairs and multi-factored secret sharing to ensure the confidentiality and integrity of communications, even if some certificate authorities are compromised.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a single certificate authority is used to issue digital certificates, then the system is simpler to operate, but the security is compromised if the certificate authority is compromised

Engineering Contradiction:
Improvecertificate management simplicityVSAvoidsecurity against certificate authority compromise
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent divides the trust function into multiple independent certificate authorities instead of relying on a single authority. Each certificate authority issues certificates independently, and the system requires a quorum (threshold number) of certificate authorities to be compromised before security is breached. This segmentation resolves the contradiction by maintaining operational simplicity while improving security through distribution of trust.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent assigns different roles and responsibilities to different certificate authorities in the distributed set. Each certificate authority operates independently with its own key pair and certificate issuance process. This local quality approach allows the system to maintain simplicity at each individual certificate authority level while achieving enhanced security through the collective distributed architecture.

Inventive Principle:
Principle #3Local quality

2Reliability

If multiple certificate authorities are used to distribute trust, then security is improved against compromise, but the system complexity increases

Engineering Contradiction:
Improvesecurity against certificate authority compromiseVSAvoidcertificate management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

By segmenting the certificate authority function into multiple independent entities, the patent achieves security through distribution while managing complexity through standardized interfaces. Each segmented certificate authority operates independently but follows the same protocol, allowing the system to scale security without proportionally increasing operational complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal framework that can accommodate any number of certificate authorities using the same standardized process. The multi-functionality of the system allows it to operate with different numbers of certificate authorities and different quorum thresholds, providing flexibility that manages complexity while maintaining security. The same basic protocol serves multiple certificate authorities and multiple security scenarios.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If certificate authorities issue digital certificates using standard protocols, then interoperability is improved, but security is weakened when certificate authorities are compromised

Engineering Contradiction:
Improveprotocol interoperabilityVSAvoidsecurity when certificate authority is compromised
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent maintains standard protocol interoperability at each individual certificate authority level while segmenting the trust function across multiple authorities. This allows each certificate authority to use standard protocols independently, ensuring interoperability, while the segmented architecture ensures that compromise of one authority does not affect the overall system security through the quorum requirement.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8745379B2Systems and methods for securing data in motion
Publication Date: 2014.06.03 SECURITY FIRST INNOVATIONS LLC
  • US8745379B2 patent drawing
  • US8745379B2 patent drawing
  • US8745379B2 patent drawing

AI summary

Two approaches are provided for distributing trust among a set of certificate authorities. Each approach may be used to secure data in motion. One approach provides methods and systems in which the secure data parser is used to distribute trust in a set of certificate authorities during initial negotiation (e.g., the key establishment phase) of a connection between two devices. Another approach provides methods and systems in which the secure data parser is used to disperse packets of data into shares. A set of tunnels is established within a communication channel using a set of certificate authorities, keys developed during the establishment of the tunnels are used to encrypt shares of data for each of the tunnels, and the shares of data are transmitted through each of the tunnels. Accordingly, trust is distributed among a set of certificate authorities in the structure of the communication channel itself.