Distributed PKI Alliance Framework for Mobile Network Resiliency

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security protocols for NextG mobile networks rely on centralized Public Key Infrastructure (PKI), making them vulnerable to attacks, scalability issues, and single-point-of-failure challenges, particularly in emerging post-quantum-safe practices, which necessitate a distributed and resilient infrastructure.

Innovation Solution

The implementation of a Distributed PKI Alliance Framework using umbrella public keys and threshold cryptography allows multiple Certificate Authorities to collaborate for secure authentication and digital certificate generation without exposing individual private keys, enabling distributed trust and fault tolerance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If centralized Public Key Infrastructure (PKI) is used for network security, then security management is simplified, but the system becomes vulnerable to attacks, single-point-of-failure, and scalability issues

Engineering Contradiction:
Improvesecurity management complexityVSAvoidnetwork resiliency
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent divides the centralized PKI into multiple distributed Certificate Authorities (CAs) organized in a hierarchical structure. Root CAs issue certificates to intermediate CAs, which in turn issue certificates to end entities. This segmentation eliminates the single-point-of-failure vulnerability while maintaining simplified security management through the hierarchical trust model.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a hierarchical dimension to the PKI structure, organizing CAs into multiple levels (root, intermediate, end-entity). This dimensional organization allows the system to achieve both distributed reliability and simplified management by establishing clear trust relationships across different hierarchical layers.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If distributed PKI alliance framework is implemented, then network resiliency and fault tolerance are improved, but computational overhead and complexity increase

Engineering Contradiction:
Improvenetwork resiliencyVSAvoidcomputational overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the computational workload across multiple CAs in the alliance. Each CA performs signature verification and certificate validation independently, distributing the computational burden. This segmentation reduces the complexity burden on any single entity while maintaining overall system resiliency.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary action by pre-establishing trust relationships and digital certificates during the offline setup phase. Certificate authorities generate and exchange cryptographic keys and certificates before the actual network operation begins. This preliminary preparation reduces real-time computational overhead during network operations.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If multiple Certificate Authorities collaborate for authentication, then trust distribution and security are enhanced, but communication overhead and authentication time increase

Engineering Contradiction:
Improvetrust distributionVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the authentication process into distinct phases: offline setup phase where trust relationships are established, and online operation phase where pre-established certificates are verified. This segmentation moves time-consuming collaborative operations to the offline phase, reducing authentication time during online operations while maintaining trust distribution.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary action by establishing all necessary trust relationships, digital certificates, and cryptographic credentials during the offline setup phase. Multiple CAs collaborate in advance to create a web of trust that is then reused during online operations, significantly reducing authentication time while maintaining enhanced trust distribution.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If post-quantum cryptography is adopted, then future security is ensured, but computational overhead and key size increase

Engineering Contradiction:
Improvefuture securityVSAvoidcomputational overhead
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent segments the cryptographic operations across multiple distributed CAs, reducing the computational burden on any single entity. Each CA performs a portion of the cryptographic verification and signature operations, distributing the energy-intensive post-quantum cryptography workload while ensuring future security.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20240396744A1System and method for increased resiliency of mobile wireless networks via distributed public-key infrastructure (PKI) alliances
Publication Date: 2024.11.28 THE STATE OF OREGON ACTING BY & THROUGH THE OREGON STATE BOARD OF HIGHER EDUCATION ON BEHALF OF OREGON STATE UNIV
  • US20240396744A1 patent drawing
  • US20240396744A1 patent drawing
  • US20240396744A1 patent drawing

AI summary

Systems, devices, and methods are disclosed herein that implement efficient frameworks for Public-Key Infrastructure (PKI) functions. In some implementations of such frameworks, a PKI alliance may comprise multiple, independent certification authorities (CAs), that can coordinate signing operations for digital certificates based on umbrella public keys that a device can use for authentication with any of the CAs. Some embodiments may use multi-party computational thresholding in such signing operations. In other aspects, a device may generate an umbrella public/private key pair, and obtain a digital certificate for the umbrella public key which can be used for efficient network handoffs among CAA members and other secure connections.