Distributed Trust Formation via Certificate Exchange

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Establishing secure communication channels between multiple computer systems is challenging due to the need for manual key management and the risk of single points of failure in centralized key management systems.

Innovation Solution

Implementing a method to establish trusted communication relationships between computing devices by exchanging certificates and credentials, allowing for secure communication without relying on centralized key management servers or manual administrator intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a centralized key management server is used, then key management is simplified, but a single point of failure is created

Engineering Contradiction:
Improvekey managementVSAvoidsystem availability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the centralized key management function into distributed key management capabilities at each computing device. Each device independently manages its own cryptographic keys and certificates without relying on a central server, thereby eliminating the single point of failure while maintaining key management functionality through decentralized autonomous operation

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces certificates as intermediary credentials that enable trust establishment between computing devices without requiring direct key exchange or a central mediator. The certificates serve as portable trust anchors that can be exchanged and verified peer-to-peer, replacing the need for a centralized key management server

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manual administrator intervention is used for key upload, then security control is improved, but administrative effort increases

Engineering Contradiction:
Improvesecurity controlVSAvoidadministrative efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent enables computing devices to autonomously generate, manage, and exchange their own cryptographic keys and certificates without requiring manual administrator intervention. Each device performs self-service key management operations including key generation, certificate creation, and secure exchange, thereby eliminating tedious manual tasks while maintaining security through automated cryptographic protocols

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent performs preliminary key generation and certificate creation at each computing device before deployment or communication needs arise. By pre-configuring cryptographic credentials locally rather than requiring post-deployment manual key uploads, the system eliminates administrative effort while ensuring security credentials are ready for immediate use

Inventive Principle:
Principle #10Preliminary action

3Reliability

If two-way trust is established between computing devices, then secure communication is achieved, but key exchange complexity increases

Engineering Contradiction:
Improvecommunication securityVSAvoidkey exchange process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses certificate copying as a simplified mechanism for establishing two-way trust. Instead of complex mutual key exchange protocols, each device creates a copy of its certificate and exchanges it with the other device. The receiving device verifies the certificate and stores it for future verification, thereby establishing bidirectional trust through simple certificate replication and verification

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent inverts the traditional approach by having devices share their certificates (public verification credentials) rather than exchanging private keys. This inversion simplifies the trust establishment process because certificates can be freely copied and verified without security risks, whereas private keys must never be exchanged. The trust relationship is established by sharing verification materials rather than secret materials

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentUS12224997B2Multi-way trust formation in a distributed system
Publication Date: 2025.02.11 HITACHI VANTARA LLC
  • US12224997B2 patent drawing
  • US12224997B2 patent drawing
  • US12224997B2 patent drawing

AI summary

In some examples, a first computing device associated with a first site may receive a certificate of a second computing device associated with a second site that is different from the first site. The first computing device may send, to the second computing device, a credential of a user associated with the second site. In addition, the first computing device may send to the second computing device, a certificate of the first computing device. Furthermore, based at least on authentication of the credential of the user by the second computing device, trusted communications may be established between the first computing device and the second computing device.