Dual Certificate Authentication for Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication systems using digital certificates for authentication face challenges in quickly and automatically detecting anomalies, leading to prolonged downtime and security breaches when key pairs are compromised or unusable, requiring manual updates and low productivity in key distribution.

Innovation Solution

Implementing a communication apparatus with dual certificate management, using an individualized certificate with identification information and a common certificate without identification information, allowing for automatic anomaly detection and rapid restoration of authentication through SSL/TLS protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual key pair updates are performed when anomalies are detected, then authentication can be restored, but the system experiences prolonged downtime and reduced productivity

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidkey distribution productivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent pre-configures multiple certificate authorities (CAs) with different key pairs before anomalies occur. When an anomaly is detected in the current CA's key pair, the system can immediately switch to a pre-configured backup CA without manual intervention or downtime, resolving the contradiction between maintaining authentication reliability and avoiding productivity loss.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a CA management apparatus as an intermediary that automatically manages key pair distribution and anomaly detection. This intermediary system continuously monitors the status of key pairs and automatically distributes new key pairs to communication apparatuses when anomalies are detected, eliminating manual updates and prolonged downtime while maintaining authentication reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If individualized certificates with identification information are used for authentication, then communication partner validation is improved, but anomaly detection and key updates become more complex

Engineering Contradiction:
Improvecommunication partner validationVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the CA system into multiple independent CA apparatuses, each with its own key pair. This segmentation allows the system to isolate anomalies to specific CAs while maintaining others operational. The communication apparatus stores multiple individualized certificates corresponding to different CAs, enabling automatic switching when one CA experiences anomalies, thus reducing overall system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the parameter of certificate validity by introducing expiration dates and status monitoring. When a CA's key pair is compromised or becomes unusable, the system automatically detects this change in status and switches to a valid alternative CA, simplifying anomaly detection from manual inspection to automated parameter monitoring.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If dual certificate management (individualized and common certificates) is implemented, then authentication resilience is improved, but device complexity increases

Engineering Contradiction:
Improveauthentication resilienceVSAvoidcertificate management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes the CA management apparatus universal by enabling it to manage multiple types of certificates (individualized certificates with identification information and common certificates without identification information). This multi-functional CA management system handles both normal authentication operations and anomaly recovery, improving authentication resilience while consolidating complexity into a single management apparatus rather than分散 across multiple devices.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7694333B2Communication apparatus, communication system, certificate transmission method, anomaly detection method and a program therefor
Publication Date: 2010.04.06 RICOH CO LTD
  • US7694333B2 patent drawing
  • US7694333B2 patent drawing
  • US7694333B2 patent drawing

AI summary

A communication apparatus has a communication part and authenticates a communication partner by using a digital certificate, wherein the communication apparatus includes an authentication part carrying out authentication of the communication partner by using a common certificate, the common certificate being a digital certificate not including identification information of an apparatus, and an individualized certificate transmission part acquiring, in the case the authentication by the authentication part has been made successfully, individualized certificate and transmitting the individualized certificate to said communication partner, the individualized certificate being a digital certificate including identification information of the communication partner.