Communication Apparatus Dual Certificate Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication systems face challenges in reliably and securely updating digital certificates and keys, particularly over the Internet, where tampering and eavesdropping risks are high, leading to potential authentication failures and insecure communication if updates are not properly managed.

Innovation Solution

A communication system that employs multiple addresses for providing individual and common digital certificates, with the ability to authenticate and update certificates securely using a common public-key certificate for backup authentication, ensuring continuous secure communication even if individual certificates become unavailable.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If individual digital certificates are used for authentication, then authentication reliability is improved, but system complexity increases due to certificate management and updates

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidcertificate management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the digital certificate into two distinct types: individual certificates for authentication and common certificates for backup authentication. This segmentation allows the system to maintain high authentication reliability through individual certificates while managing complexity by providing a simplified backup mechanism via common certificates that can be shared across multiple devices.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The common certificate acts as an intermediary backup mechanism between the individual certificate and the authentication process. When individual certificate updates fail or are unavailable, the common certificate mediates the authentication process, ensuring continuous operation without requiring direct management of complex individual certificate lifecycles across all devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If certificate updates are performed over the Internet, then adaptability is improved, but security deteriorates due to tampering and eavesdropping risks

Engineering Contradiction:
Improvecertificate update capabilityVSAvoidtampering and eavesdropping risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements beforehand cushioning by pre-configuring devices with common certificates that can serve as backup authentication credentials. This preparatory measure cushions against the harmful effects of tampering and eavesdropping during certificate updates, as devices can fall back to common certificates if individual certificate updates are compromised or fail.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Solution Approach 2:

The patent uses copying by distributing common certificates to multiple devices as replicas of the authentication credential. These copies serve as redundant authentication means that can be used if the primary individual certificates are compromised during internet-based updates, thereby maintaining security while enabling adaptability.

Inventive Principle:
Principle #26Copying

3Adaptability or versatility

If multiple addresses are used for certificate provision, then adaptability is improved, but device complexity increases

Engineering Contradiction:
Improvecertificate provision flexibilityVSAvoidaddress management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies universality by designing the communication apparatus to provide both individual and common certificates through a unified interface that handles multiple addresses. This multi-functional approach allows the system to maintain adaptability in certificate provision while avoiding the complexity of separate management mechanisms for different addresses, as the same apparatus handles all certificate operations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7451307B2Communication apparatus, communication system, communication apparatus control method and implementation program thereof
Publication Date: 2008.11.11 RICOH CO LTD
  • US7451307B2 patent drawing
  • US7451307B2 patent drawing
  • US7451307B2 patent drawing

AI summary

A communication apparatus, a communication system, a communication apparatus control method and a recording medium for storing an implementation program thereof are disclosed. The communication apparatus includes a communication part providing a communicating party with an individual certificate with identification information thereof as via a first address and a common certificate without the identification information via a second address; a request execution part executing a process corresponding to a request received from the communicating party; and a denial part denying any process corresponding to requests other than a request to set the individual certificate in communication via the second address. According to the invention, it is possible to easily maintain a condition where authentication can be properly performed while maintaining security of communication.