Independent Certificate Chains for PKI Failure Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Certificate chains in public key infrastructures can be a single-point-of-failure, leading to sudden and widespread delays or failures in computational and network activities due to expiration or unreachability of certificate authorities, with no effective server-side mitigation strategies.
Innovation Solution
Implementing a certificate management system that maintains two independent certificate chains, allowing automatic selection and serving of a functional certificate when one chain fails, ensuring redundancy and minimizing downtime by enforcing chain independence criteria such as no shared root or intermediate certificates, CRLs, and OCSP endpoints.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a single certificate chain is used in a computing network, then the system structure is simple and easy to manage, but the system becomes a single-point-of-failure that can cause widespread delays or failures when the certificate authority expires or becomes unreachable
Solution Approach 1:
The patent divides the certificate infrastructure into multiple independent certificate chains, where each chain is a separate segment with its own certificate authority. This segmentation ensures that failure in one chain does not affect other chains, eliminating the single-point-of-failure problem while maintaining manageable complexity through modular architecture
Solution Approach 2:
The patent changes the parameter of certificate chain configuration from a single chain to multiple chains with different independence levels (fully independent, partially independent, or hybrid configurations). This allows systems to adjust the number and structure of certificate chains based on specific reliability requirements and complexity tolerances
2Reliability
If multiple independent certificate chains are maintained for redundancy, then the system reliability improves and failure impact is reduced, but the system complexity and management overhead increase
Solution Approach 1:
The patent implements dynamic certificate chain selection and switching mechanisms that automatically adjust which certificate chains are active based on real-time conditions such as chain health status, expiration dates, and performance metrics. This dynamic approach maintains high reliability through automatic failover while reducing management complexity by eliminating the need for manual intervention in chain selection
Solution Approach 2:
The system incorporates self-service capabilities including automatic monitoring of certificate chain status, automated selection of valid chains, and autonomous switching between chains when failures are detected. This self-service automation significantly reduces the operational management overhead of maintaining multiple certificate chains while ensuring continuous network reliability
3Ease of operation
If certificate chains share common root or intermediate certificates, then the management and validation process is simplified, but the independence between chains is reduced and the blast radius of failures increases
Solution Approach 1:
The patent applies local quality by allowing different certificate chains to have different levels of independence based on their specific requirements. Some chains may share common root certificates for simplified validation where failure isolation is less critical, while other chains maintain complete independence for applications requiring strict failure isolation. This localized approach to independence optimizes both validation ease and reliability for different system components
Data Source
AI summary
Some embodiments provide proxies or other servers in a computing network with independent certificate chains which facilitate mitigation of certificate problems. Independence criteria are enforced against two or more installed certificate chains on a given server, identifying and avoiding dependencies such as cross-certification, shared certificate authorities, shared revocation lists, or shared certificate status protocol endpoints between the certificate chains. Some embodiments serve independent certificates concurrently in an active-active certificate server configuration. The certificate chains' coexistence and their independence from one another facilitates transitioning the network from a failing issuer or a failed chain to a chain that works better, thereby improving network resilience and limiting damage from certificate problems. By dynamically updating certificate bindings, some embodiments also facilitate safe deployment of new certificates during migration from one issuer to another. Certificate distributions are computed from issuer ratios, network topology, or both.


