Independent Certificate Chains for PKI Failure Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Certificate chains in public key infrastructures can be a single-point-of-failure, leading to sudden and widespread delays or failures in computational and network activities due to expiration or unreachability of certificate authorities, with no effective server-side mitigation strategies.

Innovation Solution

Implementing a certificate management system that maintains two independent certificate chains, allowing automatic selection and serving of a functional certificate when one chain fails, ensuring redundancy and minimizing downtime by enforcing chain independence criteria such as no shared root or intermediate certificates, CRLs, and OCSP endpoints.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single certificate chain is used in a computing network, then the system structure is simple and easy to manage, but the system becomes a single-point-of-failure that can cause widespread delays or failures when the certificate authority expires or becomes unreachable

Engineering Contradiction:
Improvecertificate chain reliabilityVSAvoidcertificate management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the certificate infrastructure into multiple independent certificate chains, where each chain is a separate segment with its own certificate authority. This segmentation ensures that failure in one chain does not affect other chains, eliminating the single-point-of-failure problem while maintaining manageable complexity through modular architecture

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the parameter of certificate chain configuration from a single chain to multiple chains with different independence levels (fully independent, partially independent, or hybrid configurations). This allows systems to adjust the number and structure of certificate chains based on specific reliability requirements and complexity tolerances

Inventive Principle:
Principle #35Parameter changes

2Reliability

If multiple independent certificate chains are maintained for redundancy, then the system reliability improves and failure impact is reduced, but the system complexity and management overhead increase

Engineering Contradiction:
Improvenetwork continuityVSAvoidcertificate chain management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic certificate chain selection and switching mechanisms that automatically adjust which certificate chains are active based on real-time conditions such as chain health status, expiration dates, and performance metrics. This dynamic approach maintains high reliability through automatic failover while reducing management complexity by eliminating the need for manual intervention in chain selection

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates self-service capabilities including automatic monitoring of certificate chain status, automated selection of valid chains, and autonomous switching between chains when failures are detected. This self-service automation significantly reduces the operational management overhead of maintaining multiple certificate chains while ensuring continuous network reliability

Inventive Principle:
Principle #25Self-service

3Ease of operation

If certificate chains share common root or intermediate certificates, then the management and validation process is simplified, but the independence between chains is reduced and the blast radius of failures increases

Engineering Contradiction:
Improvecertificate validationVSAvoidfailure isolation
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies local quality by allowing different certificate chains to have different levels of independence based on their specific requirements. Some chains may share common root certificates for simplified validation where failure isolation is less critical, while other chains maintain complete independence for applications requiring strict failure isolation. This localized approach to independence optimizes both validation ease and reliability for different system components

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12470405B2Secure certificate chain transition
Publication Date: 2025.11.11 MICROSOFT TECHNOLOGY LICENSING LLC
  • US12470405B2 patent drawing
  • US12470405B2 patent drawing
  • US12470405B2 patent drawing

AI summary

Some embodiments provide proxies or other servers in a computing network with independent certificate chains which facilitate mitigation of certificate problems. Independence criteria are enforced against two or more installed certificate chains on a given server, identifying and avoiding dependencies such as cross-certification, shared certificate authorities, shared revocation lists, or shared certificate status protocol endpoints between the certificate chains. Some embodiments serve independent certificates concurrently in an active-active certificate server configuration. The certificate chains' coexistence and their independence from one another facilitates transitioning the network from a failing issuer or a failed chain to a chain that works better, thereby improving network resilience and limiting damage from certificate problems. By dynamically updating certificate bindings, some embodiments also facilitate safe deployment of new certificates during migration from one issuer to another. Certificate distributions are computed from issuer ratios, network topology, or both.