Dynamic-PKI Certificate Authority for IoT Device Identity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Public Key Infrastructure (PKI) systems require complex and costly processes for certificate issuance and management, often necessitating external configuration of user ownership with devices, which burdens manufacturers and limits adoption due to complexity and cost.

Innovation Solution

The Dynamic-PKI system generates and issues certificates at deployment time, incorporating an automated protocol for certificate issuance and management, allowing both device and user association within a certificate, and enabling seamless transfer of certificates between users, thus simplifying the process and reducing manufacturer burdens.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If certificates are pre-provisioned during manufacturing, then device identity is established, but manufacturer cost and supply chain burden increase

Engineering Contradiction:
Improvedevice identity establishmentVSAvoidmanufacturer cost and supply chain burden
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The system performs preliminary actions by having the manufacturer provision only a root certificate and public key during manufacturing, rather than complete device certificates. This preliminary setup enables later automated certificate issuance at deployment time, reducing manufacturing complexity while ensuring device identity can be established.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

A new automated certificate issuance system acts as an intermediary between the manufacturer and the device. This intermediary handles the complex certificate issuance process at deployment time using the pre-provisioned root certificate and public key, eliminating the need for manufacturers to directly manage complex PKI processes during manufacturing.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If certificates are issued with complex verification procedures, then security is improved, but issuance process complexity increases

Engineering Contradiction:
Improvecertificate securityVSAvoidcertificate issuance process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements self-service by enabling devices to automatically obtain their own certificates at deployment time using pre-provisioned credentials. The automated issuance process eliminates the need for manual verification procedures, reducing complexity while maintaining security through cryptographic verification of device identity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual verification procedures (mechanical processes) with automated cryptographic verification. The system uses digital signatures and public key infrastructure to automatically verify device identity and issue certificates, substituting complex human-mediated verification processes with streamlined automated cryptographic operations.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If certificates are tied only to device, then device identity is secured, but user ownership association is lost

Engineering Contradiction:
Improvedevice identity securityVSAvoiduser ownership association
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system merges device identity and user ownership information into a single certificate structure. The certificate contains both device identifiers and user identity information, allowing the certificate to serve dual purposes: securing device identity and establishing user ownership association simultaneously.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The certificate is designed with multi-functionality, serving both as a device identity credential and a user ownership proof. This universal certificate structure eliminates the need for separate mechanisms to establish device identity and user ownership, enabling flexible transfer of ownership while maintaining device security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If users must understand private key protection, then security awareness is improved, but user adoption decreases

Engineering Contradiction:
Improvesecurity awarenessVSAvoiduser adoption
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements self-service by automatically managing private key protection without requiring user intervention or understanding. The device automatically protects and manages its private keys, and users can transfer ownership through simple operations without needing to understand cryptographic concepts.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The automated certificate issuance system acts as an intermediary that handles all private key management operations. Users interact with high-level operations (such as ownership transfer requests) while the intermediary system manages the complex private key protection, generation, and transfer processes in the background.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11716207B1System and method for a dynamic-PKI for a social certificate authority
Publication Date: 2023.08.01 CABLE TELEVISION LAB INC
  • US11716207B1 patent drawing
  • US11716207B1 patent drawing
  • US11716207B1 patent drawing

AI summary

Dynamic-PKI social Certificate Authority (CA) systems and methods are provided, which generate and issue certificates at time of device deployment instead of time of manufacture. The provided systems and methods utilize an interface to initiate a Certificate Signing Request (CSR), and which then generates and signs the CSR with a public key. The signed CSR is then securely transmitted to a Certificate Signing Request Processor (CSRP), which undergoes an optional verification process and is then processed to return a signed certificate. The signed certificate is then directly or indirectly provided to the device for provisioning into the network.