Dynamic Security Certificate Generation via User Trust

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Internet security protocols using security certificates fail to allow malware or virus detection on user devices to inspect encrypted data, as automatically generated dynamic certificates by man-in-the-middle proxies are not trusted by client applications due to lack of user input and trust indication.

Innovation Solution

A method and apparatus for generating a dynamic security certificate using user input to create an entropic element and metadata, which is then trusted by the user, allowing it to be used as a trusted certificate for monitoring data flow, such as in a man-in-the-middle proxy application.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a man-in-the-middle proxy automatically generates a dynamic certificate to enable data inspection, then malware or virus detection capability is improved, but the certificate is not trusted by the client application causing disconnection

Engineering Contradiction:
Improvemalware detection capabilityVSAvoidcertificate trust acceptance
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary user interaction during certificate generation, obtaining explicit user input and trust indication before the certificate is used. This preliminary action of user authorization ensures the certificate is pre-trusted by the client application, preventing disconnection and enabling seamless malware detection operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces user input and trust indication as an intermediary element between the automatic certificate generation process and the client application's trust verification. This intermediary user authorization acts as a bridge that validates the dynamically generated certificate, allowing the MITM proxy to maintain trusted connections while enabling data inspection for security purposes.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If automatic certificate generation is used without user input, then ease of operation is improved, but the certificate is recognized as a security risk

Engineering Contradiction:
Improveautomatic certificate generationVSAvoidsecurity risk recognition
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary user interaction during certificate generation, obtaining explicit user input and trust indication before the certificate is used. This preliminary action of user authorization ensures the certificate is pre-trusted by the client application, preventing disconnection and enabling seamless malware detection operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces user input and trust indication as an intermediary element between the automatic certificate generation process and the client application's trust verification. This intermediary user authorization acts as a bridge that validates the dynamically generated certificate, allowing the MITM proxy to maintain trusted connections while enabling data inspection for security purposes.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If encrypted data is transmitted to protect security, then data security is improved, but malware or virus detection applications cannot inspect the data

Engineering Contradiction:
Improvedata securityVSAvoiddata inspection capability
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The MITM proxy application acts as an intermediary that establishes separate encrypted connections with both the client and server, decrypting and re-encrypting data in the process. This intermediary position allows security software to inspect the decrypted data for malware while maintaining end-to-end encryption, thus preserving both data security and inspection capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The encryption process is segmented into separate stages: initial encryption by the proxy, inspection of decrypted content by security software, and re-encryption for transmission. This segmentation allows the encrypted data flow to be divided into secure transmission segments and inspectable content segments, enabling simultaneous security and detection.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11909894B2Method and apparatus for generating a dynamic security certificate
Publication Date: 2024.02.20 UAB 360 IT
  • US11909894B2 patent drawing
  • US11909894B2 patent drawing
  • US11909894B2 patent drawing

AI summary

A method and apparatus for generating a dynamic security certificate. The method creates an entropic element from user input, receives metadata from user input and generates a dynamic security certificate using the entropic element and the metadata. The dynamic security certificate is then trusted through user input.