Expiring Revocable Certificates for Secure Cloud Connections
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional asymmetric encryption techniques are inadequate for securing communications over networks, particularly in public cloud environments, as they do not effectively address the issue of stolen credentials being used to establish new secure connections and are vulnerable to connection losses.
Innovation Solution
Implementing an asymmetric encryption scheme with expiring revocable certificates that have a predefined validity period, where certificates are revoked and renewed regularly to prevent misuse by attackers and maintain security even during connection losses.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If certificates have long validity periods to maintain continuous secure connections during network interruptions, then connection reliability is improved, but security is worsened because stolen credentials remain valid for extended periods
Solution Approach 1:
The patent applies dynamics by making certificate validity conditional rather than static. Certificates have a base validity period that can be dynamically extended or revoked based on connection status. When connections are lost, validity extends automatically; when connections are successful, validity is revoked earlier, creating a dynamic adaptation to network conditions that resolves the contradiction between reliability and security
Solution Approach 2:
The patent changes the time parameter of certificate validity based on connection events. The validity period is not fixed but adjusts according to whether connections are maintained or lost. This parameter change allows the system to extend validity during interruptions (improving reliability) while revoking it early upon successful reconnection (maintaining security), thus resolving the contradiction
2Object-affected harmful factors
If certificates are revoked frequently to prevent credential theft, then security is improved, but connection reliability is worsened due to vulnerability during revocation transitions
Solution Approach 1:
The patent applies beforehand cushioning by extending certificate validity beyond the normal revocation time when connections are lost. This creates a buffer period that cushions against connection interruptions, ensuring that if revocation occurs during network issues, the extended validity prevents connection failures. This resolves the contradiction by protecting against both security threats and connection reliability issues during transitions
3Reliability
If certificates remain valid during connection losses to maintain resilience, then connection reliability is improved, but security is worsened as stolen credentials could be used during the loss period
Solution Approach 1:
The patent applies feedback by monitoring connection status and using this information to adjust certificate validity. The system receives feedback about connection losses and responds by extending validity; when successful connections are detected, it revokes certificates early. This feedback mechanism resolves the contradiction by maintaining validity during losses (improving reliability) while automatically revoking when security risks are detected (maintaining security)
Data Source
AI summary
Methods and apparatus are provided for an asymmetric encryption scheme with expiring revocable certificates having a predefined validity period. Communications between two devices are secured by obtaining an expiring revocable certificate; and securing said communicating with said expiring revocable certificate using asymmetric encryption. A prior expiring revocable certificate can be revoked when a new expiring revocable certificate is issued to at least one device. The expiring revocable certificate has a predefined validity period (based, for example, on a longest expected connection drop-out duration). A new expiring revocable certificate is requested at least once for each predefined revocation period. The expiring revocable certificate is revoked after the predefined revocation period, for example, only if a connection between the two devices is maintained.


