Expiring Revocable Certificates for Secure Cloud Connections

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional asymmetric encryption techniques are inadequate for securing communications over networks, particularly in public cloud environments, as they do not effectively address the issue of stolen credentials being used to establish new secure connections and are vulnerable to connection losses.

Innovation Solution

Implementing an asymmetric encryption scheme with expiring revocable certificates that have a predefined validity period, where certificates are revoked and renewed regularly to prevent misuse by attackers and maintain security even during connection losses.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If certificates have long validity periods to maintain continuous secure connections during network interruptions, then connection reliability is improved, but security is worsened because stolen credentials remain valid for extended periods

Engineering Contradiction:
Improveconnection reliabilityVSAvoidsecurity risk from stolen credentials
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies dynamics by making certificate validity conditional rather than static. Certificates have a base validity period that can be dynamically extended or revoked based on connection status. When connections are lost, validity extends automatically; when connections are successful, validity is revoked earlier, creating a dynamic adaptation to network conditions that resolves the contradiction between reliability and security

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the time parameter of certificate validity based on connection events. The validity period is not fixed but adjusts according to whether connections are maintained or lost. This parameter change allows the system to extend validity during interruptions (improving reliability) while revoking it early upon successful reconnection (maintaining security), thus resolving the contradiction

Inventive Principle:
Principle #35Parameter changes

2Object-affected harmful factors

If certificates are revoked frequently to prevent credential theft, then security is improved, but connection reliability is worsened due to vulnerability during revocation transitions

Engineering Contradiction:
Improvesecurity against credential theftVSAvoidconnection stability during revocation
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The patent applies beforehand cushioning by extending certificate validity beyond the normal revocation time when connections are lost. This creates a buffer period that cushions against connection interruptions, ensuring that if revocation occurs during network issues, the extended validity prevents connection failures. This resolves the contradiction by protecting against both security threats and connection reliability issues during transitions

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

3Reliability

If certificates remain valid during connection losses to maintain resilience, then connection reliability is improved, but security is worsened as stolen credentials could be used during the loss period

Engineering Contradiction:
Improveconnection resilience during dropsVSAvoidsecurity vulnerability during connection loss
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies feedback by monitoring connection status and using this information to adjust certificate validity. The system receives feedback about connection losses and responds by extending validity; when successful connections are detected, it revokes certificates early. This feedback mechanism resolves the contradiction by maintaining validity during losses (improving reliability) while automatically revoking when security risks are detected (maintaining security)

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9118487B1Asymmetric encryption scheme with expiring revocable certificates having a predefined validity period
Publication Date: 2015.08.25 EMC IP HLDG CO LLC
  • US9118487B1 patent drawing
  • US9118487B1 patent drawing
  • US9118487B1 patent drawing

AI summary

Methods and apparatus are provided for an asymmetric encryption scheme with expiring revocable certificates having a predefined validity period. Communications between two devices are secured by obtaining an expiring revocable certificate; and securing said communicating with said expiring revocable certificate using asymmetric encryption. A prior expiring revocable certificate can be revoked when a new expiring revocable certificate is issued to at least one device. The expiring revocable certificate has a predefined validity period (based, for example, on a longest expected connection drop-out duration). A new expiring revocable certificate is requested at least once for each predefined revocation period. The expiring revocable certificate is revoked after the predefined revocation period, for example, only if a connection between the two devices is maintained.