Future Certificate Revocation in CRL Framework
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Public Key Infrastructure (PKI) systems face challenges in managing unscheduled certificate updates, particularly in large networks, where manual intervention is often required due to the lack of native mechanisms for triggering updates in End Entities (EEs), leading to interoperability issues and increased administrative burdens.
Innovation Solution
The implementation of a Certificate Revocation List (CRL) framework that includes future revocation information to trigger unscheduled updates of Trust Anchor (TA) and other certificates, allowing for automated and seamless migration of certificates within the PKI, reducing manual effort and ensuring security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual intervention is used to manage unscheduled certificate updates, then certificate security can be maintained, but administrative burden and complexity increase significantly
Solution Approach 1:
The system enables End Entities to automatically detect future revocation information in CRLs and trigger their own certificate update processes without manual intervention. The EE autonomously monitors CRLs, detects future revocation entries, and initiates update requests to the CA, making the system self-managing while maintaining security.
Solution Approach 2:
The system implements a feedback mechanism where the CA publishes future revocation information in CRLs, which EEs continuously monitor. When EEs detect their certificate is scheduled for future revocation, they trigger update requests, creating a closed-loop feedback system that automates certificate lifecycle management while maintaining security control.
2Productivity
If automated certificate update mechanisms are implemented, then administrative effort is reduced, but native PKI mechanisms must be extended which increases system complexity
Solution Approach 1:
The invention repurposes the existing CRL mechanism, originally designed only for indicating current revocations, to also convey future revocation information. This multi-functional use of the CRL structure allows automated triggering of certificate updates without requiring entirely new PKI components, thus reducing overall system complexity while enabling automation.
Solution Approach 2:
The system publishes future revocation information in CRLs before the actual revocation occurs. This preliminary action allows End Entities to proactively initiate certificate updates before their current certificates become invalid, ensuring seamless transitions and avoiding security gaps while maintaining automation.
3Reliability
If future revocation information is included in CRLs, then seamless certificate migration is enabled, but CRL size and processing requirements increase
Solution Approach 1:
Instead of including detailed future revocation information for all possible certificates, the system selectively includes only those certificates that are actually scheduled for future revocation. This partial action approach minimizes CRL data volume while providing sufficient information for EEs to trigger necessary updates, balancing migration continuity with data efficiency.
Data Source
AI summary
It is provided a method, including checking if an indication is received that a certificate installed in a communication entity is to be revoked at a revocation time in the future; preparing, if the indication is received, a first revocation list, wherein the first revocation list includes an identifier of the certificate and the revocation time; providing the first revocation list to the communication entity.


