Future Certificate Revocation in CRL Framework

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Public Key Infrastructure (PKI) systems face challenges in managing unscheduled certificate updates, particularly in large networks, where manual intervention is often required due to the lack of native mechanisms for triggering updates in End Entities (EEs), leading to interoperability issues and increased administrative burdens.

Innovation Solution

The implementation of a Certificate Revocation List (CRL) framework that includes future revocation information to trigger unscheduled updates of Trust Anchor (TA) and other certificates, allowing for automated and seamless migration of certificates within the PKI, reducing manual effort and ensuring security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual intervention is used to manage unscheduled certificate updates, then certificate security can be maintained, but administrative burden and complexity increase significantly

Engineering Contradiction:
Improvecertificate securityVSAvoidadministrative burden
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables End Entities to automatically detect future revocation information in CRLs and trigger their own certificate update processes without manual intervention. The EE autonomously monitors CRLs, detects future revocation entries, and initiates update requests to the CA, making the system self-managing while maintaining security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements a feedback mechanism where the CA publishes future revocation information in CRLs, which EEs continuously monitor. When EEs detect their certificate is scheduled for future revocation, they trigger update requests, creating a closed-loop feedback system that automates certificate lifecycle management while maintaining security control.

Inventive Principle:
Principle #23Feedback

2Productivity

If automated certificate update mechanisms are implemented, then administrative effort is reduced, but native PKI mechanisms must be extended which increases system complexity

Engineering Contradiction:
Improveautomation efficiencyVSAvoidPKI mechanism complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The invention repurposes the existing CRL mechanism, originally designed only for indicating current revocations, to also convey future revocation information. This multi-functional use of the CRL structure allows automated triggering of certificate updates without requiring entirely new PKI components, thus reducing overall system complexity while enabling automation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system publishes future revocation information in CRLs before the actual revocation occurs. This preliminary action allows End Entities to proactively initiate certificate updates before their current certificates become invalid, ensuring seamless transitions and avoiding security gaps while maintaining automation.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If future revocation information is included in CRLs, then seamless certificate migration is enabled, but CRL size and processing requirements increase

Engineering Contradiction:
Improvecertificate migration continuityVSAvoidCRL data volume
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

Instead of including detailed future revocation information for all possible certificates, the system selectively includes only those certificates that are actually scheduled for future revocation. This partial action approach minimizes CRL data volume while providing sufficient information for EEs to trigger necessary updates, balancing migration continuity with data efficiency.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10735208B2Future certificate revocation using CRL
Publication Date: 2020.08.04 NOKIA SOLUTIONS & NETWORKS OY
  • US10735208B2 patent drawing
  • US10735208B2 patent drawing
  • US10735208B2 patent drawing

AI summary

It is provided a method, including checking if an indication is received that a certificate installed in a communication entity is to be revoked at a revocation time in the future; preparing, if the indication is received, a first revocation list, wherein the first revocation list includes an identifier of the certificate and the revocation time; providing the first revocation list to the communication entity.