Identity Contact Expression for Cross-CA Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Public key infrastructure faces challenges in authenticating users across different certificate authorities, as credentials issued by one authority may not be recognized or usable by another, limiting secure communication and transactions between users with different grounds of authentication.

Innovation Solution

The implementation of identity contact expressions that dynamically incorporate and manage multiple user certificates, allowing users to authenticate and authorize communications based on shared relationships, regardless of the original issuance ground, and enabling the use of certificates for various contexts, including friend or acquaintance relationships.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If public key infrastructure utilizes credentials issued by a certificate authority to authenticate user identity, then authentication reliability is improved, but credential compatibility across different certificate authorities deteriorates

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidcredential compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces an intermediary mechanism that translates credentials from different certificate authorities into a common authentication language. This intermediary layer enables users authenticated by one CA to interact with users authenticated by another CA, resolving the incompatibility issue while maintaining the security guarantees of each individual CA.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a universal credential representation that can function across multiple certificate authority ecosystems. By designing credentials to be multi-functional and interpretable by different CAs, the system enables a single credential to work across diverse authentication grounds, improving both compatibility and versatility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If a user holds credentials from multiple certificate authorities, then authentication versatility is improved, but the ability to use either credential to authenticate to another user deteriorates

Engineering Contradiction:
Improveauthentication versatilityVSAvoidcredential usability
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent implements dynamic credential selection and presentation mechanisms that adapt to the authentication context. The system automatically determines which credential to use based on the target user's authentication ground, eliminating the need for manual credential selection and simplifying the authentication process while maintaining versatility.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system provides self-service functionality by automatically managing multiple credentials and selecting the appropriate one for each authentication scenario. This eliminates the operational burden on users who would otherwise need to manually manage and switch between multiple credentials from different certificate authorities.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9774447B2Online identification and authentication
Publication Date: 2017.09.26 INTEL CORP
  • US9774447B2 patent drawing
  • US9774447B2 patent drawing
  • US9774447B2 patent drawing

AI summary

Systems and methods may provide for online identification and authentication. In one example, the method may include generating a credential to represent a relationship based on a common ground of authenticated communication between a first user and a second user, identifying the second user to the first user, authenticating the relationship of the second user to the first user, and initiating, upon authentication, a communication between the first user and the second user.