Identity Management System Self-Issuing Digital Certificates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing certificate handling systems for public key infrastructure (PKI) are cumbersome, insecure, and costly, requiring technical expertise and relying on third-party certificate authorities for digital certificate issuance and management, which can be inconvenient and prone to security risks.

Innovation Solution

An identity management system is used to manage digital certificates, enabling users to request, sign, and revoke certificates through a user-friendly interface, acting as a certificate authority to provide a flexible and secure certificate signing and handling protocol.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If third-party certificate authorities are used to issue digital certificates, then security and trust are improved, but device complexity and operational difficulty increase

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables users to self-issue digital certificates using their own private keys without requiring third-party certificate authorities. The identity management system allows users to generate key pairs, create certificates, and manage their own cryptographic credentials, eliminating the need for external verification bodies and reducing system complexity.

Inventive Principle:
Principle #25Self-service

2Reliability

If third-party certificate authorities are used for certificate issuance, then trust validation is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvetrust validationVSAvoidoperational convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

Users can independently generate digital certificates through the identity management system without contacting external authorities. The system provides automated key pair generation, certificate creation with customizable attributes, and instant issuance, making the process user-friendly and eliminating bureaucratic delays associated with traditional CA processes.

Inventive Principle:
Principle #25Self-service

3Reliability

If traditional certificate handling systems are used, then security protocols are established, but productivity and efficiency decrease

Engineering Contradiction:
Improvesecurity protocolVSAvoidcertificate management efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary actions by generating private keys and digital certificates automatically within the identity management system before any authentication or encryption operations are needed. This eliminates the need for separate key management processes and enables immediate use of cryptographic credentials, significantly improving operational efficiency.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system merges key generation, certificate issuance, attribute management, and revocation capabilities into a single integrated identity management platform. This consolidation eliminates the need for multiple separate systems and manual processes, streamlining certificate management while maintaining security protocols.

Inventive Principle:
Principle #5Merging (Combining)

4Reliability

If users need to prove identity to certificate authorities, then certificate issuance security is improved, but loss of time increases

Engineering Contradiction:
Improveidentity verification securityVSAvoidcertificate issuance time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Users prove their identity through the existing authentication mechanisms of the identity management system rather than undergoing separate verification processes with external certificate authorities. The system leverages already-authenticated user sessions to issue certificates, eliminating redundant identity proofing steps and reducing issuance time from days to moments.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10567370B2Certificate authority
Publication Date: 2020.02.18 NOKIA SOLUTIONS & NETWORKS OY
  • US10567370B2 patent drawing
  • US10567370B2 patent drawing
  • US10567370B2 patent drawing

AI summary

A protocol for issuing and controlling digital certificates is described in which an identity management system is used to identify a user requesting a digital certificate and is also used to issue the digital certificate itself. Accordingly, an IDM-based PKI system is provided.