Intermediate Certificate Authority Module for Secure Transmission

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Entities face challenges in securely verifying certificates generated in one component and transmitted internally, as existing methods are prone to interception and compromise, leading to inefficiencies and increased costs in managing external certificates for secure data transmission.

Innovation Solution

Implementing an intermediate certificate authority module within the internal network to generate and transmit unique verification certificates using mutual transport layer security protocol, reducing the need for external certificate management and storage in hardware security modules.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If external certificates are stored in hardware security modules for secure transmission, then security is improved, but device complexity and cost increase

Engineering Contradiction:
Improvecertificate verification securityVSAvoidhardware security module requirement
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

An intermediate certificate authority module is introduced as a mediator between the internal entity server and external third party entity servers. This module generates unique verification certificates that enable secure communication without requiring the internal entity server to store external certificates in hardware security modules, thus maintaining security while reducing complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The verification certificate generation and management function is extracted from the internal entity server and placed in a dedicated intermediate certificate authority module. This separation allows the internal server to operate without hardware security modules while still achieving secure certificate verification through the intermediate module

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If multiple external certificates are managed for different internal servers, then security coverage is improved, but management complexity and costs increase

Engineering Contradiction:
Improvesecure connection coverageVSAvoidcertificate management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The intermediate certificate authority module serves multiple internal entity servers simultaneously, generating unique verification certificates for each server. This single module replaces the need for multiple external certificates and their associated hardware security modules, achieving universal security coverage while simplifying management

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

Multiple certificate management functions are merged into a single intermediate certificate authority module. This consolidation enables the system to manage secure connections for multiple internal servers through one centralized component, reducing overall complexity and cost

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If internal entity servers store external verification certificates, then verification capability is improved, but security risk of interception increases

Engineering Contradiction:
Improvecertificate verification capabilityVSAvoidcertificate interception risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The intermediate certificate authority module acts as a secure mediator that generates and distributes verification certificates directly to both the internal entity server and external third party entity servers simultaneously. This eliminates the need for internal servers to store external certificates, removing the interception vulnerability while maintaining verification capability

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20240106817A1Systems, methods, and apparatuses for transmission of verification certificates in an electronic network
Publication Date: 2024.03.28 BANK OF AMERICA CORP
  • US20240106817A1 patent drawing
  • US20240106817A1 patent drawing
  • US20240106817A1 patent drawing

AI summary

The present invention provides for implementing an internal entity intermediate certificate authority via a mutual transport layer security conversation to allow an entity-specific certificate authority to generate its own certificate which is transmitted to a second point in the internal transmission for sending of the external certificate authority generated certificate to the external entity for mutual authentication. Further, in this way, the first point of internal transmission does not have to store the certificate in its own hardware security module.