IPv6 Multi-Element Authentication Root With Multi-Key Certificates
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional root servers face security concerns and operational inconvenience due to single-key, single-certificate, and single-platform authentication, making them unsuitable for decentralized deployments.
Innovation Solution
An IPv6-based multi-element authentication root system that integrates multiple identity and enterprise information, generates electronic seals, and issues multi-key root certificates, enabling dual-stack and multi-category interworking, and supports multi-certificate and multi-key applications on a unified platform.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional root server uses single-key, single-certificate, and single-platform authentication, then the authentication process is simple, but the security level and adaptability are insufficient
Solution Approach 1:
The patent segments the authentication system into multiple independent components: multiple keys (private key, public key, secret key), multiple certificates (identity certificate, enterprise certificate, root certificate), and multiple authentication platforms (IPv4 platform, IPv6 platform). This segmentation allows each component to perform its specific function independently, enhancing overall security while maintaining manageable complexity through modular architecture.
Solution Approach 2:
The patent creates a composite authentication system by combining multiple authentication elements (different types of keys, certificates, and platforms) into a unified multi-element authentication root system. This composite structure integrates diverse authentication mechanisms working together, providing enhanced security reliability while maintaining operational simplicity through unified management.
2Ease of operation
If conventional root server uses centralized cloud deployment, then the system is easy to manage, but it is inconvenient for government, enterprises, families, and individuals to deploy
Solution Approach 1:
The patent designs the multi-element authentication root system with universal applicability across different deployment scenarios. The system can be deployed on diverse platforms (IPv4, IPv6, centralized cloud, or decentralized edge devices) and serves multiple user types (government, enterprises, families, individuals). The unified authentication mechanism works consistently across all platforms, providing both ease of operation and deployment flexibility.
Solution Approach 2:
The patent implements dynamic deployment capabilities where the authentication system can adapt its configuration based on the deployment environment. The system supports flexible instantiation on different platforms and can dynamically adjust its operation mode (centralized or decentralized), making it convenient for various users to deploy according to their specific needs while maintaining consistent security standards.
3Reliability
If the system integrates multiple identity information, enterprise information, and digital certificates, then the authentication comprehensiveness is improved, but the system complexity increases
Solution Approach 1:
The patent segments the comprehensive authentication system into distinct functional modules: identity information management module, enterprise information management module, certificate management module, and key management module. Each module handles specific authentication elements independently, allowing the system to maintain comprehensive authentication capabilities while managing complexity through clear separation of concerns and modular architecture.
Data Source
AI summary
An internet protocol version 6 (IPv6)-based multi-element authentication root system includes a first acquisition module, a second acquisition module, a third acquisition module, and a root certificate issuing module. The first acquisition module is configured to acquire a plurality of pieces of identity information, a plurality of pieces of enterprise information and an enterprise code of a user; the second acquisition module is configured to acquire an IPv6 digital address of the user; the third acquisition module is configured to acquire a plurality of digital certificates and a plurality of corresponding keys provided by a plurality of certificate authorities; and the root certificate issuing module is configured to perform multi-key verification on the plurality of pieces of authenticated identity information and the plurality of pieces of authenticated enterprise information according to the plurality of digital certificates and the plurality of corresponding keys, and issue a plurality of root certificates.


