Issuing Device for Blockchain Digital Certificate Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for issuing digital certificates do not efficiently verify a device's identity as a counterparty in a distributed database, such as a blockchain, which is crucial for secure transactions and authentication in industrial automation systems.

Innovation Solution

An issuing device that responds to challenge requests by transmitting cryptographic challenges and verifies cryptographic responses posted to the distributed database, issuing a digital certificate only if the response is associated with the counterparty identity information and constitutes a valid proof of ownership, ensuring the device's identity is securely established.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If existing methods for issuing digital certificates are used, then the certification process can be automated, but the verification of a device's identity as a counterparty in a distributed database is inefficient and complex

Engineering Contradiction:
Improveautomation of certificate issuanceVSAvoidcomplexity of identity verification
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The issuing device is divided into two functional entities: a first entity that handles challenge requests and transmits cryptographic challenges, and a second entity that verifies cryptographic responses and issues digital certificates. This segmentation separates the complexity of verification from the automation of issuance, allowing each entity to specialize in its function while working together to resolve the technical contradiction.

Inventive Principle:
Principle #1Segmentation

2Reliability

If manual verification of counterparty identity is performed, then security can be ensured, but the process becomes time-consuming and inefficient

Engineering Contradiction:
Improvesecurity of identity verificationVSAvoidtime for certificate issuance
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The requesting device performs self-verification by posting its own cryptographic response to the distributed database ledger. The second entity of the issuing device then verifies this self-posted response against the ledger, eliminating the need for manual identity verification while maintaining security. This self-service mechanism significantly reduces the time required for certificate issuance while ensuring reliable verification through cryptographic proof.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If cryptographic challenges are verified against the distributed database ledger, then the accuracy of identity verification is improved, but the verification process becomes more complex

Engineering Contradiction:
Improveaccuracy of counterparty identity verificationVSAvoidcomplexity of verification process
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The distributed database ledger acts as an intermediary between the requesting device and the issuing device. The requesting device posts its cryptographic response to the ledger, and the second entity verifies the response by checking the ledger. This intermediary mechanism ensures accurate verification of counterparty identity while simplifying the verification process for the issuing device, as it only needs to check the ledger rather than perform complex manual verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11917081B2Issuing device and method for issuing and requesting device and method for requesting a digital certificate
Publication Date: 2024.02.27 SIEMENS AG
  • US11917081B2 patent drawing
  • US11917081B2 patent drawing
  • US11917081B2 patent drawing

AI summary

An issuing device is configured to: respond to a challenge request by transmitting a challenge; and respond to a certification request including a public key and ownership information thereof by issuing a digital certificate certifying the ownership information. The ownership information includes counterparty identity information relating to a ledger of a distributed database. The digital certificate is issued if it is successfully verified that a valid response to the challenge has been posted to the ledger of the distributed database and is associated therein with the counterparty identity information of the certification request. The digital certificate facilitates proofing that an owner of a public key is a given counterparty to a blockchain ledger. Also, a corresponding requesting device and corresponding methods and computer program products for issuing and requesting a digital certificate are disclosed.