Mesh PKI Trust Links for Cross-Party Revocation Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication security systems for interconnected devices from different manufacturers face challenges in establishing a common root of trust for secure communication, especially across different vehicles and parties, due to the impracticality of a global authority and the need for frequent updates and revocation mechanisms, which can lead to security vulnerabilities and inefficiencies.
Innovation Solution
A mesh-based public key infrastructure (PKI) structure is introduced, allowing each party to maintain its own PKI, with a mesh structure that includes root elements, mesh elements, and self-revocation and revocation elements to manage trust relationships securely, enabling secure communication and efficient revocation of compromised trust relationships without affecting other parties.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a global authority is introduced to provide a common root of trust, then trust relationship establishment is improved, but system complexity and maintenance effort increase enormously
Solution Approach 1:
The patent divides the global trust authority into multiple regional Certificate Trust Lists (CTLs), each managed by a regional authority. This segmentation reduces the complexity of any single authority while maintaining trust relationships across different regions. Each CTL manages trust for its specific region, avoiding the need for a single complex global authority.
Solution Approach 2:
The patent introduces an intermediary mechanism where devices store multiple CTLs in a hierarchical structure. When establishing trust, devices query CTLs in a predefined hierarchy, allowing intermediary regional authorities to mediate trust relationships without requiring direct global authority involvement. This intermediary layer simplifies the overall system architecture.
2Adaptability or versatility
If a global authority operates with multiple manufacturers and service providers worldwide, then coverage is improved, but neutrality and bias become difficult to maintain
Solution Approach 1:
The patent segments the global trust system into regional CTLs, each managed by independent regional authorities. This segmentation allows each region to maintain neutrality within its own context while the hierarchical structure provides global coverage. Regional authorities can make decisions tailored to their specific contexts without being influenced by conflicts of interest in other regions.
3Reliability
If frequent updates and revocation mechanisms are implemented, then security is improved, but system complexity and maintenance effort increase
Solution Approach 1:
The patent implements preliminary action by pre-configuring devices with multiple CTLs in a hierarchical structure before trust relationships are established. This pre-prepared structure allows devices to efficiently query and revoke trust relationships without requiring complex real-time updates. The hierarchical arrangement enables proactive security management with reduced maintenance overhead.
4Ease of operation
If each party maintains its own PKI with root certificate authority, then independence and control are improved, but establishing common trust between parties becomes difficult
Solution Approach 1:
The patent introduces CTLs as intermediary structures that mediate between individual PKIs. Each party maintains its own PKI for independence, but the CTLs provide a common reference point for establishing trust. When devices from different parties need to establish trust, they query the appropriate CTLs, which verify trust relationships without requiring direct coordination between the parties' PKIs.
Solution Approach 2:
The patent makes the CTLs universal by designing them to serve multiple functions: verifying trust relationships, enabling revocation, and providing a common reference across different PKIs. This multi-functional design allows devices from different parties to establish common trust using the same CTL infrastructure, bridging the gap between independent PKIs.
Data Source
AI summary
A computer-readable medium includes a mesh with a public key infrastructure relating to trust relationships between a first party and a second party. The mesh includes: a first chain representing the first party and including a first root element, mesh element and element; a second chain representing the second party and including a second root element and element. The first element includes a signature by the first party mesh certification authority, the mesh public key, a predecessor sibling hash of a preceding element in the first chain, and a neighbor link to a second linked element of the second chain; the second element includes a neighbor link to a first linked element of the first chain. The second chain includes a self-revocation element, a successor of the second linked element, and a self-revocation property and/or the first chain includes a revocation element, a first element successor, and a revocation property.


