Mesh PKI Trust Links for Cross-Party Revocation Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication security systems for interconnected devices from different manufacturers face challenges in establishing a common root of trust for secure communication, especially across different vehicles and parties, due to the impracticality of a global authority and the need for frequent updates and revocation mechanisms, which can lead to security vulnerabilities and inefficiencies.

Innovation Solution

A mesh-based public key infrastructure (PKI) structure is introduced, allowing each party to maintain its own PKI, with a mesh structure that includes root elements, mesh elements, and self-revocation and revocation elements to manage trust relationships securely, enabling secure communication and efficient revocation of compromised trust relationships without affecting other parties.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a global authority is introduced to provide a common root of trust, then trust relationship establishment is improved, but system complexity and maintenance effort increase enormously

Engineering Contradiction:
Improvetrust relationship establishmentVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the global trust authority into multiple regional Certificate Trust Lists (CTLs), each managed by a regional authority. This segmentation reduces the complexity of any single authority while maintaining trust relationships across different regions. Each CTL manages trust for its specific region, avoiding the need for a single complex global authority.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism where devices store multiple CTLs in a hierarchical structure. When establishing trust, devices query CTLs in a predefined hierarchy, allowing intermediary regional authorities to mediate trust relationships without requiring direct global authority involvement. This intermediary layer simplifies the overall system architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If a global authority operates with multiple manufacturers and service providers worldwide, then coverage is improved, but neutrality and bias become difficult to maintain

Engineering Contradiction:
ImprovecoverageVSAvoidneutrality
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the global trust system into regional CTLs, each managed by independent regional authorities. This segmentation allows each region to maintain neutrality within its own context while the hierarchical structure provides global coverage. Regional authorities can make decisions tailored to their specific contexts without being influenced by conflicts of interest in other regions.

Inventive Principle:
Principle #1Segmentation

3Reliability

If frequent updates and revocation mechanisms are implemented, then security is improved, but system complexity and maintenance effort increase

Engineering Contradiction:
ImprovesecurityVSAvoidmaintenance effort
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by pre-configuring devices with multiple CTLs in a hierarchical structure before trust relationships are established. This pre-prepared structure allows devices to efficiently query and revoke trust relationships without requiring complex real-time updates. The hierarchical arrangement enables proactive security management with reduced maintenance overhead.

Inventive Principle:
Principle #10Preliminary action

4Ease of operation

If each party maintains its own PKI with root certificate authority, then independence and control are improved, but establishing common trust between parties becomes difficult

Engineering Contradiction:
ImproveindependenceVSAvoidcommon trust establishment
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces CTLs as intermediary structures that mediate between individual PKIs. Each party maintains its own PKI for independence, but the CTLs provide a common reference point for establishing trust. When devices from different parties need to establish trust, they query the appropriate CTLs, which verify trust relationships without requiring direct coordination between the parties' PKIs.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent makes the CTLs universal by designing them to serve multiple functions: verifying trust relationships, enabling revocation, and providing a common reference across different PKIs. This multi-functional design allows devices from different parties to establish common trust using the same CTL infrastructure, bridging the gap between independent PKIs.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250373445A1Computer-readable medium relating to trust relationships between a first party and a second party, search method, computer program for an electronic device, electronic device, and first vehicle, in particular utility vehicle
Publication Date: 2025.12.04 ZF CV SYST GLOBAL GMBH
  • US20250373445A1 patent drawing
  • US20250373445A1 patent drawing
  • US20250373445A1 patent drawing

AI summary

A computer-readable medium includes a mesh with a public key infrastructure relating to trust relationships between a first party and a second party. The mesh includes: a first chain representing the first party and including a first root element, mesh element and element; a second chain representing the second party and including a second root element and element. The first element includes a signature by the first party mesh certification authority, the mesh public key, a predecessor sibling hash of a preceding element in the first chain, and a neighbor link to a second linked element of the second chain; the second element includes a neighbor link to a first linked element of the first chain. The second chain includes a self-revocation element, a successor of the second linked element, and a self-revocation property and/or the first chain includes a revocation element, a first element successor, and a revocation property.