Mobile Device Certificate Store Module Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current devices for storing digital certificates lack required security levels, making them susceptible to attacks and fraudulent use, especially as data messages pass through multiple nodes during transmission, where integrity, confidentiality, and validity may be compromised.

Innovation Solution

A method and system that utilize a certificate store module on a mobile device, which is configured to prompt a user for a passcode before releasing a digital certificate, ensuring secure transmission over an encrypted tunnel, and is only accessible via a remotely accessible server, using a secure processing unit isolated from the public processing unit to protect cryptographic keys and algorithms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If digital certificates are stored in conventional devices, then accessibility and ease of operation are improved, but security and protection against attacks are worsened

Engineering Contradiction:
Improveaccessibility of digital certificatesVSAvoidsecurity of digital certificates
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system separates the storage and management of digital certificates from conventional devices by introducing a dedicated certificate store module. This module is accessed through a mobile device via an encrypted tunnel, creating a segmented architecture where sensitive certificate data is isolated from potentially vulnerable conventional storage environments while remaining accessible when needed.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If digital certificates are transmitted through multiple network nodes, then communication versatility and adaptability are improved, but integrity and confidentiality are worsened due to interception risks

Engineering Contradiction:
Improvecommunication flexibilityVSAvoidinterception and alteration of data
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

An encrypted tunnel acts as an intermediary channel between the certificate store module and the mobile device. This tunnel uses established encryption protocols to protect the certificate data during transmission through the network, allowing versatile communication while mitigating the harmful effects of interception and alteration at intermediary nodes.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If conventional storage devices are used for digital certificates, then device complexity is reduced, but security against fraudulent use is worsened

Engineering Contradiction:
Improvestorage system simplicityVSAvoidprotection against fraud
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The mobile device serves as an intermediary layer between the simple certificate store module and the conventional communication device. This intermediary provides passcode-based authentication and encrypted transmission, enhancing security against fraudulent use while keeping the core storage system relatively simple.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Ease of operation

If digital certificates are made easily accessible, then ease of operation is improved, but security control and authorization are worsened

Engineering Contradiction:
Improvecertificate accessibilityVSAvoidauthorization control mechanism
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system implements preliminary authorization control through passcode entry requirements before the certificate store module will release any digital certificate. This preliminary action ensures that only authorized users can access the certificates, maintaining security control while allowing easy access once authorization is established.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9660814B2Providing digital certificates
Publication Date: 2017.05.23 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US9660814B2 patent drawing
  • US9660814B2 patent drawing
  • US9660814B2 patent drawing

AI summary

Systems, methods and devices for providing digital certificates are disclosed. In a method conducted at a remotely accessible server, a request, including an identifier, for a digital certificate is received. A communication address of a mobile device, having a certificate store module in communication therewith, associated with the identifier is then obtained. A request for a digital certificate is transmitted to the certificate store module via the mobile device and the certificate store module is configured to prompt a user thereof, via the mobile device, for a passcode before releasing the certificate. The digital certificate is received from the certificate store module via the mobile device in response to entry of a passcode into the certificate store module which corresponds to an offset stored in the certificate store module. The digital certificate is then transmitted to a communication device for use in digitally signing or encrypting a data message.