Mobile Device Certificate Store Module Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current devices for storing digital certificates lack required security levels, making them susceptible to attacks and fraudulent use, especially as data messages pass through multiple nodes during transmission, where integrity, confidentiality, and validity may be compromised.
Innovation Solution
A method and system that utilize a certificate store module on a mobile device, which is configured to prompt a user for a passcode before releasing a digital certificate, ensuring secure transmission over an encrypted tunnel, and is only accessible via a remotely accessible server, using a secure processing unit isolated from the public processing unit to protect cryptographic keys and algorithms.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If digital certificates are stored in conventional devices, then accessibility and ease of operation are improved, but security and protection against attacks are worsened
Solution Approach 1:
The system separates the storage and management of digital certificates from conventional devices by introducing a dedicated certificate store module. This module is accessed through a mobile device via an encrypted tunnel, creating a segmented architecture where sensitive certificate data is isolated from potentially vulnerable conventional storage environments while remaining accessible when needed.
2Adaptability or versatility
If digital certificates are transmitted through multiple network nodes, then communication versatility and adaptability are improved, but integrity and confidentiality are worsened due to interception risks
Solution Approach 1:
An encrypted tunnel acts as an intermediary channel between the certificate store module and the mobile device. This tunnel uses established encryption protocols to protect the certificate data during transmission through the network, allowing versatile communication while mitigating the harmful effects of interception and alteration at intermediary nodes.
3Device complexity
If conventional storage devices are used for digital certificates, then device complexity is reduced, but security against fraudulent use is worsened
Solution Approach 1:
The mobile device serves as an intermediary layer between the simple certificate store module and the conventional communication device. This intermediary provides passcode-based authentication and encrypted transmission, enhancing security against fraudulent use while keeping the core storage system relatively simple.
4Ease of operation
If digital certificates are made easily accessible, then ease of operation is improved, but security control and authorization are worsened
Solution Approach 1:
The system implements preliminary authorization control through passcode entry requirements before the certificate store module will release any digital certificate. This preliminary action ensures that only authorized users can access the certificates, maintaining security control while allowing easy access once authorization is established.
Data Source
AI summary
Systems, methods and devices for providing digital certificates are disclosed. In a method conducted at a remotely accessible server, a request, including an identifier, for a digital certificate is received. A communication address of a mobile device, having a certificate store module in communication therewith, associated with the identifier is then obtained. A request for a digital certificate is transmitted to the certificate store module via the mobile device and the certificate store module is configured to prompt a user thereof, via the mobile device, for a passcode before releasing the certificate. The digital certificate is received from the certificate store module via the mobile device in response to entry of a passcode into the certificate store module which corresponds to an offset stored in the certificate store module. The digital certificate is then transmitted to a communication device for use in digitally signing or encrypting a data message.


