Multi-Certificate Strategy for Device Identity Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing certificate strategies for devices are unreliable due to transient and easily modifiable information, making it difficult to authenticate a device's identity and manage its operational capabilities, especially as the device changes ownership or undergoes updates.
Innovation Solution
A multi-certificate strategy involving a manufacturing certificate and an operational certificate, where the manufacturing certificate maintains the device's identity information and the operational certificate determines its functional abilities, ensuring the device's authenticity and operational services through separate levels of certification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a single certificate is used to store both identity information and operational characteristics, then the device can be authenticated and operated, but the reliability of authentication deteriorates when the device changes ownership or undergoes updates due to transient and easily modifiable information
Solution Approach 1:
The patent divides the certificate system into two separate certificates: a manufacturing certificate that stores stable identity information (device ID, serial number, manufacturer details) and an operational certificate that handles operational characteristics. This segmentation prevents the corruption of identity information when operational data changes, thereby maintaining authentication reliability while allowing operational flexibility.
2Adaptability or versatility
If a manufacturing certificate authority provides certificates during manufacture, then the device identity can be established, but the operational capabilities cannot be dynamically managed when the device changes ownership or undergoes updates
Solution Approach 1:
The patent introduces an operational certificate authority as an intermediary between the device and the manufacturing certificate authority. This intermediary can issue, update, and manage operational certificates based on device ownership changes or updates, without requiring direct involvement of the manufacturing certificate authority. This intermediary layer enables dynamic operational capability management while keeping the manufacturing certificate stable, effectively resolving the contradiction between adaptability and complexity.
3Adaptability or versatility
If certificate information is made modifiable to accommodate device updates and ownership changes, then operational flexibility is improved, but the authenticity verification becomes unreliable
Solution Approach 1:
By segmenting the certificate system into manufacturing and operational certificates with distinct purposes and stability requirements, the patent allows operational certificate information to be modified for device lifecycle events while the manufacturing certificate remains immutable for authenticity verification. This segmentation resolves the contradiction by assigning different modification characteristics to different certificate types.
Solution Approach 2:
The patent extracts the identity verification function from the operational certificate and places it exclusively in the manufacturing certificate. This extraction ensures that authenticity verification relies only on the stable manufacturing certificate, while operational certificates can be freely updated to accommodate device lifecycle changes, thereby maintaining both reliability and adaptability.
Data Source
Figure 1(a)
Figure 1(b)
Figure 2
AI summary
Operations or functions on a device may require an operational certificate to ensure that the user of the device or the device itself is permitted to carry out the operations or functions. A system and a method are provided for providing an operational certificate to a device, whereby the operational certificate is associated with one or more operations of the device. A manufacturing certificate authority, during the manufacture of the device, obtains identity information associated with the device and provides a manufacturing certificate to the device. An operational certificate authority obtains and authenticates at least a portion of the identity information associated with the device from the manufacturing certificate and, if at least the portion of the identity information is authenticated, the operational certificate is provided to the device.