Multi-Certificate Strategy for Device Identity Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing certificate strategies for devices are unreliable due to transient and easily modifiable information, making it difficult to authenticate a device's identity and manage its operational capabilities, especially as the device changes ownership or undergoes updates.

Innovation Solution

A multi-certificate strategy involving a manufacturing certificate and an operational certificate, where the manufacturing certificate maintains the device's identity information and the operational certificate determines its functional abilities, ensuring the device's authenticity and operational services through separate levels of certification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single certificate is used to store both identity information and operational characteristics, then the device can be authenticated and operated, but the reliability of authentication deteriorates when the device changes ownership or undergoes updates due to transient and easily modifiable information

Engineering Contradiction:
Improvedevice identity authentication reliabilityVSAvoidcertificate information stability
Core Design Contradiction:
ReliabilityVSStability of the object's composition

Solution Approach 1:

The patent divides the certificate system into two separate certificates: a manufacturing certificate that stores stable identity information (device ID, serial number, manufacturer details) and an operational certificate that handles operational characteristics. This segmentation prevents the corruption of identity information when operational data changes, thereby maintaining authentication reliability while allowing operational flexibility.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If a manufacturing certificate authority provides certificates during manufacture, then the device identity can be established, but the operational capabilities cannot be dynamically managed when the device changes ownership or undergoes updates

Engineering Contradiction:
Improveoperational capability managementVSAvoidcertificate management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces an operational certificate authority as an intermediary between the device and the manufacturing certificate authority. This intermediary can issue, update, and manage operational certificates based on device ownership changes or updates, without requiring direct involvement of the manufacturing certificate authority. This intermediary layer enables dynamic operational capability management while keeping the manufacturing certificate stable, effectively resolving the contradiction between adaptability and complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If certificate information is made modifiable to accommodate device updates and ownership changes, then operational flexibility is improved, but the authenticity verification becomes unreliable

Engineering Contradiction:
Improvedevice lifecycle adaptabilityVSAvoidcertificate authenticity verification
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

By segmenting the certificate system into manufacturing and operational certificates with distinct purposes and stability requirements, the patent allows operational certificate information to be modified for device lifecycle events while the manufacturing certificate remains immutable for authenticity verification. This segmentation resolves the contradiction by assigning different modification characteristics to different certificate types.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts the identity verification function from the operational certificate and places it exclusively in the manufacturing certificate. This extraction ensures that authenticity verification relies only on the stable manufacturing certificate, while operational certificates can be freely updated to accommodate device lifecycle changes, thereby maintaining both reliability and adaptability.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP2387262B1System and method for multi-certificate and certificate authority strategy
Publication Date: 2015.04.29 BLACKBERRY LTD
  • EP2387262B1 patent drawingFigure 1(a)
  • EP2387262B1 patent drawingFigure 1(b)
  • EP2387262B1 patent drawingFigure 2

AI summary

Operations or functions on a device may require an operational certificate to ensure that the user of the device or the device itself is permitted to carry out the operations or functions. A system and a method are provided for providing an operational certificate to a device, whereby the operational certificate is associated with one or more operations of the device. A manufacturing certificate authority, during the manufacture of the device, obtains identity information associated with the device and provides a manufacturing certificate to the device. An operational certificate authority obtains and authenticates at least a portion of the identity information associated with the device from the manufacturing certificate and, if at least the portion of the identity information is authenticated, the operational certificate is provided to the device.