Multi-Certificate Strategy for Device Identity Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing certificate strategies for devices are unreliable due to transient and easily modifiable information, making it difficult to authenticate a device's identity and manage its operational capabilities, especially as the device changes ownership or undergoes updates.
Innovation Solution
A multi-certificate strategy involving a manufacturing certificate for maintaining device identity and an operational certificate for determining functional abilities, where the manufacturing certificate authority provides a manufacturing certificate during device manufacture, and the operational certificate authority authenticates device identity to issue operational certificates, separating identity and operational characteristics into different certificate levels.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If a single certificate is used to represent device identity, then the certificate structure is simple, but the reliability of device identity authentication deteriorates due to transient and easily modifiable information
Solution Approach 1:
The patent divides the certificate system into two distinct certificates: a manufacturing certificate that maintains device identity information throughout the device's lifetime, and an operational certificate that grants temporary access rights. This segmentation allows the manufacturing certificate to serve as a reliable, immutable identity anchor while the operational certificate handles dynamic access control, thereby resolving the contradiction between simplicity and reliability.
2Adaptability or versatility
If device identity information is made modifiable to adapt to ownership changes, then the adaptability of the device improves, but the reliability of identity authentication deteriorates
Solution Approach 1:
The patent segments identity management into two layers: the manufacturing certificate contains immutable device identity information that remains constant throughout the device's lifetime, while the operational certificate contains modifiable access rights that can be updated when ownership changes. This allows the system to adapt to new owners while maintaining the reliability of the underlying device identity through the immutable manufacturing certificate.
Solution Approach 2:
The operational certificate acts as an intermediary between the device and the network, absorbing the changes related to ownership and access rights without affecting the underlying device identity stored in the manufacturing certificate. This intermediary layer allows adaptability at the operational level while preserving reliability at the identity level.
3Productivity
If comprehensive device information is included in one certificate, then the authentication process is efficient, but the security control over operational capabilities deteriorates
Solution Approach 1:
The patent segments certificate contents into two categories: the manufacturing certificate contains immutable device identity information for efficient authentication, while the operational certificate contains specific operational capabilities and access rights. This segmentation maintains authentication efficiency through the manufacturing certificate while enabling fine-grained control over operational capabilities through the operational certificate, which can be selectively issued and revoked based on service requirements.
Data Source
AI summary
Operations or functions on a device may require an operational certificate to ensure that the user of the device or the device itself is permitted to carry out the operations or functions. A system and a method are provided for providing an operational certificate to a device, whereby the operational certificate is associated with one or more operations of the device. A manufacturing certificate authority, during the manufacture of the device, obtains identity information associated with the device and provides a manufacturing certificate to the device. An operational certificate authority obtains and authenticates at least a portion of the identity information associated with the device from the manufacturing certificate and, if at least the portion of the identity information is authenticated, the operational certificate is provided to the device.


