Multi-Certificate Strategy for Device Identity Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing certificate strategies for devices are unreliable due to transient and easily modifiable information, making it difficult to authenticate a device's identity and manage its operational capabilities, especially as the device changes ownership or undergoes updates.

Innovation Solution

A multi-certificate strategy involving a manufacturing certificate for maintaining device identity and an operational certificate for determining functional abilities, where the manufacturing certificate authority provides a manufacturing certificate during device manufacture, and the operational certificate authority authenticates device identity to issue operational certificates, separating identity and operational characteristics into different certificate levels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a single certificate is used to represent device identity, then the certificate structure is simple, but the reliability of device identity authentication deteriorates due to transient and easily modifiable information

Engineering Contradiction:
Improvecertificate structureVSAvoiddevice identity authentication
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent divides the certificate system into two distinct certificates: a manufacturing certificate that maintains device identity information throughout the device's lifetime, and an operational certificate that grants temporary access rights. This segmentation allows the manufacturing certificate to serve as a reliable, immutable identity anchor while the operational certificate handles dynamic access control, thereby resolving the contradiction between simplicity and reliability.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If device identity information is made modifiable to adapt to ownership changes, then the adaptability of the device improves, but the reliability of identity authentication deteriorates

Engineering Contradiction:
Improvedevice ownership changeVSAvoididentity authentication
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments identity management into two layers: the manufacturing certificate contains immutable device identity information that remains constant throughout the device's lifetime, while the operational certificate contains modifiable access rights that can be updated when ownership changes. This allows the system to adapt to new owners while maintaining the reliability of the underlying device identity through the immutable manufacturing certificate.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The operational certificate acts as an intermediary between the device and the network, absorbing the changes related to ownership and access rights without affecting the underlying device identity stored in the manufacturing certificate. This intermediary layer allows adaptability at the operational level while preserving reliability at the identity level.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If comprehensive device information is included in one certificate, then the authentication process is efficient, but the security control over operational capabilities deteriorates

Engineering Contradiction:
Improveauthentication efficiencyVSAvoidoperational capability control
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent segments certificate contents into two categories: the manufacturing certificate contains immutable device identity information for efficient authentication, while the operational certificate contains specific operational capabilities and access rights. This segmentation maintains authentication efficiency through the manufacturing certificate while enabling fine-grained control over operational capabilities through the operational certificate, which can be selectively issued and revoked based on service requirements.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8719577B2System and method for multi-certificate and certificate authority strategy
Publication Date: 2014.05.06 MALIKIE INNOVATIONS LTD
  • US8719577B2 patent drawing
  • US8719577B2 patent drawing
  • US8719577B2 patent drawing

AI summary

Operations or functions on a device may require an operational certificate to ensure that the user of the device or the device itself is permitted to carry out the operations or functions. A system and a method are provided for providing an operational certificate to a device, whereby the operational certificate is associated with one or more operations of the device. A manufacturing certificate authority, during the manufacture of the device, obtains identity information associated with the device and provides a manufacturing certificate to the device. An operational certificate authority obtains and authenticates at least a portion of the identity information associated with the device from the manufacturing certificate and, if at least the portion of the identity information is authenticated, the operational certificate is provided to the device.