Multi-Root Certificate Authority Binding for X.509 Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cryptography systems lack a convenient method for detecting tampering when one of the root certificates is compromised, especially with the advent of quantum computing, which can potentially reduce the time required to compromise certificates, and there is a need for cross-compatible solutions with existing X.509 standard systems to maintain trust between certificate authorities.

Innovation Solution

The solution involves generating root certificates that include identifiers and digital signature algorithms from multiple root certificate authorities, allowing for the binding of these authorities using extensions in the certificates, enabling trust across different digital signature schemes and ensuring that both schemes must be compromised to produce a forged certificate.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional single-root certificate authority structures are used, then system simplicity is maintained, but security vulnerability increases when a root key is compromised

Engineering Contradiction:
ImprovesecurityVSAvoidcertificate structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple root certificate authorities into a single certificate structure by embedding extensions from multiple root CAs within one certificate. This combining approach creates a multi-root bound certificate that provides enhanced security through multiple signature schemes while maintaining a unified certificate format that doesn't significantly increase structural complexity

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a composite certificate structure that combines elements from different root certificate authorities using different digital signature schemes (e.g., RSA and ECDSA). This composite approach ensures that compromising one root key does not compromise the entire system, as the certificate requires multiple signature schemes to be broken simultaneously

Inventive Principle:
Principle #40Composite materials

2Reliability

If quantum-resistant algorithms are adopted, then future security is improved, but compatibility with existing X.509 systems deteriorates

Engineering Contradiction:
Improvefuture securityVSAvoidcompatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal certificate structure that can accommodate multiple digital signature schemes including both traditional algorithms (RSA, ECDSA) and quantum-resistant algorithms. The X.509v3 extension mechanism is leveraged to embed multiple key identifiers and signature algorithm identifiers, allowing the same certificate format to serve multiple security paradigms and maintain compatibility with existing X.509 infrastructure

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent utilizes parameter changes within the existing X.509 certificate framework by modifying the extension fields to include multiple key identifiers (keyIdentifier extension) and signature algorithm identifiers (signatureAlgorithm extension). This allows the system to support different signature schemes without changing the fundamental certificate structure, maintaining backward compatibility while enabling future security algorithms

Inventive Principle:
Principle #35Parameter changes

3Reliability

If cross certificates are issued between root CAs, then trust is established, but detection of tampering becomes difficult when one root is compromised

Engineering Contradiction:
ImprovetrustVSAvoidtampering detection
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements a feedback mechanism where the bound root certificate contains embedded extensions from multiple root CAs that can be used to verify the authenticity of issued certificates. The certificate validation process checks against multiple root keys, providing feedback that enables detection of tampering by any single root, as the bound certificate maintains references to all original root authorities

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11930125B2Binding of multiple heterogeneous root certificate authorities
Publication Date: 2024.03.12 ENTRUST CORP
  • US11930125B2 patent drawing
  • US11930125B2 patent drawing
  • US11930125B2 patent drawing

AI summary

Root certificates generated by root certificate authorities may be bound at the time of generation. In an example, a first root certificate can include an identity of a first root certificate authority, a first key identifier associated with a first key of the first root certificate authority and an identity of a first digital signature algorithm used by the first root certificate authority. The first root certificate can also include at least one extension including a second key identifier of a second key associated with the second root certificate authority and an identity of a second digital signature algorithm used by the second root certificate authority, the second digital signature algorithm being different from the first digital signature algorithm.