Network Authority Private Key Delivery System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current public key infrastructure (PKI) systems are cumbersome and insecure due to the need for extensive employee involvement in private key management, leading to security risks and high costs, as well as inefficiencies in key delivery and validation processes.

Innovation Solution

A network authority-based system that directly connects users to a certificate authority, eliminating the need for physical key possession and reducing the trust chain, utilizing secure connections like DSL and FTTP to ensure private key delivery directly to users while validating identities through a network authority and certificate revocation lists.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a registration authority physically distributes private keys to users, then key delivery is achieved, but security risk increases due to employee possession and control of private keys

Engineering Contradiction:
ImprovesecurityVSAvoidtrust chain complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the private key from the registration authority's physical possession and delivers it directly to the user through secure electronic transmission. The registration authority generates the key pair but immediately transfers the private key to the user without retaining control, eliminating the security risk of employee possession while maintaining the certification function.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a secure electronic transmission system as an intermediary between the registration authority and the user. This intermediary uses encrypted communication channels and digital signatures to ensure that the private key is delivered securely without being exposed to potential misuse by registration authority employees.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If registration authorities identify users in person for private key delivery, then key delivery security is maintained, but costs and time increase due to extensive employee involvement

Engineering Contradiction:
Improvekey delivery securityVSAvoidkey delivery time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent replaces the mechanical system of in-person identification and physical key handover with an electronic identification system using digital certificates and encrypted transmission. Users can be identified and verified remotely through digital means, eliminating the need for physical presence and reducing both time and cost while maintaining security through cryptographic verification.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If a traditional PKI infrastructure with validation authorities is used, then certificate validation is achieved, but costs increase due to expensive infrastructure and employee staffing

Engineering Contradiction:
Improvecertificate validationVSAvoidinfrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the functions of the registration authority and validation authority into a single entity or system. The same authority that issues certificates also validates them, eliminating the need for separate infrastructure and reducing operational costs while maintaining the essential security function of certificate validation through digital signatures and cryptographic verification.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS8374354B2System and method to pass a private encryption key
Publication Date: 2013.02.12 VERIZON PATENT & LICENSING INC
  • US8374354B2 patent drawing
  • US8374354B2 patent drawing
  • US8374354B2 patent drawing

AI summary

A method includes receiving, via a network, a request to provision and provide a private key, the private key being for use with a public and private key system. The method further includes identifying a requester that has made the request via the network and initiating a secure session with the requester. The method also includes providing the private key using the secure session, and provisioning the private key. A system is provided including a distribution location providing access to a network, a terminal selectively connected to the network via the distribution location. The system further includes a network authority selectively connected to the network and the terminal, and a certificate authority selectively connected to the network. The certificate authority is configured to provide and provision a private key, and the network authority is configured to selectively provide a secure session between the terminal and the certificate authority.