Network Authority Private Key Delivery System
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current public key infrastructure (PKI) systems are cumbersome and insecure due to the need for extensive employee involvement in private key management, leading to security risks and high costs, as well as inefficiencies in key delivery and validation processes.
Innovation Solution
A network authority-based system that directly connects users to a certificate authority, eliminating the need for physical key possession and reducing the trust chain, utilizing secure connections like DSL and FTTP to ensure private key delivery directly to users while validating identities through a network authority and certificate revocation lists.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a registration authority physically distributes private keys to users, then key delivery is achieved, but security risk increases due to employee possession and control of private keys
Solution Approach 1:
The patent extracts the private key from the registration authority's physical possession and delivers it directly to the user through secure electronic transmission. The registration authority generates the key pair but immediately transfers the private key to the user without retaining control, eliminating the security risk of employee possession while maintaining the certification function.
Solution Approach 2:
The patent introduces a secure electronic transmission system as an intermediary between the registration authority and the user. This intermediary uses encrypted communication channels and digital signatures to ensure that the private key is delivered securely without being exposed to potential misuse by registration authority employees.
2Reliability
If registration authorities identify users in person for private key delivery, then key delivery security is maintained, but costs and time increase due to extensive employee involvement
Solution Approach 1:
The patent replaces the mechanical system of in-person identification and physical key handover with an electronic identification system using digital certificates and encrypted transmission. Users can be identified and verified remotely through digital means, eliminating the need for physical presence and reducing both time and cost while maintaining security through cryptographic verification.
3Reliability
If a traditional PKI infrastructure with validation authorities is used, then certificate validation is achieved, but costs increase due to expensive infrastructure and employee staffing
Solution Approach 1:
The patent merges the functions of the registration authority and validation authority into a single entity or system. The same authority that issues certificates also validates them, eliminating the need for separate infrastructure and reducing operational costs while maintaining the essential security function of certificate validation through digital signatures and cryptographic verification.
Data Source
AI summary
A method includes receiving, via a network, a request to provision and provide a private key, the private key being for use with a public and private key system. The method further includes identifying a requester that has made the request via the network and initiating a secure session with the requester. The method also includes providing the private key using the secure session, and provisioning the private key. A system is provided including a distribution location providing access to a network, a terminal selectively connected to the network via the distribution location. The system further includes a network authority selectively connected to the network and the terminal, and a certificate authority selectively connected to the network. The certificate authority is configured to provide and provision a private key, and the network authority is configured to selectively provide a secure session between the terminal and the certificate authority.


