PKI Certificate Distribution via Mobile Storefront Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The secure distribution of Public Key Infrastructure (PKI) certificates is challenging, especially when conveying them to a large population over an insecure medium like the internet, as they can be intercepted and used to fake identities, and physically delivering them requires a vast infrastructure of pick-up locations.
Innovation Solution
A method utilizing a mobile telephony provider's infrastructure to securely deliver PKI certificates by requesting them from a certificate authority through private channels, mailing an activation key, and requiring users to physically verify their identity at a storefront to receive and activate the certificate.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If PKI certificates are digitally conveyed over the internet, then distribution to large population is enabled, but interception and identity fraud risks increase
Solution Approach 1:
The distribution process is segmented into multiple secure stages: certificate request through mobile provider's secure channel, physical delivery of activation key via mail, in-person verification at storefront, and final certificate installation. This segmentation ensures that sensitive operations occur over secure channels while maintaining broad distribution capability.
Solution Approach 2:
The mobile telephony provider acts as an intermediary between the Certificate Authority and the end user. The provider uses its existing secure infrastructure and physical storefront network to facilitate certificate distribution, leveraging its trusted relationship with users while providing secure conveyance through channels that cannot be intercepted.
2Object-affected harmful factors
If PKI certificates are physically delivered to users, then interception risks are eliminated, but infrastructure complexity and cost increase
Solution Approach 1:
The mobile telephony provider's existing infrastructure is leveraged for multiple purposes: the secure communication channels are used for certificate conveyance, the physical storefront network provides distribution locations, and the customer service representative system handles verification. This multi-functionality eliminates the need for dedicated physical distribution infrastructure while maintaining security.
Solution Approach 2:
The system uses the mobile provider's existing self-service storefront network and customer service infrastructure to handle certificate distribution. The provider's established processes for customer verification and service delivery are repurposed for PKI certificate distribution, eliminating the need for new complex infrastructure.
3Reliability
If PKI certificates are distributed through mobile telephony provider infrastructure, then secure delivery with physical verification is achieved, but distribution process complexity increases
Solution Approach 1:
The activation key is mailed to the user's address before the in-person verification appointment. This preliminary action allows the user to prepare their device and identification documents in advance, while the secure channel ensures the key cannot be intercepted. The storefront is pre-configured with the user's information from the mobile provider's database.
Solution Approach 2:
The distribution process merges the mobile provider's existing customer service operations with PKI certificate distribution. The same storefronts, customer service representatives, and verification processes used for routine mobile service are combined with certificate issuance, eliminating the need for separate complex distribution infrastructure.
Data Source
AI summary
The present invention discloses a system and method of leveraging mobile telephone provider assets and distribution network to securely deliver security tokens, such as PKI certificates. The invention is not limited to using a mobile telephony infrastructure and other pre-existing distributions can also be used. In the invention, a user requested security token can be delivered to a storefront associated with a mobile telephone provider. The storefront can be one proximate to a requesting user. An optional activation key can also be conveyed to the requesting user. The requesting user can be required to physically travel to the storefront to receive the security token. At the storefront, an identity of the requesting user can be verified, such as through photo identification. The security token can be provided when the requesting user has been successfully verified. Use of the security token can still require activation involving the activation key.


