Portable Certification Authority for Ad Hoc Network Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In ad hoc networks, especially among emergency responders, secure communication and authentication of nodes across different agencies are challenging due to the need for a trusted certification authority, which can be cumbersome and computationally intensive, especially in mobile and emergency scenarios.

Innovation Solution

A portable electronic device functions as a portable certification authority, pre-loaded with key pairs and capable of generating and updating certificates, allowing it to authenticate nodes by transferring signed certificates and keys, reducing computational requirements and enabling quick trust establishment based on user judgment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a central certification authority is used to issue digital certificates in ad hoc networks, then security and authentication are ensured, but device complexity and computational requirements increase

Engineering Contradiction:
Improveauthentication securityVSAvoidCA system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the central CA functionality into distributed portable CA devices, each capable of independently issuing certificates. This divides the monolithic CA system into multiple smaller units that can operate autonomously in ad hoc networks, reducing the complexity burden on any single device while maintaining authentication security through distributed trust.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces portable CA devices as intermediary entities between end devices and the root CA. These portable CAs receive certificates from the root CA and distribute them locally, acting as mediators that eliminate the need for end devices to directly communicate with or process complex root CA operations, thus reducing device complexity while preserving security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a central certification authority processes certificate requests in real-time, then certificate freshness is improved, but processing speed and response time decrease in mobile scenarios

Engineering Contradiction:
Improvecertificate validityVSAvoidcertificate issuance speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent implements preliminary action by having portable CA devices pre-loaded with root CA certificates and authorization to issue certificates locally. This allows certificate issuance to occur immediately without real-time communication with the central CA, dramatically improving issuance speed while maintaining certificate validity through pre-established trust relationships.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables dynamic operation where portable CA devices can independently issue certificates without continuous connection to the central CA. This dynamic capability allows the system to adapt to mobile scenarios where connectivity is intermittent, maintaining both certificate validity and fast issuance by allowing offline certificate generation.

Inventive Principle:
Principle #15Dynamics

3Measurement precision

If full certificate verification is performed computationally, then authentication accuracy is improved, but energy consumption and computational burden increase on mobile devices

Engineering Contradiction:
Improveauthentication accuracyVSAvoiddevice energy consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent extracts the computationally intensive certificate verification and issuance operations from mobile end devices and concentrates them in portable CA devices. This extraction allows end devices to perform simpler verification tasks while the heavy computational lifting is done by the specialized portable CAs, reducing energy consumption on battery-powered devices while maintaining authentication accuracy.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent enables portable CA devices to self-perform certificate issuance and verification operations without requiring end devices to have full CA capabilities. The portable CAs serve themselves by maintaining their own key pairs and certificate stores, eliminating the need for energy-intensive verification operations on resource-constrained mobile devices while preserving authentication accuracy.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11418318B2Portable certification authority
Publication Date: 2022.08.16 MOTOROLA SOLUTIONS INC
  • US11418318B2 patent drawing
  • US11418318B2 patent drawing
  • US11418318B2 patent drawing

AI summary

A portable electronic device is operable as a portable certification authority. The portable electronic device stores a pair of keys of a public key infrastructure, issued by a parent certification authority and generates a certificate dependent upon the pair of keys. The private key and corresponding public key certificate are transmitted to a network device of a second agency to allow the device to be authenticated by any node of the network of the first agency that posses anchor information of the parent certification authority. This enables the device of the second agency to be authenticated by a network node of the first agency.