Positive List Data Structure for Secure Certificate Updates
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In industrial automation installations, updating certificates for communication partners leads to a high volume of messages, tying up processor capacity and generating excessive network traffic, as existing methods require frequent updates and validation across multiple servers.
Innovation Solution
A data structure for a positive list within devices includes entries for each permitted communication partner with a unique identifier, a certificate field value, and a check value generated using a one-way function, allowing for autonomous validation and update of certificates, reducing network load by maintaining both old and new check values during transition periods.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If certificate updates are performed using traditional validation methods, then communication security is maintained, but network traffic increases and processor capacity is tied up
Solution Approach 1:
The patent extracts the essential verification element (check value) from the complete certificate validation process. Instead of transmitting and validating entire certificates, only the critical check value is exchanged and verified, dramatically reducing network traffic while maintaining security validation.
Solution Approach 2:
The patent uses check values as simplified copies or representations of the full certificate validation state. These check values contain the essential authentication information needed to verify certificate validity without requiring the complete certificate data to be transmitted and processed.
2Reliability
If frequent certificate updates are performed to maintain security, then authentication reliability is improved, but network loading and processor usage increase
Solution Approach 1:
The patent extracts only the necessary verification component (check value) from the full certificate update process. This allows frequent authentication checks to be performed with minimal data transmission and processing overhead, maintaining authentication reliability without sacrificing network efficiency.
3Measurement precision
If complete certificate validation is performed for each communication partner, then authentication accuracy is improved, but communication speed decreases
Solution Approach 1:
The patent uses check values as compact representations that capture the essential authentication information. Verifying these check values provides sufficient authentication accuracy for the application while being significantly faster than complete certificate validation, thus improving communication speed.
Data Source
AI summary
A data structure is provided for use as a positive list in a device, including an entry for each permitted communication partner of the device having a first identifier that explicitly identifies the communication partner, a value of a predetermined certificate field that identifies a certificate as explicitly associated with the communication partner, and a respective check value from at least one certificate of a communication partner that explicitly identifies the certificate. A method for updating the positive list for certificates from permitted communication partners of a device comprises the method steps of receiving a new certificate from a communication partner in the device, checking whether the positive list has an entry having an identifier of the communication partner and a value of a predetermined certificate field from the new certificate.


