Proxy System for Certificate Request Interception and Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Certificate Authorities face challenges in detecting and preventing mis-issued digital certificates, which can lead to security issues due to lack of public scrutiny and potential malicious activities, as these errors may remain undetected for a long time, allowing attackers to exploit them.

Innovation Solution

A proxy system intercepts certificate requests and transmitted certificates, using a workflow engine to run checks based on the certificate contents, requester, and system providing the request or certificate, denying problematic requests, providing warnings, and logging information for audit purposes, ensuring accountability and compliance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If Certificate Authorities keep their internal CA systems and processes confidential and secret, then security protection is improved, but detection of problematic certificate issuance becomes difficult

Engineering Contradiction:
Improvesecurity protectionVSAvoiddetection of problematic certificate issuance
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces a proxy system as an intermediary between the public and the confidential CA internal systems. This proxy system can scrutinize certificate issuance processes without exposing the internal confidential systems, thereby maintaining security while enabling detection of problematic certificates.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The proxy system performs preliminary checks and validations on certificate requests before they are processed by the internal CA systems. This allows potential issues to be detected early in the process while the internal systems remain protected and confidential.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If Certificate Authorities issue certificates without public scrutiny, then issuance speed is improved, but mis-issued certificates remain undetected for long periods

Engineering Contradiction:
Improvecertificate issuance speedVSAvoidcertificate issuance accuracy
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The proxy system acts as a mediator that can validate certificates without significantly slowing down the issuance process. It performs automated checks that are much faster than manual public scrutiny while maintaining high accuracy in detecting mis-issued certificates.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces manual public scrutiny with automated computational validation performed by the proxy system. This substitution maintains high issuance speed while improving detection accuracy through systematic automated checks rather than slow manual processes.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Difficulty of detecting and measuring

If a proxy system is introduced to intercept and evaluate certificate requests, then detection capability is improved, but system complexity increases

Engineering Contradiction:
Improvedetection capabilityVSAvoidsystem complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The proxy system is designed as a separate, modular component that can be added to existing CA infrastructure without restructuring the entire system. This segmentation allows the detection functionality to be implemented independently, reducing the complexity burden on the overall system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

By positioning the proxy system as an intermediary layer, the patent avoids the need to modify internal CA systems. The proxy handles all detection and validation functions externally, preventing complexity from propagating into the core confidential systems while still achieving comprehensive detection capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9208350B2Certificate information verification system
Publication Date: 2015.12.08 DIGICERT INC
  • US9208350B2 patent drawing
  • US9208350B2 patent drawing
  • US9208350B2 patent drawing

AI summary

The invention discloses a system and apparatus for detecting problematic certificate action requests and digital certificates. Ideally, the invention will be used to detect a certificate request that will result in security problems and detect issued certificates that lack essential information. The invention uses a proxy system that intercepts certificate requests and transmitted certificates. The proxy system runs a series of checks on the intercepted request and/or certificate. The checks vary depending on the certificate contents, requester, and system providing the request or certificate.