Registration Authority Certificate Requests with Verified Audit Logging

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In public key infrastructure (PKI) systems, attackers can gain access to registration authority credentials, enabling them to request and install counterfeit certificates on devices, and tamper with log information, making it difficult to trace the origin of certificate requests.

Innovation Solution

A method involving a logging device that stores certificate requests in an audit-proof manner, using confirmation identifiers signed with cryptographic keys, ensuring that each request is logged and verified before a certificate is issued, allowing tracing back to the requesting registration authority.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If certificate requests are transmitted through multiple hops with sender information modified by multiple components, then the certificate issuance process can be distributed and flexible, but the ability to trace the originating registry is lost

Engineering Contradiction:
Improvedistributed certificate issuanceVSAvoidoriginating registry information
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent applies preliminary action by embedding the originating registry identifier and request information into the certificate request message before it is transmitted through multiple hops. This ensures that the traceability information is preserved throughout the distributed processing chain, allowing the certification authority to identify the original requesting registry even after the request has been modified by intermediate components.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If log data is stored locally on the registry, then logging can be performed without centralized coordination, but an attacker can access and manipulate the log information

Engineering Contradiction:
Improvedistributed loggingVSAvoidlog integrity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a logging device as an intermediary component that receives logging messages from the registry and stores them in an audit-proof manner. This mediator separates the logging function from the registry itself, maintaining the ease of distributed logging while ensuring log integrity through cryptographic verification and centralized secure storage.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies preliminary anti-action by implementing cryptographic signing of logging messages and using confirmation identifiers before the attacker can manipulate the logs. The audit-proof storage mechanism and verification processes are established in advance to prevent log tampering, rather than attempting to detect or correct manipulation after it occurs.

Inventive Principle:
Principle #9Preliminary anti-action

3Productivity

If a registry is manipulated by an attacker, then counterfeit certificates can be issued, but the manipulated registry cannot be easily identified without centralized logging

Engineering Contradiction:
Improvecertificate issuance speedVSAvoidregistry compromise detection
Core Design Contradiction:
ProductivityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements feedback by requiring the registry to receive a confirmation identifier from the logging device that verifies the logging message was successfully stored. This feedback mechanism ensures that each certificate request is properly logged and traceable, enabling quick identification of manipulated registries while maintaining efficient certificate issuance through automated verification.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP4466822B1Traceable request of a certificate request by a registration authority
Publication Date: 2025.09.03 SIEMENS AG
  • EP4466822B1 patent drawingFigure 1~2
  • EP4466822B1 patent drawingFigure 3~5
  • EP4466822B1 patent drawingFigure 6

AI summary

The invention relates to a method and a system (20) for requesting certificates for a user (10) in a documented manner, comprising at least one registration point (21, 22), a logging device (23), and a certification point (24) which are designed to carry out the following steps: a) receiving in the registration point (21) a certificate request for issuing a certificate to a user (10), b) transmitting a logging message which contains information on the certificate request from the registration point (21) to a logging device (23), c) receiving a confirmation identifier if the information in the logging device (23) has been successfully stored, d) forwarding to the certification point (24) an expanded certificate request message which is complemented by the confirmation identifier, e) checking the confirmation identifier, and f) processing the expanded certificate request and outputting a certificate response by means of the certification point (24) only if the check is successfully carried out.