Registration Authority Certificate Requests with Verified Audit Logging
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In public key infrastructure (PKI) systems, attackers can gain access to registration authority credentials, enabling them to request and install counterfeit certificates on devices, and tamper with log information, making it difficult to trace the origin of certificate requests.
Innovation Solution
A method involving a logging device that stores certificate requests in an audit-proof manner, using confirmation identifiers signed with cryptographic keys, ensuring that each request is logged and verified before a certificate is issued, allowing tracing back to the requesting registration authority.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If certificate requests are transmitted through multiple hops with sender information modified by multiple components, then the certificate issuance process can be distributed and flexible, but the ability to trace the originating registry is lost
Solution Approach 1:
The patent applies preliminary action by embedding the originating registry identifier and request information into the certificate request message before it is transmitted through multiple hops. This ensures that the traceability information is preserved throughout the distributed processing chain, allowing the certification authority to identify the original requesting registry even after the request has been modified by intermediate components.
2Ease of operation
If log data is stored locally on the registry, then logging can be performed without centralized coordination, but an attacker can access and manipulate the log information
Solution Approach 1:
The patent introduces a logging device as an intermediary component that receives logging messages from the registry and stores them in an audit-proof manner. This mediator separates the logging function from the registry itself, maintaining the ease of distributed logging while ensuring log integrity through cryptographic verification and centralized secure storage.
Solution Approach 2:
The patent applies preliminary anti-action by implementing cryptographic signing of logging messages and using confirmation identifiers before the attacker can manipulate the logs. The audit-proof storage mechanism and verification processes are established in advance to prevent log tampering, rather than attempting to detect or correct manipulation after it occurs.
3Productivity
If a registry is manipulated by an attacker, then counterfeit certificates can be issued, but the manipulated registry cannot be easily identified without centralized logging
Solution Approach 1:
The patent implements feedback by requiring the registry to receive a confirmation identifier from the logging device that verifies the logging message was successfully stored. This feedback mechanism ensures that each certificate request is properly logged and traceable, enabling quick identification of manipulated registries while maintaining efficient certificate issuance through automated verification.
Data Source
Figure 1~2
Figure 3~5
Figure 6
AI summary
The invention relates to a method and a system (20) for requesting certificates for a user (10) in a documented manner, comprising at least one registration point (21, 22), a logging device (23), and a certification point (24) which are designed to carry out the following steps: a) receiving in the registration point (21) a certificate request for issuing a certificate to a user (10), b) transmitting a logging message which contains information on the certificate request from the registration point (21) to a logging device (23), c) receiving a confirmation identifier if the information in the logging device (23) has been successfully stored, d) forwarding to the certification point (24) an expanded certificate request message which is complemented by the confirmation identifier, e) checking the confirmation identifier, and f) processing the expanded certificate request and outputting a certificate response by means of the certification point (24) only if the check is successfully carried out.