Relay Device Certificate Transmission Policy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Digital certificates issued to users are sometimes inadvertently disclosed to unauthorized business operators, posing security risks, particularly for issuers who wish to restrict access due to concerns about security breaches.

Innovation Solution

A communication system comprising a relay device that manages and relays digitally issued certificates, with a transmission policy controlling which verifiers can receive the certificates, ensuring that certificates are only transmitted to authorized parties as per the issuer's policy, thereby preventing disclosure to undesired operators.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a user presents a digital certificate to a verifier, then the verifier can confirm the user's identity attributes, but the certificate may be disclosed to unauthorized business operators causing security risks

Engineering Contradiction:
Improveidentity verification reliabilityVSAvoidcertificate disclosure risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a relay device as an intermediary between the user and the verifier. The relay device receives the certificate from the user, verifies the user's identity, and then relays the certificate to the verifier. This intermediary mechanism prevents direct disclosure of the certificate to unauthorized operators while maintaining verification reliability, as the relay device controls and monitors the certificate transmission process.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If the issuer restricts certificate access to specific verifiers, then security is improved, but the complexity of managing transmission policies increases

Engineering Contradiction:
Improveunauthorized access preventionVSAvoidtransmission policy management complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by having the relay device pre-establish transmission policies that specify which verifiers are authorized to receive certificates. These policies are configured in advance, allowing the system to automatically enforce access restrictions without complex real-time decision-making. The relay device stores and manages these policies, simplifying the complexity by having a dedicated component handle policy enforcement.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3944583B1Communication program, relay device, and communication method
Publication Date: 2023.07.12 FUJITSU LTD
  • EP3944583B1 patent drawingFigure 1
  • EP3944583B1 patent drawingFigure 2
  • EP3944583B1 patent drawingFigure 3

AI summary

A non-transitory computer-readable storage medium storing a program that causes a computer to execute a process, the process includes receiving a certification of a first communication device from a second communication device which issues the certification to the first communication device; receiving, from the second communication device, policy information which indicates whether the certificate is permitted to be sent; when the first communication device requests that the certificate be sent to the third communication device, determining whether the certificate is permitted to be sent to the third communication device, the third communication device requesting the first communication device to send the certificate, when determining that the certificate is permitted to be sent to the third communication device, sending, to the third communication device, the certificate.