Relay Device Certificate Transmission Policy
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Digital certificates issued to users are sometimes inadvertently disclosed to unauthorized business operators, posing security risks, particularly for issuers who wish to restrict access due to concerns about security breaches.
Innovation Solution
A communication system comprising a relay device that manages and relays digitally issued certificates, with a transmission policy controlling which verifiers can receive the certificates, ensuring that certificates are only transmitted to authorized parties as per the issuer's policy, thereby preventing disclosure to undesired operators.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a user presents a digital certificate to a verifier, then the verifier can confirm the user's identity attributes, but the certificate may be disclosed to unauthorized business operators causing security risks
Solution Approach 1:
The patent introduces a relay device as an intermediary between the user and the verifier. The relay device receives the certificate from the user, verifies the user's identity, and then relays the certificate to the verifier. This intermediary mechanism prevents direct disclosure of the certificate to unauthorized operators while maintaining verification reliability, as the relay device controls and monitors the certificate transmission process.
2Object-affected harmful factors
If the issuer restricts certificate access to specific verifiers, then security is improved, but the complexity of managing transmission policies increases
Solution Approach 1:
The patent implements preliminary action by having the relay device pre-establish transmission policies that specify which verifiers are authorized to receive certificates. These policies are configured in advance, allowing the system to automatically enforce access restrictions without complex real-time decision-making. The relay device stores and manages these policies, simplifying the complexity by having a dedicated component handle policy enforcement.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A non-transitory computer-readable storage medium storing a program that causes a computer to execute a process, the process includes receiving a certification of a first communication device from a second communication device which issues the certification to the first communication device; receiving, from the second communication device, policy information which indicates whether the certificate is permitted to be sent; when the first communication device requests that the certificate be sent to the third communication device, determining whether the certificate is permitted to be sent to the third communication device, the third communication device requesting the first communication device to send the certificate, when determining that the certificate is permitted to be sent to the third communication device, sending, to the third communication device, the certificate.