Rescue Public Key Certificate for Secure Communication Continuity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication systems face challenges in securely authenticating communication apparatuses over networks, particularly when public key certificates expire, leading to disruptions in secure communication due to the inability to reliably renew or obtain new certificates, especially in scenarios where apparatuses are switched off or inoperable.
Innovation Solution
A communication apparatus and system that employs a dual-certification approach using a regular public key certificate with a short validity term and a rescue public key certificate with a longer validity term, allowing authentication to continue even after the regular certificate expires, enabling secure transmission and updating of new certificates.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a public key certificate with a short validity term is used for authentication, then security is improved by limiting the exposure window, but communication continuity deteriorates when the certificate expires
Solution Approach 1:
The system performs preliminary actions by storing both the current certificate and a backup certificate in advance. When the current certificate expires, the backup certificate is immediately activated without interruption, ensuring continuous authentication capability. This preliminary preparation resolves the contradiction by having ready-to-use alternative authentication materials before the primary certificate expires.
Solution Approach 2:
The system changes the parameter of certificate validity by maintaining two certificates with different validity terms - a current certificate with shorter validity for security and a backup certificate with longer validity for continuity. This parameter differentiation allows the system to transition from security-oriented to continuity-oriented authentication when needed.
2Duration of action of stationary object
If a public key certificate with a long validity term is used for authentication, then communication continuity is maintained, but security deteriorates due to extended exposure window
Solution Approach 1:
The authentication function is segmented into two separate certificate components: a current certificate with short validity for security-critical operations and a backup certificate with long validity for continuity. This segmentation allows each certificate to serve its specific purpose optimally, resolving the contradiction between security and continuity.
Solution Approach 2:
The system employs parameter changes by assigning different validity terms to different certificates based on their functional roles. The current certificate uses short validity for security, while the backup certificate uses long validity for continuity, allowing the system to optimize both parameters simultaneously.
3Reliability
If certificate renewal procedures are made complex to ensure security, then authentication security is improved, but ease of operation deteriorates
Solution Approach 1:
The system implements self-service by automatically switching from the current certificate to the backup certificate when expiration is detected, without requiring manual intervention. The authentication function handles its own renewal process internally, maintaining security while simplifying operation for users.
Solution Approach 2:
The backup certificate acts as an intermediary that automatically takes over when the current certificate expires. This intermediary mechanism bridges the gap between certificate expiration and renewal, ensuring continuous operation without complex user actions.
Data Source
AI summary
A communication apparatus includes an authentication part for authenticating another communication apparatus with a first digital certificate, and a certificate transmission part for transmitting a second digital certificate when the authentication part succeeds in authenticating the other communication apparatus with the first digital certificate.


