Root Certificate Distribution Across Heterogeneous Trust Hierarchies

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In a public network, securely distributing and authenticating root certificates across devices with different certificate hierarchies is challenging, especially when devices are not certified by a common authority, hindering secure communication and content transfer between devices with varying trust chains.

Innovation Solution

A system comprising a central trust controller, trust repository system, and network headends that receive and distribute root certificates, allowing endpoint devices to request and obtain necessary root certificates to verify identities, even if they belong to different certificate hierarchies, facilitating secure communication and content transfer.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If devices with different certificate hierarchies communicate over a public network, then communication versatility is improved, but authentication reliability deteriorates because devices cannot verify each other's identities without common root certificates

Engineering Contradiction:
Improvecommunication compatibilityVSAvoididentity verification
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a intermediary system (certificate distribution server or network headend) that acts as a mediator between devices with different certificate hierarchies. This intermediary stores multiple root certificates from different certificate authorities and distributes them to devices that need them, enabling cross-hierarchy verification without requiring the device itself to maintain multiple trust chains.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary distribution of root certificates to devices before they need to communicate. Network headends pre-load and store root certificates from various certificate authorities, so when devices need to verify identities, the required certificates are already available locally, enabling immediate verification without real-time network requests.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If root certificates are distributed on-demand from a central server, then certificate freshness is improved, but network traffic and bandwidth consumption increase

Engineering Contradiction:
Improvecertificate freshnessVSAvoidnetwork bandwidth
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

Root certificates are distributed and cached in advance at network headends and intermediate servers before they are needed. This preliminary distribution creates a distributed cache system where certificates are stored locally at multiple points in the network, eliminating the need for real-time downloads from the central server and reducing network traffic.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements local caching of root certificates at network headends and intermediate servers rather than relying on a single central distribution point. Each local node stores relevant certificates and serves them to devices in its vicinity, reducing the load on the central server and minimizing network bandwidth consumption for certificate distribution.

Inventive Principle:
Principle #3Local quality

3Reliability

If multiple root certificates are stored and distributed across the network, then authentication capability is improved, but device complexity and storage requirements increase

Engineering Contradiction:
Improveauthentication capabilityVSAvoidcertificate storage
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the storage and distribution of root certificates across multiple network nodes rather than concentrating all certificates in one location or requiring each device to store all certificates. Network headends, intermediate servers, and local devices each store a subset of certificates appropriate to their function and location, distributing the storage burden throughout the network infrastructure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Network headends and intermediate servers are designed with multi-functionality, serving both as network infrastructure components and as certificate distribution points. These nodes perform their primary network functions while also storing and distributing root certificates, eliminating the need for separate dedicated certificate storage systems and reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Speed

If devices pre-load all possible root certificates, then verification speed is improved, but device memory and storage requirements increase

Engineering Contradiction:
Improveverification speedVSAvoiddevice storage
Core Design Contradiction:
SpeedVSQuantity of substance

Solution Approach 1:

Instead of uniformly distributing all root certificates to all devices, the system implements local quality by having each device and network node store only the subset of certificates relevant to its specific needs and location. Network headends store certificates for devices in their network segment, and devices store certificates for the specific certificate authorities used by devices they need to communicate with.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system performs preliminary distribution of certificates at the network infrastructure level rather than requiring each device to pre-load all certificates. Network headends and intermediate servers pre-load and cache certificates in advance, making them readily available for local devices without requiring the devices themselves to maintain large certificate stores.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS7877600B2Method and apparatus for distributing root certification
Publication Date: 2011.01.25 GOOGLE TECHNOLOGY HOLDINGS LLC
  • US7877600B2 patent drawing
  • US7877600B2 patent drawing
  • US7877600B2 patent drawing

AI summary

An apparatus and method for providing at least one root certificate are disclosed. Specifically, a plurality of root certificates is received and stored. Afterwards, a request is received from a first endpoint device for a desired root certificate, where the desired root certificate is used by the first endpoint device to verify an identity of a second endpoint device. Furthermore, the first endpoint device and the second endpoint device are associated with different certificate hierarchies. The desired root certificate is then sent to at least the first endpoint device.