Root Certificate Management via Multi-Key Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems for securely managing root certificates in electronic devices are vulnerable as they rely on external security mechanisms, making it difficult to update compromised root certificates within the device, leading to potential loss of authentication capabilities.
Innovation Solution
The implementation of a certificate management system within electronic devices that allows for secure replacement of root certificates using multiple private keys for digital signatures, ensuring that only authorized updates can occur, and includes mechanisms for revoking and adding new certificates while maintaining system integrity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If root certificates are embedded in hardware or software at manufacturing time, then initial security and trustworthiness are established, but the system becomes unable to securely update compromised root certificates
Solution Approach 1:
The patent transforms the static embedded certificate system into a dynamic system where root certificates can be securely updated. The certificate management unit enables the system to transition from fixed manufacturing-time certificates to flexible, security-driven certificate replacement without compromising authentication reliability.
Solution Approach 2:
The patent introduces a certificate management unit as an intermediary component between the external certificate authority and the internal authentication system. This mediator enables secure certificate updates by verifying new certificates against stored root certificates before deployment, resolving the contradiction between maintaining trust and enabling updates.
2Ease of manufacture
If external security mechanisms are used for root certificate distribution, then initial certificate installation is simplified, but the system loses the ability to verify integrity of updates autonomously
Solution Approach 1:
The patent enables the system to perform self-service certificate verification by storing root certificates locally in the certificate management unit. The system autonomously verifies incoming certificate updates against these stored roots without requiring continuous external security mechanisms, maintaining both ease of installation and update integrity verification.
3Ease of operation
If root certificates are stored in devices, then authentication functions can operate, but compromised certificates cannot be revoked without external intervention
Solution Approach 1:
The patent implements a feedback mechanism where the certificate management unit receives revocation information from certificate authorities and automatically updates stored root certificates accordingly. This enables reliable certificate revocation within the system without requiring manual intervention or external security mechanisms for each update operation.
Data Source
AI summary
The systems, methods and apparatuses described herein provide a computing environment that manages root certificates. An apparatus according to the present disclosure may comprise a non-volatile storage storing a plurality of root certificates and a supervisor. The supervisor may be configured to receive a message identifying one of the plurality of root certificates stored in the non-volatile storage to be revoked, verify the message being signed by at least two private keys corresponding to two root certificates stored in the non-volatile storage and revoke the root certificate identified in the message.


