Distributed Satellite CA for IoT Certificate Renewal
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing certificate renewal methods for IoT devices face challenges such as delayed renewal due to geographical dispersion, high processing burden on central Certificate Authorities (CAs), and low efficiency, leading to security vulnerabilities and system failures.
Innovation Solution
A distributed CA structure is introduced, with satellite CAs having limited functions to share the processing burden, allowing IoT devices to access nearby satellite CAs for efficient certificate renewal, using a level 3 certificate system where satellite CAs generate new device certificates by signing procedures using a private key corresponding to a level 3 certificate.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If a centralized CA system is used for certificate renewal, then certificate management is simplified, but the processing burden on the central CA becomes large and system reliability decreases
Solution Approach 1:
The patent divides the centralized CA system into multiple distributed CAs (first CA, second CA, third CA, etc.), each responsible for managing certificates for specific device groups. This segmentation reduces the processing burden on any single CA while maintaining simplified management through hierarchical organization, thereby improving system reliability without sacrificing management simplicity.
2Extent of automation
If manual renewal application to central CA is used, then centralized control is maintained, but renewal efficiency becomes low
Solution Approach 1:
The patent implements self-service renewal mechanisms where CAs automatically manage certificate renewals for their respective device groups without requiring manual applications from individual devices or the central authority. The first CA, second CA, and third CA autonomously perform renewal operations, significantly improving efficiency while maintaining controlled automation through predefined policies and hierarchical oversight.
3Reliability
If central CA handles all certificate renewals, then centralized security control is maintained, but processing time increases and user experience deteriorates
Solution Approach 1:
The patent assigns different roles and responsibilities to different CAs based on local needs and device distributions. The first CA, second CA, and third CA each manage renewal operations for specific local device groups, enabling faster processing times while maintaining security control through hierarchical policies and centralized oversight for critical security functions.
Data Source
AI summary
A certificate renewal method includes a satellite certification authority (CA) receiving, from a central CA, permission configuration information including permission information for indicating that only renewal processes are executed, receiving a renewal request transmitted by a device, judging whether a renewal condition is satisfied, generating a new device certificate via a signing procedure implemented using a private key corresponding to a level 3 certificate of the satellite CA in response to determining that the renewal condition is satisfied, and transmitting the new device certificate to the device.


