Distributed Satellite CA for IoT Certificate Renewal

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing certificate renewal methods for IoT devices face challenges such as delayed renewal due to geographical dispersion, high processing burden on central Certificate Authorities (CAs), and low efficiency, leading to security vulnerabilities and system failures.

Innovation Solution

A distributed CA structure is introduced, with satellite CAs having limited functions to share the processing burden, allowing IoT devices to access nearby satellite CAs for efficient certificate renewal, using a level 3 certificate system where satellite CAs generate new device certificates by signing procedures using a private key corresponding to a level 3 certificate.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a centralized CA system is used for certificate renewal, then certificate management is simplified, but the processing burden on the central CA becomes large and system reliability decreases

Engineering Contradiction:
Improvecertificate management complexityVSAvoidsystem reliability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent divides the centralized CA system into multiple distributed CAs (first CA, second CA, third CA, etc.), each responsible for managing certificates for specific device groups. This segmentation reduces the processing burden on any single CA while maintaining simplified management through hierarchical organization, thereby improving system reliability without sacrificing management simplicity.

Inventive Principle:
Principle #1Segmentation

2Extent of automation

If manual renewal application to central CA is used, then centralized control is maintained, but renewal efficiency becomes low

Engineering Contradiction:
Improverenewal automation levelVSAvoidrenewal efficiency
Core Design Contradiction:
Extent of automationVSProductivity

Solution Approach 1:

The patent implements self-service renewal mechanisms where CAs automatically manage certificate renewals for their respective device groups without requiring manual applications from individual devices or the central authority. The first CA, second CA, and third CA autonomously perform renewal operations, significantly improving efficiency while maintaining controlled automation through predefined policies and hierarchical oversight.

Inventive Principle:
Principle #25Self-service

3Reliability

If central CA handles all certificate renewals, then centralized security control is maintained, but processing time increases and user experience deteriorates

Engineering Contradiction:
Improvesecurity controlVSAvoidrenewal processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent assigns different roles and responsibilities to different CAs based on local needs and device distributions. The first CA, second CA, and third CA each manage renewal operations for specific local device groups, enabling faster processing times while maintaining security control through hierarchical policies and centralized oversight for critical security functions.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11483165B2Certificate renewal method, apparatus, system, medium, and device
Publication Date: 2022.10.25 LINGCHUANFENG (GUIZHOU) INFORMATION TECHNOLOGY CO LTD
  • US11483165B2 patent drawing
  • US11483165B2 patent drawing
  • US11483165B2 patent drawing

AI summary

A certificate renewal method includes a satellite certification authority (CA) receiving, from a central CA, permission configuration information including permission information for indicating that only renewal processes are executed, receiving a renewal request transmitted by a device, judging whether a renewal condition is satisfied, generating a new device certificate via a signing procedure implemented using a private key corresponding to a level 3 certificate of the satellite CA in response to determining that the renewal condition is satisfied, and transmitting the new device certificate to the device.