SCVP Stapling for Mobile Certificate Validation Overhead

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Resource-constrained communication devices, such as digital radio devices in mission-critical settings, face performance impairments due to the resource-intensive process of digital certificate validation, leading to unclear or broken communications.

Innovation Solution

Implementing a stapling technique within the server-based certificate validation protocol (SCVP) where a SCVP responder aggregates validated certificate paths into a SCVP response, which is periodically provided to clients, allowing them to offer this response to relying parties during authentication, thereby reducing the burden on the relying party.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If certificate validation is performed by resource-constrained devices, then authentication security is maintained, but device performance and reliability deteriorate

Engineering Contradiction:
Improveauthentication securityVSAvoiddevice performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts the certificate validation process from the resource-constrained relying party device and relocates it to a server-based SCVP responder. The responder performs the computationally intensive validation operations, while the relying party only needs to send validation requests and receive responses, significantly reducing the processing burden on mobile devices while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an SCVP responder as an intermediary between the relying party and the certificate authority infrastructure. This mediator handles the complex certificate validation operations, including building certificate paths and verifying signatures, thereby shielding resource-constrained devices from performance degradation while preserving authentication security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional SCVP validation is used, then certificate security is ensured, but message traffic and processing overhead increase

Engineering Contradiction:
Improvecertificate securityVSAvoidprocessing overhead
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent implements preliminary action by having the SCVP responder pre-compute and cache validated certificate paths before they are needed by relying parties. When a relying party needs validation, the pre-computed results are readily available, eliminating the need for real-time computation and reducing both processing overhead and energy consumption while maintaining certificate security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system uses periodic action by having the SCVP responder validate certificates at scheduled intervals and update cached validation results. This approach allows the responder to perform intensive validation operations during off-peak periods and serve pre-validated results during active communication, reducing real-time processing overhead while ensuring security through regular validation updates.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS9306932B2Utilizing a stapling technique with a server-based certificate validation protocol to reduce overhead for mobile communication devices
Publication Date: 2016.04.05 MOTOROLA SOLUTIONS INC
  • US9306932B2 patent drawing
  • US9306932B2 patent drawing
  • US9306932B2 patent drawing

AI summary

A certificate issuer (210) can periodically request, receive, and store current server-based certificate validation protocol (SCVP) staples (225) for supported relying parties (205) from at least one server-based certificate validation protocol (SCVP) responder (215). The certificate issuer (210) can receive a contact initiation request (220) from one of the relying parties (205). Responsive to receiving the contact initiation request (220), the certificate issuer (210) can identify a current SCVP staple from the saved staples that is applicable to the relying party (205). The certificate issuer (210) can conveying a response to the contact initiation request (220) to the relying party (205). The response can comprise the identified SCVP staple and a public key infrastructure (PKI) certificate (230) of the certificate issuer. The SCVP staple can validate a certification path between the PKI certificate (230) and a different certificate trusted by the relying party (205).