SCVP Stapling for Mobile Certificate Validation Overhead
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Resource-constrained communication devices, such as digital radio devices in mission-critical settings, face performance impairments due to the resource-intensive process of digital certificate validation, leading to unclear or broken communications.
Innovation Solution
Implementing a stapling technique within the server-based certificate validation protocol (SCVP) where a SCVP responder aggregates validated certificate paths into a SCVP response, which is periodically provided to clients, allowing them to offer this response to relying parties during authentication, thereby reducing the burden on the relying party.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If certificate validation is performed by resource-constrained devices, then authentication security is maintained, but device performance and reliability deteriorate
Solution Approach 1:
The patent extracts the certificate validation process from the resource-constrained relying party device and relocates it to a server-based SCVP responder. The responder performs the computationally intensive validation operations, while the relying party only needs to send validation requests and receive responses, significantly reducing the processing burden on mobile devices while maintaining security.
Solution Approach 2:
The patent introduces an SCVP responder as an intermediary between the relying party and the certificate authority infrastructure. This mediator handles the complex certificate validation operations, including building certificate paths and verifying signatures, thereby shielding resource-constrained devices from performance degradation while preserving authentication security.
2Reliability
If traditional SCVP validation is used, then certificate security is ensured, but message traffic and processing overhead increase
Solution Approach 1:
The patent implements preliminary action by having the SCVP responder pre-compute and cache validated certificate paths before they are needed by relying parties. When a relying party needs validation, the pre-computed results are readily available, eliminating the need for real-time computation and reducing both processing overhead and energy consumption while maintaining certificate security.
Solution Approach 2:
The system uses periodic action by having the SCVP responder validate certificates at scheduled intervals and update cached validation results. This approach allows the responder to perform intensive validation operations during off-peak periods and serve pre-validated results during active communication, reducing real-time processing overhead while ensuring security through regular validation updates.
Data Source
AI summary
A certificate issuer (210) can periodically request, receive, and store current server-based certificate validation protocol (SCVP) staples (225) for supported relying parties (205) from at least one server-based certificate validation protocol (SCVP) responder (215). The certificate issuer (210) can receive a contact initiation request (220) from one of the relying parties (205). Responsive to receiving the contact initiation request (220), the certificate issuer (210) can identify a current SCVP staple from the saved staples that is applicable to the relying party (205). The certificate issuer (210) can conveying a response to the contact initiation request (220) to the relying party (205). The response can comprise the identified SCVP staple and a public key infrastructure (PKI) certificate (230) of the certificate issuer. The SCVP staple can validate a certification path between the PKI certificate (230) and a different certificate trusted by the relying party (205).


