SCVP Stapling for Mobile Certificate Validation Overhead
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Resource-constrained communication devices, such as those used in public safety settings, face impaired performance due to the resource-intensive process of digital certificate validation, leading to unclear or broken communications.
Innovation Solution
Implementing a stapling technique with the server-based certificate validation protocol (SCVP) where the certificate subject aggregates and maintains SCVP responses, reducing the need for the relying party to perform extensive certificate path validation by providing pre-validated SCVP staples during communication initiation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the relying party performs full certificate path validation, then authentication security is ensured, but processing overhead and resource consumption increase significantly
Solution Approach 1:
The certificate subject performs certificate path validation in advance and obtains SCVP responses before communication occurs. These pre-validated responses are then provided to the relying party, eliminating the need for the relying party to perform resource-intensive validation operations.
Solution Approach 2:
The certificate subject acts as an intermediary that performs validation on behalf of the relying party. By having the subject aggregate and maintain SCVP responses, the system transfers the validation burden from the resource-constrained relying party to the subject, which has more computational resources available.
2Reliability
If the relying party performs extensive certificate validation, then authentication reliability is improved, but message traffic and bandwidth consumption increase
Solution Approach 1:
The validation process and SCVP responses are extracted from the relying party and consolidated into the certificate subject. The subject aggregates validation results for multiple relying parties, reducing redundant message traffic and bandwidth consumption that would occur if each relying party performed independent validation.
3Reliability
If resource-constrained devices perform certificate validation, then security is maintained, but communication performance and reliability deteriorate
Solution Approach 1:
The certificate subject serves itself and other relying parties by performing validation operations and maintaining SCVP responses. This self-service approach allows the subject to handle validation tasks that would otherwise burden resource-constrained relying parties, maintaining security while improving communication performance.
Data Source
AI summary
A certificate issuer (210) can periodically request, receive, and store current server-based certificate validation protocol (SCVP) staples (225) for supported relying parties (205) from at least one server-based certificate validation protocol (SCVP) responder (215). The certificate issuer (210) can receive a contact initiation request (220) from one of the relying parties (205). Responsive to receiving the contact initiation request (220), the certificate issuer (210) can identify a current SCVP staple from the saved staples that is applicable to the relying party (205). The certificate issuer (210) can conveying a response to the contact initiation request (220) to the relying party (205). The response can comprise the identified SCVP staple and a public key infrastructure (PKI) certificate (230) of the certificate issuer. The SCVP staple can validate a certification path between the PKI certificate (230) and a different certificate trusted by the relying party (205).


