Secondary Network Certificate Validation Bypassing DNS Spoofing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing public key infrastructure (PKI) systems rely on correct operation of Internet services like DNS and network traffic routing, making them vulnerable to interference by malicious entities that can disrupt certificate validation processes, such as returning incorrect IP addresses or blocking communication with certificate revocation lists (CRLs) or Online Certificate Status Protocol (OCSP) responders.

Innovation Solution

A system and method that utilize a secondary network to validate certificates independently of the primary network path, allowing secure communication by querying a private server that communicates with a third server through a network path not controlled by the interfering entity, thereby avoiding selective filtering and jurisdictional firewalls, and using protocols like OCSP, CRL, and delegated path validation for certificate validation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If certificate validation is performed through the primary network path using standard PKI protocols, then the validation process can access CRLs and OCSP responders, but the network path may be compromised by malicious entities that can return incorrect IP addresses or block communications

Engineering Contradiction:
Improvecertificate validation reliabilityVSAvoidnetwork interference
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a secondary network path as an intermediary channel for certificate validation. This separate path acts as a mediator that bypasses the compromised primary network, allowing validation requests to reach CRLs and OCSP responders without being subjected to DNS spoofing or traffic blocking by malicious entities controlling the primary network path.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the network communication into two distinct paths: a primary network path for general communication and a secondary network path specifically for certificate validation. This segmentation isolates the validation process from potential compromises in the primary network, ensuring that even if the primary path is attacked, the validation function can still operate through the separate secondary path.

Inventive Principle:
Principle #1Segmentation

2Reliability

If a secondary network path is introduced for certificate validation, then validation reliability is improved by bypassing compromised network paths, but system complexity increases due to multiple network paths

Engineering Contradiction:
Improvecertificate validation reliabilityVSAvoidnetwork path complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The secondary network path serves as a dedicated intermediary infrastructure that simplifies the overall system architecture by providing a specialized channel for validation. Rather than complicating the primary network with multiple validation routes, the patent creates a separate, purpose-built path that handles only certificate validation, making each path's function clear and manageable.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2888854B1A system and method for providing a certificate-based trust framework using a secondary network
Publication Date: 2018.02.21 BLACKBERRY LTD
  • EP2888854B1 patent drawingFigure 1
  • EP2888854B1 patent drawingFigure 2
  • EP2888854B1 patent drawingFigure 3

AI summary

A system for providing security services to a mobile device (100) where the mobile device (100) is in communication with a public network (310) through a first network path (324) that is subject to interference by a third party. The system includes a security server (308) and a private network (306). The security server (308) is operative to communicate with the mobile device (100) through the private network (306). The security server (308) is also operative to communicate with the public network (310) through a second network path (320) that is less susceptible to the interference by the third party than is the first network path (324). The security server (308) communicates with the public network (310) through the second network path (320) to provide security services to the mobile device (100) that are delivered over the private network (306).