Secondary Network Certificate Validation Bypassing DNS Spoofing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing public key infrastructure (PKI) systems rely on correct operation of Internet services like DNS and network traffic routing, making them vulnerable to interference by malicious entities that can disrupt certificate validation processes, such as returning incorrect IP addresses or blocking communication with certificate revocation lists (CRLs) or Online Certificate Status Protocol (OCSP) responders.
Innovation Solution
A system and method that utilize a secondary network to validate certificates independently of the primary network path, allowing secure communication by querying a private server that communicates with a third server through a network path not controlled by the interfering entity, thereby avoiding selective filtering and jurisdictional firewalls, and using protocols like OCSP, CRL, and delegated path validation for certificate validation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If certificate validation is performed through the primary network path using standard PKI protocols, then the validation process can access CRLs and OCSP responders, but the network path may be compromised by malicious entities that can return incorrect IP addresses or block communications
Solution Approach 1:
The patent introduces a secondary network path as an intermediary channel for certificate validation. This separate path acts as a mediator that bypasses the compromised primary network, allowing validation requests to reach CRLs and OCSP responders without being subjected to DNS spoofing or traffic blocking by malicious entities controlling the primary network path.
Solution Approach 2:
The patent segments the network communication into two distinct paths: a primary network path for general communication and a secondary network path specifically for certificate validation. This segmentation isolates the validation process from potential compromises in the primary network, ensuring that even if the primary path is attacked, the validation function can still operate through the separate secondary path.
2Reliability
If a secondary network path is introduced for certificate validation, then validation reliability is improved by bypassing compromised network paths, but system complexity increases due to multiple network paths
Solution Approach 1:
The secondary network path serves as a dedicated intermediary infrastructure that simplifies the overall system architecture by providing a specialized channel for validation. Rather than complicating the primary network with multiple validation routes, the patent creates a separate, purpose-built path that handles only certificate validation, making each path's function clear and manageable.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A system for providing security services to a mobile device (100) where the mobile device (100) is in communication with a public network (310) through a first network path (324) that is subject to interference by a third party. The system includes a security server (308) and a private network (306). The security server (308) is operative to communicate with the mobile device (100) through the private network (306). The security server (308) is also operative to communicate with the public network (310) through a second network path (320) that is less susceptible to the interference by the third party than is the first network path (324). The security server (308) communicates with the public network (310) through the second network path (320) to provide security services to the mobile device (100) that are delivered over the private network (306).