Secure Certificate System With Multiple Digital Signatures
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing certificate systems are vulnerable to compromise, where a compromised certification authority or certificate can lead to security breaches, such as man-in-the-middle attacks, and replacing multiple certificates can be complex and time-consuming.
Innovation Solution
Implementing a secure certificate system that uses multiple digital signatures and public keys from multiple certification authorities, allowing seamless replacement of compromised signatures and keys without interrupting service, and requiring multiple certificates to verify the organization's ownership and establish a secure session.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a single certificate and digital signature are used to verify website ownership, then the system is simpler to manage, but the security is vulnerable to compromise and replacement is time-consuming
Solution Approach 1:
The patent divides the certificate verification system into multiple independent digital signatures and certificates from different certification authorities. Instead of relying on a single certificate, the system segments the security validation across multiple certificates, allowing the organization to maintain several certificates simultaneously. This segmentation enables seamless replacement of compromised certificates without interrupting service, as other certificates continue to provide validation.
2Reliability
If multiple certificates from multiple certification authorities are used, then security is enhanced with additional validation layers, but the system complexity increases
Solution Approach 1:
The patent merges multiple certificates and digital signatures into a unified verification process. The user application is configured to accept and verify multiple certificates from different certification authorities as equivalent validation of organization ownership. This merging approach consolidates the complexity of managing multiple certificates into a single verification mechanism, where any valid certificate from the trusted list suffices for authentication.
Solution Approach 2:
The system implements universality by making the user application capable of verifying multiple types of certificates from different certification authorities through a common verification process. The application is designed to handle various certificate formats and issuing authorities uniformly, allowing any certified certificate to serve the same authentication function. This multi-functionality reduces the operational complexity despite having multiple certificates.
3Reliability
If a compromised certificate is detected and replaced, then security is maintained, but service interruption occurs during the replacement process
Solution Approach 1:
The patent implements preliminary action by maintaining multiple valid certificates from different certification authorities in advance. Before any certificate is compromised, the organization already has backup certificates ready and configured in the user application. When a compromise is detected, the system can immediately switch to an alternative certificate without interruption, as the replacement certificate was already in place and verified.
Solution Approach 2:
The system allows for discarding compromised certificates while recovering service continuity through alternative certificates. When a certificate is found to be compromised, it is discarded from the verification process, and the system automatically recovers by using another valid certificate from the multiple certificates that were previously configured. This discarding and recovering process occurs seamlessly without service interruption.
4Reliability
If multiple public keys are used for encryption, then security against compromised keys is improved, but the key management process becomes more complex
Solution Approach 1:
The system implements self-service by automatically managing multiple public keys and their corresponding certificates. The user application is configured to handle multiple public keys seamlessly, automatically selecting and using appropriate keys for encryption without requiring manual intervention. The system self-manages the complexity of key storage, retrieval, and rotation, making the process as easy as single-key management while providing enhanced security through multiple keys.
Data Source
AI summary
Systems, computer products, and methods are described herein for an improved secure certificate system that utilizes multiple digital signatures, and in some cases multiple public keys within one or more certificates. The improved secure certificate systems allows for additional security by having multiple certification authorities validate the organization as the owner of the organization application (e.g., website, dedicated application, or the like), as well as allowing for the use of the multiple digital signatures and/or certificates to provide seamless verification of the organization application should one or more of the digital signatures and/or certificates become compromised. Moreover, security may be improved by utilizing multiple public keys to encrypt a session key for use in sending and receiving data.


