Secure Certificate System With Multiple Digital Signatures

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing certificate systems are vulnerable to compromise, where a compromised certification authority or certificate can lead to security breaches, such as man-in-the-middle attacks, and replacing multiple certificates can be complex and time-consuming.

Innovation Solution

Implementing a secure certificate system that uses multiple digital signatures and public keys from multiple certification authorities, allowing seamless replacement of compromised signatures and keys without interrupting service, and requiring multiple certificates to verify the organization's ownership and establish a secure session.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single certificate and digital signature are used to verify website ownership, then the system is simpler to manage, but the security is vulnerable to compromise and replacement is time-consuming

Engineering Contradiction:
ImprovesecurityVSAvoidcertificate management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the certificate verification system into multiple independent digital signatures and certificates from different certification authorities. Instead of relying on a single certificate, the system segments the security validation across multiple certificates, allowing the organization to maintain several certificates simultaneously. This segmentation enables seamless replacement of compromised certificates without interrupting service, as other certificates continue to provide validation.

Inventive Principle:
Principle #1Segmentation

2Reliability

If multiple certificates from multiple certification authorities are used, then security is enhanced with additional validation layers, but the system complexity increases

Engineering Contradiction:
Improvesecurity validationVSAvoidcertificate system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple certificates and digital signatures into a unified verification process. The user application is configured to accept and verify multiple certificates from different certification authorities as equivalent validation of organization ownership. This merging approach consolidates the complexity of managing multiple certificates into a single verification mechanism, where any valid certificate from the trusted list suffices for authentication.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system implements universality by making the user application capable of verifying multiple types of certificates from different certification authorities through a common verification process. The application is designed to handle various certificate formats and issuing authorities uniformly, allowing any certified certificate to serve the same authentication function. This multi-functionality reduces the operational complexity despite having multiple certificates.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If a compromised certificate is detected and replaced, then security is maintained, but service interruption occurs during the replacement process

Engineering Contradiction:
Improvesecurity maintenanceVSAvoidservice continuity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements preliminary action by maintaining multiple valid certificates from different certification authorities in advance. Before any certificate is compromised, the organization already has backup certificates ready and configured in the user application. When a compromise is detected, the system can immediately switch to an alternative certificate without interruption, as the replacement certificate was already in place and verified.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system allows for discarding compromised certificates while recovering service continuity through alternative certificates. When a certificate is found to be compromised, it is discarded from the verification process, and the system automatically recovers by using another valid certificate from the multiple certificates that were previously configured. This discarding and recovering process occurs seamlessly without service interruption.

Inventive Principle:
Principle #34Discarding and recovering

4Reliability

If multiple public keys are used for encryption, then security against compromised keys is improved, but the key management process becomes more complex

Engineering Contradiction:
Improveencryption securityVSAvoidkey management ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements self-service by automatically managing multiple public keys and their corresponding certificates. The user application is configured to handle multiple public keys seamlessly, automatically selecting and using appropriate keys for encryption without requiring manual intervention. The system self-manages the complexity of key storage, retrieval, and rotation, making the process as easy as single-key management while providing enhanced security through multiple keys.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10361852B2Secure verification system
Publication Date: 2019.07.23 BANK OF AMERICA CORP
  • US10361852B2 patent drawing
  • US10361852B2 patent drawing
  • US10361852B2 patent drawing

AI summary

Systems, computer products, and methods are described herein for an improved secure certificate system that utilizes multiple digital signatures, and in some cases multiple public keys within one or more certificates. The improved secure certificate systems allows for additional security by having multiple certification authorities validate the organization as the owner of the organization application (e.g., website, dedicated application, or the like), as well as allowing for the use of the multiple digital signatures and/or certificates to provide seamless verification of the organization application should one or more of the digital signatures and/or certificates become compromised. Moreover, security may be improved by utilizing multiple public keys to encrypt a session key for use in sending and receiving data.