Secure Certificate Signing Subsystem with Remote Authority

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing certificate signing systems stored on flash disks are insecure, leading to risks of theft and have slow execution speeds, along with high setup costs due to the need for on-site setup by the unit requiring the certificate.

Innovation Solution

A management system and method for secure certificate signing that uses asymmetric algorithms to generate and manage public and private keys, with secure storage and authorization mechanisms to protect internal files, ensuring identity verification and secure data transfer, and a controlled setup process to reduce costs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the certificate signing system is stored in a flash disk for portability, then the system can be carried along arbitrarily, but the security is compromised because there is no facility to protect internal files

Engineering Contradiction:
ImproveportabilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system is segmented into a certificate management client that handles portability and a remote certificate authority server that handles security. The private key is segmented into two parts: one stored securely on the client device and another part held by the remote server, so that neither part alone can compromise security while maintaining portability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A remote certificate authority server acts as an intermediary between the portable flash disk and the certificate signing process. The flash disk communicates with the remote server, which verifies identities and performs signing operations, eliminating the need for the flash disk to store sensitive signing capabilities locally.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If the certificate signing system is stored in a flash disk, then portability is achieved, but the execution speed is poor

Engineering Contradiction:
ImproveportabilityVSAvoidexecution speed
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The computationally intensive certificate signing operations are extracted from the portable flash disk and performed on a remote server with greater computational resources. The flash disk retains only lightweight functions for key storage and communication, significantly improving execution speed while maintaining portability.

Inventive Principle:
Principle #2Taking out (Extraction)

3Adaptability or versatility

If each unit sets up their own certificate signing system, then customization is possible, but the setup costs increase

Engineering Contradiction:
ImprovecustomizationVSAvoidsetup costs
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The remote certificate authority server provides universal certificate signing services to multiple different units and organizations. Each unit can be customized with specific certificate templates and policies, but the underlying infrastructure is shared, dramatically reducing setup and maintenance costs compared to each unit having its own complete signing system.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3890263B1Management system and method for secure signing of certificates
Publication Date: 2024.11.20 ECOLUX TECH CO LTD
  • EP3890263B1 patent drawingFigure 1
  • EP3890263B1 patent drawingFigure 2
  • EP3890263B1 patent drawingFigure 3

AI summary

A management system and a method for secure signing of certificates, which have a certificate signing subsystem set up in a device of a controlled management site, unless authorized externally, internal data of the subsystem cannot be accessed arbitrarily, and each unit applying for a certificate needs confirmation of identity to increase the security of certificate application and signing. In addition, the certificate signing subsystem is a device with arithmetic capability, which operates fast and can increase the efficiency of certificate signing. Because units or companies applying for certificates do not need to set up a certificate signing system by themselves, provided that they are connected to the certificate signing subsystem of the present invention, certificates can be applied for and obtained, thereby saving business operating costs.