Secure Certificate Signing Subsystem with Remote Authority
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing certificate signing systems stored on flash disks are insecure, leading to risks of theft and have slow execution speeds, along with high setup costs due to the need for on-site setup by the unit requiring the certificate.
Innovation Solution
A management system and method for secure certificate signing that uses asymmetric algorithms to generate and manage public and private keys, with secure storage and authorization mechanisms to protect internal files, ensuring identity verification and secure data transfer, and a controlled setup process to reduce costs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the certificate signing system is stored in a flash disk for portability, then the system can be carried along arbitrarily, but the security is compromised because there is no facility to protect internal files
Solution Approach 1:
The system is segmented into a certificate management client that handles portability and a remote certificate authority server that handles security. The private key is segmented into two parts: one stored securely on the client device and another part held by the remote server, so that neither part alone can compromise security while maintaining portability.
Solution Approach 2:
A remote certificate authority server acts as an intermediary between the portable flash disk and the certificate signing process. The flash disk communicates with the remote server, which verifies identities and performs signing operations, eliminating the need for the flash disk to store sensitive signing capabilities locally.
2Adaptability or versatility
If the certificate signing system is stored in a flash disk, then portability is achieved, but the execution speed is poor
Solution Approach 1:
The computationally intensive certificate signing operations are extracted from the portable flash disk and performed on a remote server with greater computational resources. The flash disk retains only lightweight functions for key storage and communication, significantly improving execution speed while maintaining portability.
3Adaptability or versatility
If each unit sets up their own certificate signing system, then customization is possible, but the setup costs increase
Solution Approach 1:
The remote certificate authority server provides universal certificate signing services to multiple different units and organizations. Each unit can be customized with specific certificate templates and policies, but the underlying infrastructure is shared, dramatically reducing setup and maintenance costs compared to each unit having its own complete signing system.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A management system and a method for secure signing of certificates, which have a certificate signing subsystem set up in a device of a controlled management site, unless authorized externally, internal data of the subsystem cannot be accessed arbitrarily, and each unit applying for a certificate needs confirmation of identity to increase the security of certificate application and signing. In addition, the certificate signing subsystem is a device with arithmetic capability, which operates fast and can increase the efficiency of certificate signing. Because units or companies applying for certificates do not need to set up a certificate signing system by themselves, provided that they are connected to the certificate signing subsystem of the present invention, certificates can be applied for and obtained, thereby saving business operating costs.