Security Assurance Attributes in Mobile Certificates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Service providers face challenges in determining the security assurance level of client processes, as simply validating certificates is insufficient, especially when specialized hardware processors are involved, necessitating additional security information to assess the confidence level for secure services.

Innovation Solution

Incorporating security assurance information into certificates, which includes attributes such as UE security, key generation, and key access, allowing service providers to assess the security mechanisms and determine the confidence level, with a communication system involving a registration authority and certificate authority to generate and sign certificates with these attributes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If service providers only validate certificates, then the authentication process is simple and fast, but they cannot determine the security assurance level of client processes

Engineering Contradiction:
Improvesecurity assurance level determinationVSAvoidcertificate validation process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by incorporating security assurance information into certificates during the certificate issuance process. The certificate authority collects security information from the client process beforehand and embeds it in the certificate, so that service providers can directly use this pre-packaged information without needing to conduct separate security assessments.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses the certificate as an intermediary that carries security assurance information from the client process to the service provider. Instead of direct communication between the client and service provider about security levels, the certificate acts as a mediator that encapsulates and transports the necessary security information.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If service providers conduct comprehensive security assessments, then they can determine security assurance levels accurately, but the authentication process becomes time-consuming and complex

Engineering Contradiction:
Improvesecurity level assessment accuracyVSAvoidauthentication time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

Security assessments are performed in advance during certificate issuance rather than at authentication time. The certificate authority evaluates the client process's security mechanisms beforehand and records the results in the certificate, eliminating the need for repeated assessments during authentication.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The client process self-declares its security assurance information to the certificate authority, which then verifies and incorporates it into the certificate. This self-service approach reduces the burden on service providers and accelerates the authentication process.

Inventive Principle:
Principle #25Self-service

3Reliability

If certificates include detailed security assurance information, then service providers can make informed security decisions, but the certificate structure becomes more complex

Engineering Contradiction:
Improvesecurity decision accuracyVSAvoidcertificate structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments security assurance information into distinct attributes within the certificate structure, such as security level indicators, hardware security characteristics, and software security features. This segmentation allows for organized storage and selective use of different security information types without creating a monolithic complex structure.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP3163490B1Providing security assurance information
Publication Date: 2019.06.05 BLACKBERRY LTD
  • EP3163490B1 patent drawingFigure 1~2
  • EP3163490B1 patent drawingFigure 3

AI summary

Systems, methods, and software can be used to provide security assurance information. In some aspects, a certificate request for a client process on a mobile device is received. A security assurance character for the client process is determined. Whether to grant the certificate request is determined based on the determined security assurance character. In response to determining to grant the certificate request, a certificate is generated.