Security Chip Self-Signed Certificate Issuance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The intervention of a Certificate Authority (CA) in public key infrastructure (PKI) systems increases costs and poses a risk of exposing private keys, which are stored on devices.

Innovation Solution

A security chip is designed to perform PKI communications without a CA, by generating and managing digital signatures using a stored CA private key, allowing devices to securely issue certificates and perform security protocols, reducing the risk of private key exposure and eliminating the need for a separate CA.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a Certificate Authority (CA) is introduced in PKI systems, then certificate issuance and verification can be standardized, but costs increase and private key exposure risk increases

Engineering Contradiction:
Improvecertificate verification reliabilityVSAvoidprivate key exposure risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the CA private key from the traditional external CA system and stores it locally within the security chip. This allows the device to autonomously generate digital signatures for its own certificate without requiring interaction with an external CA, thereby eliminating the risk of private key exposure through transmission or storage on external servers while maintaining certificate verification reliability

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The device performs self-certification by using its own stored CA private key to generate digital signatures on its certificate. The security chip autonomously completes the certificate issuance process without requiring external CA intervention, reducing costs and eliminating dependencies on external CA infrastructure while maintaining security standards

Inventive Principle:
Principle #25Self-service

2Ease of manufacture

If a separate CA is used for certificate issuance, then certificate authority functions are centralized, but system costs increase

Engineering Contradiction:
Improvecertificate issuance standardizationVSAvoidsystem cost
Core Design Contradiction:
Ease of manufactureVSQuantity of substance

Solution Approach 1:

Each device equipped with the security chip can independently issue its own certificate by using the stored CA private key. This eliminates the need for centralized CA infrastructure, reducing system costs while maintaining standardized certificate issuance through consistent cryptographic operations and protocol implementation

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The security chip serves multiple functions: it acts as both a certificate holder and a self-signed CA. By integrating the CA private key storage and digital signature generation capabilities within the same chip that stores device credentials, the system eliminates the need for separate CA infrastructure while maintaining standardized certificate issuance

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10263961B2Security chip and application processor
Publication Date: 2019.04.16 SAMSUNG ELECTRONICS CO LTD
  • US10263961B2 patent drawing
  • US10263961B2 patent drawing
  • US10263961B2 patent drawing

AI summary

A security chip and an application processor may be included in a device configured to engage in encrypted communications with an external client, including public key infrastructure communications, in an environment where a certificate authority is absent. The security chip may provide the application processor with a device public key from among a pair of device keys related to public key infrastructure communications, receive a request from the application processor to generate a digital signature on a certificate form including the device public key, provide the application processor with a digital signature generated based on an encryption operation using a certificate authority private key, and receive and store a certificate including the digital signature from the application processor.