Self-Signed Certificate Exchange for Secure Device Pairing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems for establishing trust relationships between communication devices are limited by the inability to readily transfer or create new secure relationships using root certificates, which are often pre-installed and not user-manageable, and lack flexibility in establishing secure connections between devices.

Innovation Solution

A method and system for sending a self-signed certificate from one communication device to another, allowing for the establishment of a trust relationship by broadcasting presence, displaying certificate hashes, and enabling secure sessions over short-range or direct communication channels using protocols like LTE, facilitating secure communication and certificate exchange.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If root certificates are pre-installed in operating systems or pushed through auto-updates, then trust relationships are established automatically, but users cannot readily transfer or create new secure relationships

Engineering Contradiction:
ImproveUser ability to transfer certificatesVSAvoidCertificate installation complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system enables devices to automatically generate, exchange, and verify self-signed certificates without requiring manual user intervention or complex installation procedures. The certificate exchange happens autonomously through the communication protocol, allowing devices to establish trust relationships independently

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent divides the certificate exchange process into distinct phases: certificate generation, certificate transmission through communication channels, and certificate verification. This segmentation allows each component to be optimized independently and simplifies the overall process

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If root certificates are pre-installed and not user-manageable, then system security is maintained, but flexibility in establishing secure connections between devices is limited

Engineering Contradiction:
ImproveFlexibility in establishing secure connectionsVSAvoidSystem security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system dynamically generates and exchanges certificates based on the specific communication session requirements rather than using static pre-installed certificates. This allows the trust relationship to be established on-demand for each device pair while maintaining security through cryptographic verification

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces communication channels as intermediaries that facilitate the certificate exchange process. These channels provide a secure pathway for transmitting certificates between devices, enabling flexible connection establishment without direct manual intervention

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If conventional certificate systems are used, then existing security protocols are maintained, but devices cannot readily create new or temporary secure relationships

Engineering Contradiction:
ImproveSpeed of secure relationship establishmentVSAvoidCertificate transfer ease
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The system performs preliminary actions by pre-generating certificates and pre-configuring communication channels before the actual secure connection is needed. This allows for rapid establishment of secure relationships when devices need to communicate, as the certificate exchange process is already prepared and optimized

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2600274B1Method Of Sending A Self-Signed Certificate From A Communication Device
Publication Date: 2019.04.24 BLACKBERRY LTD
  • EP2600274B1 patent drawingFigure 1
  • EP2600274B1 patent drawingFigure 2
  • EP2600274B1 patent drawingFigure 3

AI summary

A method of sending a self-signed certificate from a communication device (201), the self-signed certificate being signed by the communication device (201). The method includes: receiving a communication in relation to establishing a session from a second communication device (302) in proximity to said communication device (201), outputting on an output device of said communication device (201) a certificate hash of the self-signed certificate or an address of where to obtain the certificate hash, and sending the self-signed certificate to said second communication device (302). The method may also include sending a broadcast message to announce a presence of the communication device (201).