Self-Signed Certificate Exchange for Secure Device Pairing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems for establishing trust relationships between communication devices are limited by the inability to readily transfer or create new secure relationships using root certificates, which are often pre-installed and not user-manageable, and lack flexibility in establishing secure connections between devices.
Innovation Solution
A method and system for sending a self-signed certificate from one communication device to another, allowing for the establishment of a trust relationship by broadcasting presence, displaying certificate hashes, and enabling secure sessions over short-range or direct communication channels using protocols like LTE, facilitating secure communication and certificate exchange.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If root certificates are pre-installed in operating systems or pushed through auto-updates, then trust relationships are established automatically, but users cannot readily transfer or create new secure relationships
Solution Approach 1:
The system enables devices to automatically generate, exchange, and verify self-signed certificates without requiring manual user intervention or complex installation procedures. The certificate exchange happens autonomously through the communication protocol, allowing devices to establish trust relationships independently
Solution Approach 2:
The patent divides the certificate exchange process into distinct phases: certificate generation, certificate transmission through communication channels, and certificate verification. This segmentation allows each component to be optimized independently and simplifies the overall process
2Adaptability or versatility
If root certificates are pre-installed and not user-manageable, then system security is maintained, but flexibility in establishing secure connections between devices is limited
Solution Approach 1:
The system dynamically generates and exchanges certificates based on the specific communication session requirements rather than using static pre-installed certificates. This allows the trust relationship to be established on-demand for each device pair while maintaining security through cryptographic verification
Solution Approach 2:
The patent introduces communication channels as intermediaries that facilitate the certificate exchange process. These channels provide a secure pathway for transmitting certificates between devices, enabling flexible connection establishment without direct manual intervention
3Productivity
If conventional certificate systems are used, then existing security protocols are maintained, but devices cannot readily create new or temporary secure relationships
Solution Approach 1:
The system performs preliminary actions by pre-generating certificates and pre-configuring communication channels before the actual secure connection is needed. This allows for rapid establishment of secure relationships when devices need to communicate, as the certificate exchange process is already prepared and optimized
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method of sending a self-signed certificate from a communication device (201), the self-signed certificate being signed by the communication device (201). The method includes: receiving a communication in relation to establishing a session from a second communication device (302) in proximity to said communication device (201), outputting on an output device of said communication device (201) a certificate hash of the self-signed certificate or an address of where to obtain the certificate hash, and sending the self-signed certificate to said second communication device (302). The method may also include sending a broadcast message to announce a presence of the communication device (201).