Software Integrity Verification via Multi-CA Certificate Switching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing software verification systems are disrupted when a certificate authority (CA) of a software vendor cannot issue or maintain digital certificates, leading to interruptions in software verification services, compromising software integrity and security.

Innovation Solution

A method that reads flag information to select between multiple digital certificates, including those issued by a software vendor CA and a user or third-party CA, using cryptographic resources to verify software integrity, ensuring continuity of verification services even if the primary CA is unavailable.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single digital certificate from a software vendor CA is used for software verification, then verification security is maintained, but verification service continuity is compromised when the CA becomes unavailable

Engineering Contradiction:
Improveverification service continuityVSAvoidcertificate management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the verification service by introducing multiple independent digital certificates from different CAs (vendor CA, user CA, third-party CA) instead of relying on a single certificate. This segmentation ensures that if one CA becomes unavailable, other certificates can still provide verification services, thus improving continuity while maintaining manageable complexity through modular certificate storage and selection mechanisms

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the parameter of certificate authority diversity by allowing the system to switch between certificates issued by different CAs based on availability. The device can dynamically select which CA's certificate to use for verification, transforming a static single-certificate approach into a dynamic multi-certificate system that adapts to CA availability status

Inventive Principle:
Principle #35Parameter changes

2Reliability

If multiple digital certificates from different CAs are stored and managed, then verification service continuity is improved, but system complexity increases

Engineering Contradiction:
Improveverification service continuityVSAvoidcertificate selection and verification process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies preliminary action by pre-storing multiple digital certificates from different CAs in the device before verification needs arise. The system prepares multiple verification options in advance, so when verification is needed, the device can immediately select from available certificates without complex real-time decision-making, simplifying the operational process while ensuring continuity

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements self-service by enabling the device to autonomously select and use appropriate digital certificates for verification without requiring external intervention or complex user input. The system automatically manages the certificate selection process based on predefined criteria and CA availability, making the multi-certificate system as easy to operate as a single-certificate system

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12056260B2Method for protecting device software integrity in continuity scenario
Publication Date: 2024.08.06 HUAWEI TECH CO LTD
  • US12056260B2 patent drawing
  • US12056260B2 patent drawing
  • US12056260B2 patent drawing

AI summary

A software verification method and apparatus are provided. The method includes: reading flag information, where the flag information is used to indicate a target digital certificate; selecting one of a plurality of digital certificates as a target digital certificate based on the flag information, where the plurality of digital certificates include a first digital certificate and a second digital certificate, and the target digital certificate includes a cryptographic resource; and verifying software deployed on a device based on the cryptographic resource. Using the foregoing technical solution can ensure continuity of the software verification service in the device.