Embedding Symmetric Secrets in Digital Certificates for Scalable Revocation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing digital certificate systems struggle to efficiently revoke authorization for devices using symmetric cryptographic secrets, as standard revocation mechanisms are not directly applicable to systems based on asymmetric algorithms.

Innovation Solution

A method and apparatus that embed a cryptographic function of a secret within a digital certificate, allowing for the use of standard certificate revocation mechanisms in systems with symmetric keys by generating a leaf digital certificate with a unique identifier and a two-way or one-way cryptographic function, enabling scalable and error-prone revocation of devices through sub-CA certificate revocation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If standard digital certificate revocation mechanisms are used for asymmetric cryptographic systems, then revocation efficiency is improved through Sub-CA grouping, but these mechanisms cannot be directly applied to symmetric cryptographic systems

Engineering Contradiction:
Improverevocation efficiencyVSAvoidapplicability to symmetric cryptographic systems
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent applies universality by making digital certificates applicable to both asymmetric and symmetric cryptographic systems. By embedding symmetric cryptographic secrets directly in certificates and using cryptographic functions (hashing or encryption) of these secrets, the invention enables standard certificate-based revocation mechanisms to work with symmetric cryptography, allowing one certificate structure to serve multiple cryptographic paradigms.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent applies parameter changes by transforming how secrets are represented in certificates. Instead of using public-private key pairs as in traditional asymmetric systems, the invention embeds symmetric secrets and uses cryptographic functions (changing the parameter from raw secret to hashed/encrypted form) of these secrets, enabling compatibility with standard certificate infrastructure while maintaining symmetric cryptography benefits.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If individual device authorization is revoked in symmetric cryptographic systems, then security is improved, but the process becomes complex and error-prone compared to Sub-CA revocation

Engineering Contradiction:
ImprovesecurityVSAvoidrevocation process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies merging by combining multiple devices into certificate groups issued by Sub-CAs, similar to asymmetric systems. By embedding Sub-CA identifiers in certificates and enabling revocation at the Sub-CA level rather than individual device level, the invention reduces operational complexity while maintaining security through grouped authorization management.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The invention enables Sub-CA level revocation in symmetric systems, making the revocation mechanism as efficient as in asymmetric systems. This universal approach allows operators to revoke entire groups of devices by revoking a single Sub-CA certificate, eliminating the need for manual individual device revocation and reducing operational complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Device complexity

If symmetric cryptographic secrets are used in devices, then device simplicity is improved, but standard certificate revocation mechanisms cannot be applied

Engineering Contradiction:
Improvedevice simplicityVSAvoidcompatibility with standard certificate systems
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent makes symmetric cryptographic systems compatible with standard certificate infrastructure by embedding secrets in certificates and using cryptographic functions of these secrets. This allows simple symmetric cryptography in devices to work with universal certificate-based authentication and revocation mechanisms, enabling devices to participate in standard PKI ecosystems without requiring complex asymmetric cryptography.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The invention introduces cryptographic functions (hashing or encryption) as intermediaries between symmetric secrets and certificate verification. These functions transform device secrets into forms that can be verified by standard certificate infrastructure, acting as a mediator that enables compatibility between simple symmetric device cryptography and complex standard certificate systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9912485B2Method and apparatus for embedding secret information in digital certificates
Publication Date: 2018.03.06 ARRIS INC
  • US9912485B2 patent drawing
  • US9912485B2 patent drawing
  • US9912485B2 patent drawing

AI summary

A method and system is provided for embedding cryptographically modified versions of secret in digital certificates for use in authenticating devices and in providing services subject to conditional access conditions.