Embedding Symmetric Secrets in Digital Certificates for Scalable Revocation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing digital certificate systems struggle to efficiently revoke authorization for devices using symmetric cryptographic secrets, as standard revocation mechanisms are not directly applicable to systems based on asymmetric algorithms.
Innovation Solution
A method and apparatus that embed a cryptographic function of a secret within a digital certificate, allowing for the use of standard certificate revocation mechanisms in systems with symmetric keys by generating a leaf digital certificate with a unique identifier and a two-way or one-way cryptographic function, enabling scalable and error-prone revocation of devices through sub-CA certificate revocation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If standard digital certificate revocation mechanisms are used for asymmetric cryptographic systems, then revocation efficiency is improved through Sub-CA grouping, but these mechanisms cannot be directly applied to symmetric cryptographic systems
Solution Approach 1:
The patent applies universality by making digital certificates applicable to both asymmetric and symmetric cryptographic systems. By embedding symmetric cryptographic secrets directly in certificates and using cryptographic functions (hashing or encryption) of these secrets, the invention enables standard certificate-based revocation mechanisms to work with symmetric cryptography, allowing one certificate structure to serve multiple cryptographic paradigms.
Solution Approach 2:
The patent applies parameter changes by transforming how secrets are represented in certificates. Instead of using public-private key pairs as in traditional asymmetric systems, the invention embeds symmetric secrets and uses cryptographic functions (changing the parameter from raw secret to hashed/encrypted form) of these secrets, enabling compatibility with standard certificate infrastructure while maintaining symmetric cryptography benefits.
2Reliability
If individual device authorization is revoked in symmetric cryptographic systems, then security is improved, but the process becomes complex and error-prone compared to Sub-CA revocation
Solution Approach 1:
The patent applies merging by combining multiple devices into certificate groups issued by Sub-CAs, similar to asymmetric systems. By embedding Sub-CA identifiers in certificates and enabling revocation at the Sub-CA level rather than individual device level, the invention reduces operational complexity while maintaining security through grouped authorization management.
Solution Approach 2:
The invention enables Sub-CA level revocation in symmetric systems, making the revocation mechanism as efficient as in asymmetric systems. This universal approach allows operators to revoke entire groups of devices by revoking a single Sub-CA certificate, eliminating the need for manual individual device revocation and reducing operational complexity.
3Device complexity
If symmetric cryptographic secrets are used in devices, then device simplicity is improved, but standard certificate revocation mechanisms cannot be applied
Solution Approach 1:
The patent makes symmetric cryptographic systems compatible with standard certificate infrastructure by embedding secrets in certificates and using cryptographic functions of these secrets. This allows simple symmetric cryptography in devices to work with universal certificate-based authentication and revocation mechanisms, enabling devices to participate in standard PKI ecosystems without requiring complex asymmetric cryptography.
Solution Approach 2:
The invention introduces cryptographic functions (hashing or encryption) as intermediaries between symmetric secrets and certificate verification. These functions transform device secrets into forms that can be verified by standard certificate infrastructure, acting as a mediator that enables compatibility between simple symmetric device cryptography and complex standard certificate systems.
Data Source
AI summary
A method and system is provided for embedding cryptographically modified versions of secret in digital certificates for use in authenticating devices and in providing services subject to conditional access conditions.


