Token-Based Certificate Issuance for Supply Chain Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Public Key Infrastructure (PKI) systems in manufacturing supply chains face challenges when a Certificate Authority (CA) is compromised, leading to the invalidation of millions of legitimate devices, as existing solutions often require revoking all digital certificates signed by the CA, even for devices manufactured before the compromise.

Innovation Solution

Implementing a token-based system that constrains certificate issuance with a monotonically increasing sequence number, allowing secure identification and revocation of specific ranges of devices, using a smart card or hardware security module with policy logic to limit certificate issuance and provide auditable records, and linking the token to a manufacturing station to prevent unauthorized signing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the CA certificate is revoked to prevent unauthorized device operation, then security is improved, but a large number of legitimate devices are invalidated

Engineering Contradiction:
ImprovesecurityVSAvoidnumber of valid devices
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent segments the device population into groups based on their certificate issuance time and sequence numbers. By introducing sequence numbers and time-based constraints in certificate issuance, the system can identify and revoke only devices issued during compromised periods, rather than revoking all certificates from a CA. This segmentation allows precise targeting of unauthorized devices while preserving legitimate ones.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary actions by embedding sequence numbers and time constraints directly into the certificate issuance process before compromise occurs. The token-based system pre-establishes issuance limits and sequence tracking, so that when compromise is detected, the system already has the data needed to identify exactly which devices were issued during the compromised period, enabling targeted revocation without affecting pre-issue legitimate devices.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If all certificates signed by a compromised CA are revoked, then unauthorized devices are blocked, but replacement costs increase

Engineering Contradiction:
Improveunauthorized device blockingVSAvoidreplacement cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

By segmenting devices into legitimate and unauthorized groups based on issuance sequence numbers and time constraints, the system enables selective revocation. This means only the segmented group of unauthorized devices needs replacement, not the entire device population, significantly reducing replacement costs while maintaining security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements feedback mechanisms through sequence number tracking and issuance limit monitoring. The token-based system continuously tracks the number of certificates issued and compares them against authorized limits. When compromise is detected, this feedback data enables precise identification of unauthorized devices, allowing targeted replacement only where necessary, thereby reducing overall replacement costs.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If a token-based system with sequence numbers is implemented, then device identification precision is improved, but system complexity increases

Engineering Contradiction:
Improvedevice identification precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces a token-based intermediary between the CA and device issuance. This token carries sequence numbers and issuance constraints, acting as a mediator that simplifies the overall system architecture. Instead of complex centralized tracking, the token distributes the necessary identification data to manufacturing stations, enabling precise device identification without requiring complex system-wide coordination mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent uses sequence numbers as a form of copying information about issuance history. Rather than maintaining complex records of all issued certificates, the system copies only the essential sequence number information into each token and certificate. This copying approach enables precise identification of unauthorized devices while significantly reducing the complexity of tracking and management systems.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS9542713B2Systems and methods for securing the manufacturing supply chain
Publication Date: 2017.01.10 ITRON NETWORKED SOLUTIONS INC
  • US9542713B2 patent drawing
  • US9542713B2 patent drawing
  • US9542713B2 patent drawing

AI summary

Securing the manufacturing supply chain with digital certificates. A token is coupled to a manufacturing station and enabled via a personal identification number. The token includes a counter limiting the maximum number of certificates to be signed, and compares a serial number of a digital certificate to a tracked serial number. In some embodiments, the token is linked to a particular manufacturing station once the token is enabled.