Trust Advising Service for Certificate Authority Evaluation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The certificating authority system is vulnerable to exploitation due to flaws in mathematical models, lack of uniform security practices, and difficulty in detecting malicious activities, particularly in decentralized environments where certificating authorities may issue inauthentic certificates and withhold relevant information.

Innovation Solution

A collective model for gathering, evaluating, and disseminating trust information about certificating authorities and certificates using a trust advising service that collects certificates from various users and devices, evaluates them using heuristics, and generates a trust set indicating the trustworthiness of certificating authorities, which is then disseminated to devices for evaluating subsequent certificates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a decentralized certificating authority system is used to issue certificates for various domains, then the versatility and accessibility of certificate issuance is improved, but the reliability and security of the certificate system deteriorates due to potential exploitation and malicious actions by individual CAs

Engineering Contradiction:
Improvecertificate issuance accessibilityVSAvoidcertificate authenticity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a trust advising service as an intermediary between relying parties and certificating authorities. This service collects certificate data from multiple sources, evaluates trust levels using heuristics and collective information, and provides guidance to relying parties. The intermediary resolves the contradiction by enabling versatile certificate issuance while maintaining reliability through centralized trust evaluation and warning mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If individual devices evaluate certificates independently without collective information sharing, then the ease of operation is improved, but the difficulty of detecting and measuring malicious activities increases

Engineering Contradiction:
Improveindependent certificate evaluationVSAvoidmalicious activity detection
Core Design Contradiction:
Ease of operationVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements a feedback mechanism where the trust advising service collects certificate evaluation data from multiple devices, analyzes patterns using heuristics, and disseminates trust level information back to relying parties. This collective feedback loop enables individual devices to maintain operational simplicity while significantly improving malicious activity detection through aggregated intelligence and pattern recognition across the distributed system.

Inventive Principle:
Principle #23Feedback

3Ease of operation

If certificating authorities withhold relevant information about issued certificates and security techniques, then the ease of operation for individual CAs is improved, but the reliability of the overall certificate system deteriorates

Engineering Contradiction:
ImproveCA information managementVSAvoidsystem transparency
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the trust evaluation function from the certificating authority system itself and places it in a separate trust advising service. This service collects and analyzes certificate data that CAs may withhold, evaluating trust levels independently using heuristics and collective information from multiple sources. By separating the evaluation function, the patent enables CAs to maintain operational simplicity while ensuring system reliability through independent, transparent trust assessment.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP3005641B1Certificating authority trust evaluation
Publication Date: 2019.10.23 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP3005641B1 patent drawingFigure 1
  • EP3005641B1 patent drawingFigure 2
  • EP3005641B1 patent drawingFigure 3

AI summary

In many information security scenarios, a certificate issued by a certificating authority may be presented to a client in order to assert a trust level of a certificated item, such as a message or a web page. However, due to a decentralized structure and incomplete coordination among certificating authorities, the presence and exploitation of security vulnerabilities to issue untrustworthy certificates may be difficult to determine, particularly for an individual client. Presented herein are techniques for providing a certificating authority trust service that collects and evaluates certificates submitted to clients by certificating authorities, and advises the clients of a certificating authority trust level for respective certificating authorities (e.g., determined as a consensus of the evaluated certificates issued by the certificating authority). The clients may use a certificating authority trust set distributed by the certificating authority trust service to determine whether to trust a certificate issued from a particular certificating authority.