Multi-System Trust Chain via Intermediate Nonce Signing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Establishing an end-to-end trust chain between OT and IT systems is challenging due to midstream security controls that break encryption, leading to confidentiality and integrity issues, and existing solutions introduce throughput bottlenecks and require secret sharing.

Innovation Solution

A three-way handshake method is introduced, where a trusted intermediate system signs and verifies a nonce between the client and remote service, maintaining end-to-end encryption and establishing a multi-system trust chain without breaking encryption, using a signature service to authenticate and attest trust anchors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If midstream security controls break encryption for content inspection, then security inspection capability is improved, but end-to-end confidentiality and integrity are compromised

Engineering Contradiction:
Improvesecurity inspection capabilityVSAvoidconfidentiality and integrity
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces a trust anchor as an intermediary component that enables security inspection without breaking end-to-end encryption. The trust anchor establishes a chain of trust through cryptographic signatures, allowing intermediate systems to verify data integrity and authenticate sources while the encryption remains intact for unauthorized parties. This mediator approach resolves the contradiction by enabling inspection capability through trust verification rather than encryption breaking.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a trust anchor is provided at the midstream security control, then end-to-end trust is reestablished, but throughput and scalability are reduced due to session level decryption and encryption

Engineering Contradiction:
Improveend-to-end trustVSAvoidthroughput and scalability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies preliminary action by establishing trust relationships and cryptographic signatures during initial session setup, rather than performing decryption and re-encryption at each intermediate point during data transmission. The trust anchor performs authentication and signature verification based on pre-established trust chains, eliminating the need for repeated cryptographic operations on every data packet. This preliminary establishment of trust maintains both reliability and high throughput.

Inventive Principle:
Principle #10Preliminary action

3Loss of information

If client applications encrypt data exchanges using trust anchor, then confidentiality and integrity are preserved, but content inspection and anomaly detection at intermediate devices become challenging

Engineering Contradiction:
Improveconfidentiality and integrityVSAvoidcontent inspection capability
Core Design Contradiction:
Loss of informationVSReliability

Solution Approach 1:

The patent segments the security verification function from the data encryption function. The trust anchor provides a separate verification layer that operates independently from the encrypted data channel. Intermediate inspection devices can verify cryptographic signatures and trust chain validity without needing to decrypt the actual data content. This segmentation allows confidentiality to be maintained while enabling integrity verification and anomaly detection through signature validation.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11818108B2System and method for a multi system trust chain
Publication Date: 2023.11.14 DIGICERT INC
  • US11818108B2 patent drawing
  • US11818108B2 patent drawing
  • US11818108B2 patent drawing

AI summary

A trust chain having client system and a remote system in a secure connection, wherein an intermediary system associated with the network flow path serves as a signing entity to establish an end to end transitive trust. The intermediate system is a corroborative entity in the operations technology realm of the client system. The remote system serves as the host for a plurality of services in the information technology realm. A two way handshake during the initial secure exchange protocol between a local client application and a remote service is extended to a three way handshake that includes a nonce issued by the remote service on the remote system and a digital signature for the nonce issued by a signature service on an associated intermediate system. The nonce signature is verified authoritatively at the remote system based on the signing certificate of the intermediate system for explicit proof of association.