Trust Management in Electronic Environments

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In shared-resource environments, the lack of real-time information for verifying digital certificate requests can lead to security vulnerabilities or delayed resource availability, as existing methods either blindly trust machines or wait for complete information, which is impractical for scalable deployments.

Innovation Solution

A two-part decision process involving a rationalization procedure and a justification procedure to determine whether to grant a signed digital certificate, using available information to assess trustworthiness and scoring against a threshold, and later verifying the decision with complete information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the system waits for complete verification information before issuing digital certificates, then security is improved, but resource availability and deployment speed deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoidresource availability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the certificate issuance process into two distinct phases: a rationalization phase that makes initial trust decisions with available information, and a justification phase that completes verification when full information becomes available. This segmentation allows the system to issue certificates promptly while maintaining security through subsequent validation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies preliminary action by performing the rationalization procedure in advance, making initial trust decisions before complete verification information is available. This allows resources to be allocated and certificates issued promptly, with the justification procedure serving as a subsequent validation step.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If the system blindly trusts machines without verification, then resource availability is improved, but security vulnerabilities increase

Engineering Contradiction:
Improveresource availabilityVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent divides the trust decision process into two stages: rationalization (initial decision with available information) and justification (subsequent validation when complete information is available). This prevents blind trust while enabling timely resource allocation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary verification mechanism that processes available information to make initial trust decisions, then uses complete verification information to justify those decisions. This intermediary layer prevents both blind trust and unnecessary delays.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If complete verification information is required before certificate issuance, then security is improved, but deployment time increases

Engineering Contradiction:
ImprovesecurityVSAvoiddeployment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary rationalization using available information to make initial trust decisions and issue certificates promptly. The complete verification information is then used in a subsequent justification phase, eliminating deployment delays while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent makes the verification process dynamic by adapting the level of verification based on information availability. When information is limited, rationalization provides timely decisions; when complete information is available, justification provides enhanced validation, optimizing both speed and security.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10447682B1Trust management in an electronic environment
Publication Date: 2019.10.15 AMAZON TECH INC
  • US10447682B1 patent drawing
  • US10447682B1 patent drawing
  • US10447682B1 patent drawing

AI summary

A new machine being initiated for a deployment can attempt to authenticate itself using a signed certificate, and a decision is made whether to trust the machine and issue the signed certificate. Since not all information may be readily available, a rationalization procedure can utilize the available information, as may be associated with a certificate signing request, determine to whether to trust the machine and issue the signed certificate. When the source of truth data subsequently becomes available, a justification process can use that data to determine whether the machine should be trusted and the decision to sign the certificate was proper. If the machine should not be trusted, the certificate can be revoked and the machine terminated.