Trust Model Disseminator for SSL Certificate Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing SSL trust models fail to effectively communicate trust models to relying parties, leaving users unaware of the trust model in use and vulnerable to compromised certificates, as the decision on trust validation is solely in the user's hands, regardless of their experience level.

Innovation Solution

A method is introduced to communicate trust models by using a disseminator component that provides trust model identifiers outside the SSL certificate trust path, allowing relying parties to validate certificates based on defined trust models, with secure communication and optional use of DNSsec for infrastructure leverage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If traditional SSL trust models are used, then certificate validation is simple, but relying parties cannot communicate their chosen trust model to users, leaving users unaware of the trust model in use

Engineering Contradiction:
Improvetrust model informationVSAvoidtrust model communication system
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent introduces a disseminator component as an intermediary that communicates trust model information from the server to the relying party. This mediator enables the server to convey its chosen trust model (traditional, multiple notaries, or monitored changes) to users without requiring direct complex interactions between the server and user, thus resolving the information loss problem while maintaining acceptable system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the trust model communication into distinct components: the server that selects the trust model, the disseminator that communicates it, and the relying party that receives and applies it. This segmentation allows each component to perform its function independently, making the overall system more manageable while ensuring complete trust model information is transmitted to users.

Inventive Principle:
Principle #1Segmentation

2Reliability

If multiple notaries are required to validate SSL servers, then trust validation is more robust, but the system complexity increases and existing users may ignore warnings

Engineering Contradiction:
Improvetrust validationVSAvoiduser interaction
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements feedback mechanisms where the disseminator communicates trust model decisions to the relying party, and the system monitors user behavior. When users ignore warnings or exhibit behavior indicating distrust, the system can adapt by enhancing notifications or involving multiple notaries, thus maintaining reliability while adjusting to user operational patterns.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The trust validation system is made dynamic by allowing it to adapt based on user behavior and trust model configuration. The system can switch between different validation approaches (single notary vs. multiple notaries) based on real-time conditions, making the process more robust when needed while maintaining simplicity during normal operation.

Inventive Principle:
Principle #15Dynamics

3Ease of operation

If certificate trust warnings are left to user control, then system simplicity is maintained, but less experienced users cannot make informed trust decisions

Engineering Contradiction:
Improveuser controlVSAvoidtrust decision quality
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The disseminator component acts as an intermediary that provides trust model information to users in a standardized format. This mediator ensures that even less experienced users receive clear, consistent information about the trust model being used, improving trust decision quality without requiring users to directly manage complex trust validation processes.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system changes the parameters of trust communication by providing detailed trust model information (such as which CAs are trusted, what monitoring is in place) in a standardized manner. This allows users to make more informed decisions based on concrete parameter information rather than abstract warnings, improving reliability while maintaining ease of operation.

Inventive Principle:
Principle #35Parameter changes

4Loss of information

If SSL certificates contain markers to inform relying parties of trust models, then trust model communication is enabled, but attackers can replace certificates with compromised CA certificates

Engineering Contradiction:
Improvetrust model communicationVSAvoidcertificate substitution attacks
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The patent segments the trust model communication from the SSL certificate itself by using a separate disseminator component. This segmentation ensures that trust model information is conveyed through a distinct channel that is not part of the certificate validation path, making it difficult for attackers to substitute certificates while maintaining trust model communication.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The disseminator serves as an intermediary that communicates trust model information independently of the certificate chain. This mediator ensures that even if an attacker manages to substitute a certificate, the trust model information remains separate and can still be verified through the disseminator, preventing the attack from succeeding.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9043592B1Communicating trust models to relying parties
Publication Date: 2015.05.26 EMC IP HLDG CO LLC
  • US9043592B1 patent drawing
  • US9043592B1 patent drawing
  • US9043592B1 patent drawing

AI summary

Methods, apparatus and articles of manufacture for communicating trust models to relying parties are provided herein. A method includes receiving a first item of cryptographic information from a first entity, wherein said first item of cryptographic information is derived from a second item of cryptographic information provided by an authentication source; receiving a request for access to the first item of cryptographic information from a second entity, wherein the request comprises the second item of cryptographic information; and providing identification information associated with the first item of cryptographic information to the second entity in response to said request.