Untrusted Root Certificate Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing certificate-based authentication methods, particularly those relying on a hierarchical structure and traditional certificate authorities, are inefficient and costly for entities and users, as they require extensive resources and time to configure and scale, especially when dealing with untrusted root certificates.

Innovation Solution

The system allows a client to establish a secure connection with a server using a certificate that does not chain up to a trusted root certificate authority, enabling the association of an untrusted client certificate with an existing account, and storing the client certificate and private key in integrated circuit cards or computer-readable media, facilitating authentication without a traditional hierarchy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional certificate authority hierarchy is used for authentication, then security is improved, but device complexity and configuration time increase

Engineering Contradiction:
Improveauthentication securityVSAvoidcertificate hierarchy structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the root certificate authority verification step from the authentication process. Instead of requiring certificates to chain up to a trusted root CA, the system allows direct registration of client certificates with the server without root verification, thereby simplifying the certificate structure while maintaining security through direct server-side validation

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The server acts as an intermediary that directly registers and validates client certificates without requiring a certificate authority hierarchy. The server stores and verifies client certificates directly, eliminating the need for intermediate CAs and root certificates in the authentication chain

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional certificate authority hierarchy is used for authentication, then authentication security is improved, but loss of time and configuration resources increase

Engineering Contradiction:
Improveauthentication securityVSAvoidcertificate configuration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary registration of client certificates directly with the server before authentication occurs. Client certificates are pre-registered and stored in the server's database, so that during actual authentication, the server can directly verify the certificate against its stored records without time-consuming hierarchy validation

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent removes the time-consuming root certificate verification and hierarchy chain validation steps from the authentication process, retaining only the essential certificate verification against server-stored records, thereby significantly reducing configuration and authentication time

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If traditional certificate authority hierarchy is used for authentication, then security is improved, but productivity and scalability decrease

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication scalability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system enables self-service certificate registration where clients can directly register their certificates with the server without requiring enrollment through a certificate authority hierarchy. This eliminates bottlenecks in the certificate issuance process and allows direct, scalable authentication

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent extracts and eliminates the certificate authority enrollment infrastructure from the authentication system, allowing direct client-server certificate validation. This removes the scalability limitations imposed by CA hierarchy management and enables more flexible, high-volume authentication

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS8924714B2Authentication with an untrusted root
Publication Date: 2014.12.30 ZHIGU HLDG
  • US8924714B2 patent drawing
  • US8924714B2 patent drawing
  • US8924714B2 patent drawing

AI summary

Techniques and systems for authentication with an untrusted root between a client and a server are disclosed. In some aspects, a client may connect to a server. The server and client may initiate a secure connection by exchanging certificates. The server may accept a client certificate having an untrusted root that does not chain up to a root certificate verifiable to the server certificate authority. In further aspects, the server may enable the client to associate an untrusted certificate with an existing account associated with the server. The client certificate may be hardware based or generated in software, and may be issued to the client independent of interactions with the server.