Web Email PKI Account Creation via Local Key Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Web-based Email Systems complicate the process of creating PKI Email Accounts and managing digital keys, potentially compromising security due to the need for multiple steps involving Certificate Authorities and Internet key transmission.

Innovation Solution

A coordinated system between a Certificate Authority and a Web-based Email System simplifies the creation of PKI Email Accounts, utilizing a Keystore System for enhanced digital key management, including signing, encryption, and decryption, and allowing access via a Computer Network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional protocols (S/MIME, PGP, OpenPGP, PEM, MOSS) are used to protect email privacy and authenticate senders, then email security is improved, but the process complexity increases and digital key security may be compromised due to multiple steps involving Certificate Authorities and Internet key transmission

Engineering Contradiction:
Improveemail securityVSAvoidprocess complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the Certificate Authority functions directly into the Web-based Email System server. The server now performs certificate issuance, validation, and key management internally rather than relying on external CAs. This integration eliminates the need for users to interact with separate CA systems and prevents digital keys from being transmitted over the Internet, thereby reducing process complexity while maintaining security.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces a secure local key storage mechanism that acts as an intermediary between the user's email client and the email server. Private keys are generated and stored locally in the user's browser or device, never leaving the local environment. This intermediary approach allows secure email encryption and decryption without requiring Internet transmission of sensitive keys, simplifying the overall process while enhancing security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If conventional protocols require users to contact Certificate Authorities and transmit PKI digital keys over the Internet, then email authentication and encryption are achieved, but the risk of key exposure and security compromise increases

Engineering Contradiction:
Improveemail authentication and encryptionVSAvoiddigital key exposure risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the private key generation and storage functions from the remote server environment and places them entirely within the user's local device or browser. Private keys are generated locally using cryptographic functions available in the user's environment and are never transmitted over the network. This extraction eliminates the security vulnerability of Internet key transmission while maintaining the ability to perform secure email operations.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The user's local browser or email client performs all cryptographic operations independently without requiring external CA intervention for key management. The system uses built-in cryptographic libraries to generate keys, sign emails, and verify certificates locally. This self-service approach empowers the user's device to handle security functions autonomously, eliminating the need to transmit sensitive information to external systems.

Inventive Principle:
Principle #25Self-service

3Reliability

If multiple steps are required to create a PKI Email Account with conventional systems, then proper certificate validation and key management are ensured, but user convenience and ease of operation deteriorate

Engineering Contradiction:
Improvecertificate validation and key managementVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent combines multiple separate security functions (certificate issuance, validation, key generation, and email encryption/decryption) into a single integrated Web-based Email System. Users create accounts and obtain security credentials through a unified process rather than separately interacting with multiple systems. This consolidation maintains security requirements while significantly improving user convenience.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system performs preliminary certificate validation and key pair generation automatically during the account creation process, before the user needs to send or receive encrypted emails. Security credentials are pre-configured and validated in advance, eliminating the need for users to manually perform complex setup steps later. This preliminary action maintains security rigor while simplifying the user experience.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS7912906B2Generating PKI email accounts on a web-based email system
Publication Date: 2011.03.22 GO DADDY OPERATING CO LLC
  • US7912906B2 patent drawing
  • US7912906B2 patent drawing
  • US7912906B2 patent drawing

AI summary

The present invention provides systems and methods for allowing an Email User to create a Public Key Infrastructure (PKI) Email Account and thereafter to digitally sign, send, verify and receive PKI encrypted emails over a computer network, such as the Internet. The systems and methods preferably include a Web-based Email System and a Certificate Authority that coordinate their actions to make the process of creating, maintaining and using the PKI Account as easy as possible for the Email User. In a preferred embodiment, a Keystore System may also be used to enhance the management and use of digital keypairs.