Access Point Certificates Without Wildcards for Complex Domain Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional certificate generation approaches use wildcard entries to manage multiple domains and subdomains, which introduce security and compliance concerns, and fail to efficiently handle complex DNS topologies and CDN proxies, leading to incorrect configurations and increased attack surfaces.

Innovation Solution

A certificate management system generates certificates based on a graph representing relationships between access points and domains/subdomains, listing each node separately without wildcard entries, and continuously updates the certificates in response to changes in domain relationships.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If wildcard entries are used in certificates to represent multiple domains or subdomains, then certificate management becomes simpler and fewer certificates are needed, but security compliance deteriorates and attack surfaces increase

Engineering Contradiction:
Improvecertificate management simplicityVSAvoidsecurity compliance
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent segments the certificate by creating separate certificate entries for each specific domain and subdomain associated with an access point, rather than using a single wildcard entry. This segmentation allows precise control over which domains are covered while maintaining security compliance, as each entry is explicitly defined rather than broadly covered by a wildcard pattern.

Inventive Principle:
Principle #1Segmentation

2Quantity of substance

If wildcard entries are used in certificates, then the number of certificates needed is reduced, but the attack surface increases

Engineering Contradiction:
Improvenumber of certificatesVSAvoidattack surface
Core Design Contradiction:
Quantity of substanceVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by making each certificate entry specific to particular domains and subdomains rather than using a general wildcard pattern. This localized approach ensures that the certificate only covers the exact domains intended, reducing the attack surface while still providing comprehensive coverage for all legitimate domains through multiple specific entries within the same certificate.

Inventive Principle:
Principle #3Local quality

3Ease of manufacture

If conventional certificate approaches are used with wildcard entries, then certificate generation is simpler, but accuracy in reflecting current domain relationships deteriorates

Engineering Contradiction:
Improvecertificate generation simplicityVSAvoidaccuracy of domain relationships
Core Design Contradiction:
Ease of manufactureVSMeasurement precision

Solution Approach 1:

The patent implements feedback by continuously monitoring changes in domain relationships and automatically updating the certificate accordingly. The system receives notifications when domains are added or removed from the access point, and the certificate is regenerated to reflect only the current, accurate set of domains and subdomains, ensuring precision without manual intervention.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12615247B2Wildcard-free certificates for network address domains
Publication Date: 2026.04.28 EBAY INC
  • US12615247B2 patent drawing
  • US12615247B2 patent drawing
  • US12615247B2 patent drawing

AI summary

Generating an access point certificate based on a graph that defines relationships between an access point and at least one domain is described. Relationship data describing how data is to be routed between an access point and domains is received by a certificate management system. The certificate management system generates a graph representing an access point and associated domains as nodes, with edges connecting various nodes to model relationships between the access point and the associated domains. Based on the graph, a certificate is generated that individually lists each domain associated with the access point and includes information describing data routing for the domain via the access point. The certificate excludes wildcard entries that represent multiple domains via a single entry. The certificate is used to control data communication traffic via the access point and is updated responsive to changes in in domain relationship data for the access point.