Application-Specific Certificate Management for Mobile Enterprise Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile device management faces challenges in securely accessing enterprise resources without pre-defined access lists, and existing VPN solutions can be resource-intensive and difficult to establish.

Innovation Solution

Implementing application-specific certificate deployment, where an application generates a security certificate with a public key and private key, with the public key stored in a shared memory segment for secure encryption and decryption of resources, and compliance with security policies to manage access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a VPN is established to provide secure communication, then security is improved, but the process becomes resource intensive and difficult to establish

Engineering Contradiction:
Improvesecure communicationVSAvoidestablishment process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the core security function from the complex VPN protocol by using existing operating system communication channels combined with security certificates. Instead of establishing a full VPN tunnel, the solution extracts only the essential security layer using certificates to authenticate and encrypt data over existing channels, thereby reducing complexity while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces security certificates as an intermediary mechanism between applications and enterprise resources. Rather than directly establishing complex VPN connections, certificates act as mediators that enable secure authentication and communication through existing OS channels, simplifying the connection process while ensuring security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Use of energy by moving object

If existing communication channels are leveraged with security certificates, then resource consumption is reduced, but applications without pre-defined access lists cannot securely access enterprise resources

Engineering Contradiction:
Improveresource consumptionVSAvoidaccess flexibility
Core Design Contradiction:
Use of energy by moving objectVSAdaptability or versatility

Solution Approach 1:

The patent makes security certificates universal by enabling any application to use them for secure access to enterprise resources. Instead of requiring pre-defined access lists for specific applications, any application can obtain and use security certificates to authenticate and access resources, providing universal access capability while maintaining security and reducing resource consumption.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If security certificates are used for secure access, then access control is improved, but key management complexity increases

Engineering Contradiction:
Improveaccess controlVSAvoidkey management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service key management where applications automatically generate, store, and manage their own security certificates and cryptographic keys. The system provides automated certificate enrollment, key generation, and storage mechanisms that eliminate manual key management overhead, allowing applications to autonomously handle their security credentials while maintaining strong access control.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10911226B2Application specific certificate management
Publication Date: 2021.02.02 OMNISSA LLC
  • US10911226B2 patent drawing
  • US10911226B2 patent drawing
  • US10911226B2 patent drawing

AI summary

Application specific certificate deployment may be provided. An application may generate a security certificate comprising a public key and a first private key. The public key may be stored in a shared segment of a memory store, from where it may be retrieved and signed. The signed public key may be re-deployed and/or used to transmit securely encrypted resources.