Appliance Certificate Authority for Secure Network Addressing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for securing communications with networked appliances, such as printers and scanners, fail to reliably identify the intended device and ensure privacy due to dynamic IP addresses and the risk of impersonation, particularly in public venues, and do not adequately address key distribution and verification.

Innovation Solution

Establishing a trusted association between the appliance and a certificate authority before deployment, creating and announcing a signed certificate with the appliance's communications address, and verifying this address to ensure secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a label-based approach is used to identify appliance addresses, then ease of operation is improved, but reliability deteriorates due to dynamic IP addresses and impersonation risks

Engineering Contradiction:
Improveease of identifying appliance addressVSAvoidreliability of address identification
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary actions by establishing trusted associations and creating signed certificates before the appliance is deployed on the network. The certificate is prepared in advance with the appliance's identity information, ensuring that when the appliance connects, its identity is already verified and authenticated, preventing impersonation attacks.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a certificate authority as an intermediary that issues signed certificates to appliances. This intermediary verifies the appliance's identity and provides a trusted credential that allows clients to authenticate the appliance's true identity, resolving the reliability issue without compromising ease of operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If SSL encryption is used to protect data transmission, then privacy is improved, but device complexity increases due to key management requirements

Engineering Contradiction:
Improveprivacy protection against eavesdroppingVSAvoidcomplexity of key management
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The signed certificate serves multiple functions simultaneously: it provides encryption keys for SSL/TLS communication, acts as an identity verification credential, and enables authentication without requiring separate key distribution mechanisms. This multi-functionality reduces overall system complexity while maintaining strong privacy protection.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The appliance autonomously obtains and manages its own signed certificate without requiring manual key distribution or complex administrative overhead. The certificate self-containedly provides all necessary cryptographic material for secure communication, simplifying key management.

Inventive Principle:
Principle #25Self-service

3Reliability

If IP-Sec is used to secure packet routing, then reliability is improved, but ease of operation deteriorates due to complex address verification requirements

Engineering Contradiction:
Improvereliability of message deliveryVSAvoidease of verifying appliance identity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent extracts the identity verification function from the complex IP-Sec routing mechanism and implements it through simpler signed certificate validation. The certificate contains the appliance's identity information in a readily verifiable format, allowing clients to easily authenticate appliances without implementing full IP-Sec complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS8375202B2Communications methods and appliances
Publication Date: 2013.02.12 HEWLETT PACKARD ENTERPRISE DEV LP
  • US8375202B2 patent drawing
  • US8375202B2 patent drawing
  • US8375202B2 patent drawing

AI summary

Communications methods and appliances are described. According to one embodiment, a communications method includes prior to deployment of an appliance, establishing a trusted association between the appliance and a certificate authority, during deployment of the appliance, associating the appliance with a communications address of a communications medium, using the certificate authority, creating a signed certificate including the communications address of the appliance, announcing the signed certificate using the appliance, after the announcing, extracting the communications address of the appliance from the signed certificate, and after the extracting, verifying the communications address of the appliance.