Automated CA Certificate Installation for SSL Inspection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing SSL man-in-the-middle inspection systems require manual installation of CA certificates on client machines, which is inconvenient for users due to the need for knowledge of certificates and varying installation processes across different operating systems.

Innovation Solution

A client security manager automatically downloads and installs a CA certificate from a network security appliance into the client's certificate store, making it a trusted root certificate, thus eliminating the need for manual installation and ensuring secure connections without warning messages.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual installation of CA certificate is performed, then security trust is established, but user convenience deteriorates due to complex installation process

Engineering Contradiction:
Improvesecurity trustVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs self-service by automatically detecting the need for CA certificate installation and executing the installation process without requiring user intervention. The security appliance autonomously generates the CA certificate, stores it securely, and manages its distribution to clients, thereby establishing security trust while maintaining user convenience.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The CA certificate is generated and prepared in advance by the security appliance before actual SSL inspection operations begin. This preliminary action ensures that the certificate is ready for immediate use, establishing security trust upfront while avoiding the need for complex manual installation procedures when needed.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If automatic installation is implemented, then user convenience is improved, but system complexity increases due to automated certificate management

Engineering Contradiction:
Improveuser convenienceVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent merges the CA certificate generation, storage, and distribution functions into the existing security appliance infrastructure. By combining these certificate management tasks with the appliance's existing SSL inspection and security enforcement capabilities, the system achieves automatic installation without proportionally increasing overall system complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The security appliance acts as an intermediary between the certificate authority function and the client systems. It mediates the entire certificate lifecycle including generation, secure storage, and automated distribution to clients, thereby simplifying the user experience while concentrating the complexity within the appliance's managed environment.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10326756B2Management of certificate authority (CA) certificates
Publication Date: 2019.06.18 FORTINET INC
  • US10326756B2 patent drawing
  • US10326756B2 patent drawing
  • US10326756B2 patent drawing

AI summary

Systems and methods for automatically installing CA certificates received from a network security appliance by a client security manager to make the CA certificate become a trusted CA certificate to a client machine are provided. In one embodiment, a client security manager establishes a connection with a network security appliance through a network, wherein the client security manager is configured for managing security of a client at the client side and the network security appliance is configured for managing the security of traffic pass through the network. The client security manager downloads from the network security appliance a certificate authority (CA) certificate to be used for signing a server certificate of a secure connection between the network security appliance and the client and automatically installs the CA certificate into a certificate store of the client.