Automated CA Certificate Setup via Terminal Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Administrators of information processing apparatuses face difficulties in accurately setting and verifying Certificate Authority (CA) certificates for secure SSL/TLS communication, due to the need for expertise and knowledge of communication destinations, which is often lacking.

Innovation Solution

An information processing system that includes a generator for instructions to verify failed electronic certificates, a transmitter to send verification information, and a setting unit to set CA certificates based on user terminal verification results, facilitating easy CA certificate setup by administrators.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If administrators manually set CA certificates for SSL/TLS communication, then security verification can be performed, but the operation becomes complex and difficult due to required expertise and knowledge of communication destinations

Engineering Contradiction:
Improvecertificate verification accuracyVSAvoidcertificate setting difficulty
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The terminal automatically performs certificate verification and extracts CA certificate information without requiring administrator intervention. The system serves itself by utilizing the terminal's existing verification capabilities to automatically acquire and set the necessary CA certificates, eliminating the need for administrators to manually configure security settings

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The terminal acts as an intermediary between the information processing apparatus and the certificate authority. It receives verification results from the information processing apparatus, performs independent verification using its own certificate storage, and automatically sets the CA certificate based on these results, mediating the complex certificate management process

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If administrators verify certificates manually, then accurate verification can be achieved, but the process requires advanced expertise that administrators often lack

Engineering Contradiction:
Improveverification accuracyVSAvoidverification process complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The terminal uses its existing certificate verification capability to copy and apply the same verification logic to the CA certificate. By leveraging the terminal's built-in verification mechanisms (which administrators already trust for web browsing), the system achieves accurate verification without requiring administrators to understand or perform complex manual verification procedures

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The terminal's certificate verification capability, originally designed for general web security, is applied universally to verify CA certificates for SSL/TLS communication. This multi-functional use of the verification mechanism eliminates the need for separate, complex verification procedures specific to CA certificate management

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10425397B2Information processing system, information processing apparatus, and non-transitory computer readable recording medium storing information processing program
Publication Date: 2019.09.24 FUJIFILM BUSINESS INNOVATION CORP
  • US10425397B2 patent drawing
  • US10425397B2 patent drawing
  • US10425397B2 patent drawing

AI summary

An information processing apparatus includes; a generator that generates an instruction for a terminal used by an administrator of the information processing apparatus to verify a first electronic certificate whose verification has failed; a transmitter that transmits information indicating the first electronic certificate and the instruction to the terminal used by the administrator of the information processing apparatus; and a setting unit that, when an instruction to set a second electronic certificate is received from the terminal, sets the second electronic certificate.