CA Hierarchy for Secure Branch Appliance Certificates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprises face challenges in creating a cost-effective, secure, and optimized wide area network (WAN) that connects branches, data centers, and mobile users over the Internet, with existing solutions like MPLS being expensive and limited in reach, and requiring additional VPN concentrators for branch office support.

Innovation Solution

An overlay network is configured with an endpoint appliance in an untrusted network, using a Certificate Authority (CA) hierarchy to dynamically generate server certificates with shorter time-to-live (TTL) values, allowing secure information flow termination and reducing risk by limiting certificate compromise impact.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If MPLS is used for WAN connectivity, then security and reliability are improved, but cost increases significantly

Engineering Contradiction:
ImprovesecurityVSAvoidcost
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent introduces an overlay network as an intermediary layer that operates on top of the public Internet, providing enterprise-grade security and reliability without requiring expensive MPLS infrastructure. The overlay network uses encapsulation and tunneling protocols to create secure virtual paths over the untrusted Internet, effectively mediating between the need for security and the availability of low-cost Internet connectivity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates virtual copies of private network behaviors over the public Internet through the overlay network. By implementing virtual routing, encapsulation, and tunneling protocols, the system replicates the security and reliability characteristics of private MPLS networks over the public Internet infrastructure, allowing enterprises to achieve similar security postures without the associated costs.

Inventive Principle:
Principle #26Copying

2Adaptability or versatility

If VPN concentrators are deployed at MPLS cloud edge, then branch office connectivity is enabled, but device complexity and deployment difficulty increase

Engineering Contradiction:
Improvebranch office connectivityVSAvoiddeployment complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The overlay network gateway device performs multiple functions including routing, encryption, decryption, and protocol translation within a single unified platform. This multi-functional approach eliminates the need for separate VPN concentrators and simplifies deployment, as the gateway can serve multiple branch offices and handle various protocols without requiring additional specialized hardware at each location.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent combines previously separate functions (MPLS routing, VPN termination, branch office connectivity) into a unified overlay network architecture. By merging these functions into the overlay gateway and using a single protocol stack, the system reduces device complexity and streamlines deployment while maintaining the ability to connect multiple branch offices.

Inventive Principle:
Principle #5Merging (Combining)

3Duration of action of moving object

If certificates with long TTL are used, then certificate validity duration is improved, but security risk increases upon compromise

Engineering Contradiction:
Improvecertificate validityVSAvoidsecurity risk
Core Design Contradiction:
Duration of action of moving objectVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic certificate management where the Time-To-Live (TTL) of certificates is adjusted based on security requirements and trust levels. Rather than using static long-term certificates, the system dynamically issues certificates with appropriate TTL values that balance validity duration with security risk, allowing certificates to be automatically renewed or revoked based on changing security conditions.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the parameter of certificate TTL from a fixed long duration to a variable duration that can be adjusted based on security policies, trust relationships, and risk assessments. This parameter change allows the system to optimize both certificate validity and security by using shorter TTLs for untrusted networks and longer TTLs for trusted environments.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11818279B2Certificate authority (CA) security model in an overlay network supporting a branch appliance
Publication Date: 2023.11.14 AKAMAI TECHNOLOGIES INC
  • US11818279B2 patent drawing
  • US11818279B2 patent drawing
  • US11818279B2 patent drawing

AI summary

A method to generate a trusted certificate on an endpoint appliance located in an untrusted network, wherein client devices are configured to trust a first Certificate Authority (CA) that is administered by the untrusted network. In this approach, an overlay network is configured between the endpoint appliance and an origin server associated with the endpoint appliance. The overlay comprises an edge machine located proximate the endpoint appliance, and an associated key management service. A second CA is configured in association with the key management service to receive a second certificate signed by the first CA. A third CA is configured in association with the edge machine to receive a third certificate signed by the second CA. In response to a request from the appliance, a server certificate signed by the third CA is dynamically generated and provided to the appliance. A client device receiving the server certificate from the endpoint appliance trusts the server certificate as if the server certificate originated from the first CA, thereby enabling the endpoint appliance to terminate a secure information flow received at the endpoint appliance.