CA Hierarchy for Secure Branch Appliance Certificates
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprises face challenges in creating a cost-effective, secure, and optimized wide area network (WAN) that connects branches, data centers, and mobile users over the Internet, with existing solutions like MPLS being expensive and limited in reach, and requiring additional VPN concentrators for branch office support.
Innovation Solution
An overlay network is configured with an endpoint appliance in an untrusted network, using a Certificate Authority (CA) hierarchy to dynamically generate server certificates with shorter time-to-live (TTL) values, allowing secure information flow termination and reducing risk by limiting certificate compromise impact.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If MPLS is used for WAN connectivity, then security and reliability are improved, but cost increases significantly
Solution Approach 1:
The patent introduces an overlay network as an intermediary layer that operates on top of the public Internet, providing enterprise-grade security and reliability without requiring expensive MPLS infrastructure. The overlay network uses encapsulation and tunneling protocols to create secure virtual paths over the untrusted Internet, effectively mediating between the need for security and the availability of low-cost Internet connectivity.
Solution Approach 2:
The patent creates virtual copies of private network behaviors over the public Internet through the overlay network. By implementing virtual routing, encapsulation, and tunneling protocols, the system replicates the security and reliability characteristics of private MPLS networks over the public Internet infrastructure, allowing enterprises to achieve similar security postures without the associated costs.
2Adaptability or versatility
If VPN concentrators are deployed at MPLS cloud edge, then branch office connectivity is enabled, but device complexity and deployment difficulty increase
Solution Approach 1:
The overlay network gateway device performs multiple functions including routing, encryption, decryption, and protocol translation within a single unified platform. This multi-functional approach eliminates the need for separate VPN concentrators and simplifies deployment, as the gateway can serve multiple branch offices and handle various protocols without requiring additional specialized hardware at each location.
Solution Approach 2:
The patent combines previously separate functions (MPLS routing, VPN termination, branch office connectivity) into a unified overlay network architecture. By merging these functions into the overlay gateway and using a single protocol stack, the system reduces device complexity and streamlines deployment while maintaining the ability to connect multiple branch offices.
3Duration of action of moving object
If certificates with long TTL are used, then certificate validity duration is improved, but security risk increases upon compromise
Solution Approach 1:
The patent implements dynamic certificate management where the Time-To-Live (TTL) of certificates is adjusted based on security requirements and trust levels. Rather than using static long-term certificates, the system dynamically issues certificates with appropriate TTL values that balance validity duration with security risk, allowing certificates to be automatically renewed or revoked based on changing security conditions.
Solution Approach 2:
The system changes the parameter of certificate TTL from a fixed long duration to a variable duration that can be adjusted based on security policies, trust relationships, and risk assessments. This parameter change allows the system to optimize both certificate validity and security by using shorter TTLs for untrusted networks and longer TTLs for trusted environments.
Data Source
AI summary
A method to generate a trusted certificate on an endpoint appliance located in an untrusted network, wherein client devices are configured to trust a first Certificate Authority (CA) that is administered by the untrusted network. In this approach, an overlay network is configured between the endpoint appliance and an origin server associated with the endpoint appliance. The overlay comprises an edge machine located proximate the endpoint appliance, and an associated key management service. A second CA is configured in association with the key management service to receive a second certificate signed by the first CA. A third CA is configured in association with the edge machine to receive a third certificate signed by the second CA. In response to a request from the appliance, a server certificate signed by the third CA is dynamically generated and provided to the appliance. A client device receiving the server certificate from the endpoint appliance trusts the server certificate as if the server certificate originated from the first CA, thereby enabling the endpoint appliance to terminate a secure information flow received at the endpoint appliance.


