Centralized Certificate Management System for Data Centers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing certificate management systems lack a unified, application-centric approach to manage certificates across multiple data centers, leading to inefficiencies, increased complexity, and heightened risks due to the use of multiple independent tools and device-centric views that do not meet the needs of application owners and network administrators.

Innovation Solution

An application-centric centralized certificate management system that includes modules for discovering, inventorying, and managing certificates across data centers, featuring a processor, memory, and display unit, with modules for discovering certificates, providing inventory details, creating policies, and generating compliance reports, enabling granular object-level management and automatic renewal of certificates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple independent tools are used for certificate management across data centers, then each tool can be specialized for specific devices, but the system complexity increases and no single-view visibility is achieved

Engineering Contradiction:
Improvedevice-specific management capabilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges multiple independent certificate management tools into a single centralized system that provides unified management across all data centers. The system consolidates certificate discovery, inventory, compliance checking, and renewal capabilities into one platform, eliminating the need for multiple separate tools while maintaining device-specific management capabilities through its modular architecture.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The centralized certificate management system is designed to be universal, capable of managing certificates across diverse devices and data centers through a single interface. The system provides multi-functional capabilities including discovery, inventory management, compliance verification, and automated renewal, making it adaptable to various certificate management needs without requiring separate specialized tools.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If device level operations are used on management tools, then device-specific control is achieved, but routing traffic amongst data centers becomes unnecessarily complex

Engineering Contradiction:
Improvedevice-specific controlVSAvoidtraffic routing complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces a centralized certificate management system as an intermediary layer between devices and traffic routing operations. This intermediary provides device-specific control through unified policies and procedures, simplifying traffic routing among data centers by managing certificates centrally rather than requiring complex device-level operations at each endpoint.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If independent tools are used for each data center, then local management autonomy is maintained, but migration and upgrading of network tools becomes almost impossible

Engineering Contradiction:
Improvelocal management autonomyVSAvoidtool migration and upgrading
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The patent combines local management capabilities into a centralized system that maintains autonomy through modular design. The unified platform allows for standardized migration and upgrading across all data centers simultaneously, eliminating the impossibility of updating independent tools while preserving local management flexibility through configurable policies and centralized control.

Inventive Principle:
Principle #5Merging (Combining)

4Adaptability or versatility

If multiple independent tools are used for certificate management, then specialized functionality is available, but an unreasonable amount of time and resources are spent on writing scripts

Engineering Contradiction:
Improvespecialized functionalityVSAvoidtime and resources for scripting
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The centralized certificate management system provides self-service capabilities through automated discovery, inventory management, compliance checking, and renewal processes. The system eliminates the need for manual scripting by offering built-in specialized functionalities that automatically perform certificate management tasks, saving time and resources while maintaining adaptability to different certificate types and devices.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3497633A1Application centric centralized certificate management system for managing certificates across data centers
Publication Date: 2019.06.19 APPVIEWX INC

AI summary

A system for managing one or more certificates on granular object level in one or more datacenters is provided. The system includes a discover module, an inventory module, a work order module, and a policy module. The discover module is configured to discover the one or more certificates. The inventory module is configured to provide details of the one or more certificates. The work order module is configured to store details of (i) a work order id of the one or more certificates, (ii) device information of the one or more certificates, (iii) a time stamp of implementation of the one or more certificates, and (iv) a status the one or more certificates. The policy module is configured to create a policy that specifies (i) usage of the one or more certificates, and (ii) practices that a certificate authority (CA) employs to manage the one or more certificates.