Automated Digital Certificate Discovery Scanner

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems lack a comprehensive method to discover, analyze, catalog, inventory, and monitor digital certificates installed on a network, leading to potential disruptions due to untrustworthy or expiring certificates, as administrators do not have tools to manage these certificates proactively.

Innovation Solution

A scanner system that scans an address range to discover digital certificates, analyzes, catalogs, and monitors them, including an analyzing module, cataloging module, and monitoring module to manage the certificates by categorizing, inventorying, and periodically re-checking their validity and trustworthiness.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If SSL analysis is performed only in the context of authorizing access to applications, then real-time certificate validation occurs, but the system cannot discover or manage digital certificates proactively

Engineering Contradiction:
Improvecertificate validation reliabilityVSAvoidcertificate management capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements preliminary scanning of address ranges to discover digital certificates before they are needed for SSL transactions. The system proactively identifies certificates, checks their validity, and maintains an inventory in advance, rather than waiting for SSL handshake failures to reveal certificate issues. This preliminary discovery and validation approach resolves the contradiction by enabling both real-time validation reliability and proactive management capability.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If digital certificates are analyzed only during message verification, then source and contents verification is ensured, but comprehensive certificate management is not achieved

Engineering Contradiction:
Improvemessage verification reliabilityVSAvoidcertificate inventory information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent creates a universal certificate management system that performs multiple functions: discovering certificates across the network, validating their authenticity, tracking expiration dates, maintaining inventories, and supporting both SSL and email verification. This multi-functional approach ensures message verification reliability while simultaneously preventing information loss about certificate status, location, and validity across the entire network.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Loss of information

If administrators manually track digital certificates, then some certificate awareness is achieved, but comprehensive cataloging and monitoring cannot be maintained

Engineering Contradiction:
Improvecertificate awarenessVSAvoidmanagement system complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent implements a self-service automated system where the scanner automatically discovers certificates, validates them, updates inventories, and monitors expiration dates without requiring administrator intervention. The system serves itself by maintaining current certificate information across the network, eliminating the need for manual tracking while providing comprehensive cataloging and monitoring capabilities without proportional increases in operational complexity.

Inventive Principle:
Principle #25Self-service

4Device complexity

If no proactive certificate monitoring is implemented, then system simplicity is maintained, but network disruptions occur due to untrustworthy or expiring certificates

Engineering Contradiction:
Improvemonitoring system complexityVSAvoidnetwork operation reliability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent implements a feedback mechanism where the scanner continuously monitors certificate validity, expiration dates, and trustworthiness, then provides this information back to administrators through inventories and alerts. This feedback loop enables proactive identification of problematic certificates before they cause network disruptions, maintaining high reliability while keeping the monitoring system complexity manageable through automated processes.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS7546454B2Automated digital certificate discovery and management
Publication Date: 2009.06.09 SBC KNOWLEDGE VENTURES LP
  • US7546454B2 patent drawing
  • US7546454B2 patent drawing
  • US7546454B2 patent drawing

AI summary

A scanner discovers digital certificates by scanning an address range. The scanner scans the address range to determine whether a digital certificate has been installed for each address in the address range. The scanner receives digital certificate information when the digital certificate has been installed for an address. The address range that is scanned may include addresses associated with an installed digital certificate and addresses not associated with an installed digital certificate.