Certificate Issuance Notification Validation via Mail Server Mediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In Public Key Infrastructure (PKI) systems, users face challenges in managing certificate issuance notification messages, particularly on wireless devices, where automated mechanisms are lacking, leading to user awareness issues, potential malicious message processing, and security vulnerabilities.

Innovation Solution

A method is introduced to validate certificate issuance notification messages by receiving and determining their validity, authenticating signatures, and extracting Uniform Resource Locators (URLs) for processing, implemented in a mail server and computer-readable medium to automate the certificate retrieval and management process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If automated mechanisms are introduced for certificate management on wireless devices, then ease of operation and productivity are improved, but device complexity increases

Engineering Contradiction:
Improvecertificate managementVSAvoidautomation mechanism
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces a mail server as an intermediary component that handles certificate issuance notifications and automated retrieval processes. This mediator absorbs the complexity of automation logic, allowing wireless devices to benefit from automated certificate management without bearing the full complexity burden themselves. The mail server acts as a buffer between the certificate authority and the end user device, managing the automated mechanisms centrally.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If validation mechanisms are implemented for certificate issuance notifications, then security and reliability are improved, but processing time and complexity increase

Engineering Contradiction:
Improvemessage validationVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary validation actions by establishing expected norms and criteria for certificate issuance notifications before actual processing occurs. The mail server is pre-configured with validation rules, sender identification criteria, and message format expectations. When a notification arrives, these pre-established criteria enable rapid validation without requiring complex real-time analysis, thus maintaining security while minimizing processing time.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If manual user awareness mechanisms are used for certificate issuance, then user control is maintained, but productivity and ease of operation deteriorate

Engineering Contradiction:
Improvecertificate issuance processingVSAvoiduser involvement
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The patent implements self-service mechanisms where the system automatically retrieves certificates, validates notifications, and manages the entire certificate issuance workflow without requiring active user participation. The mail server autonomously processes certificate issuance notifications, extracts URLs, retrieves certificates, and delivers them to the appropriate destinations. This eliminates the need for users to manually monitor or intervene in the certificate issuance process, significantly improving productivity while maintaining ease of operation.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8826007B2System and method for validating certificate issuance notification messages
Publication Date: 2014.09.02 MALIKIE INNOVATIONS LTD
  • US8826007B2 patent drawing
  • US8826007B2 patent drawing
  • US8826007B2 patent drawing

AI summary

To validate a received certificate issuance notification message, a device may verify that the certificate issuance notification message conforms to expected norms or authenticate a signature associate with the certificate issuance notification message. Upon validating, the device may then transmit a uniform resource locator, extracted from the certificate issuance notification message, to a network entity configured for processing certificate issuance.