Automated Certificate Update for Portable Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for updating digital certificates on portable devices, such as smart cards used by healthcare professionals, are inefficient and require manual intervention, leading to potential certificate expiration and security risks due to the lack of automated and transparent updating processes.

Innovation Solution

A method for automatically updating certificates on portable devices connected to a client station via a network, involving the client station generating requests for new certificates, executing actions, and installing them, without requiring administrative or physical procedures from the certificate holder, ensuring secure and timely updates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Extent of automation

If manual certificate update procedures are used, then human supervision and control are maintained, but the update process requires significant user intervention and time

Engineering Contradiction:
Improvecertificate update automationVSAvoiduser intervention requirement
Core Design Contradiction:
Extent of automationVSEase of operation

Solution Approach 1:

The system enables self-service certificate updates by allowing the portable device to automatically request, receive, and install new certificates from the server without requiring user intervention. The device autonomously manages the entire certificate renewal process including generating update requests, receiving authentication, and installing updated certificates.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by proactively detecting expiring certificates before their validity period ends and initiating the update process in advance. The server sends authentication requests to users beforehand, and the device automatically receives and installs new certificates before the old ones expire, ensuring continuous validity.

Inventive Principle:
Principle #10Preliminary action

2Loss of time

If automated certificate updates are implemented, then user time and administrative overhead are reduced, but security risks may increase due to reduced human supervision

Engineering Contradiction:
Improvecertificate update timeVSAvoidupdate security
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

The system implements feedback mechanisms where the server sends authentication requests to users for certificate updates, and the device provides status information about the update process. Users receive notifications and can approve or reject update requests, maintaining human oversight while enabling automated execution upon approval.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The server acts as an intermediary between the portable device and the certificate authority. It mediates the update process by receiving update requests from the device, obtaining user authentication, retrieving new certificates from the authority, and securely transmitting them to the device. This intermediary role maintains security control while enabling automation.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If certificates are updated manually in person, then security and authenticity are ensured through physical authentication, but the process is inefficient and requires summoning users at regular intervals

Engineering Contradiction:
Improvecertificate update efficiencyVSAvoidupdate process complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system replaces the mechanical process of in-person certificate updates with an automated electronic system. Instead of physically summoning users to update their certificates, the device automatically communicates with the server over a network, transmitting update requests and receiving new certificates electronically, thereby eliminating the need for physical presence and manual intervention.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Duration of action of stationary object

If certificate validity periods are extended, then fewer updates are needed, but the risk of using outdated certificates increases

Engineering Contradiction:
Improvecertificate validity periodVSAvoidcertificate currency
Core Design Contradiction:
Duration of action of stationary objectVSReliability

Solution Approach 1:

The system implements periodic certificate updates by automatically detecting when certificates are approaching expiration and initiating renewal processes at regular intervals. The server monitors certificate validity periods and sends update requests periodically, ensuring certificates are refreshed before expiration without requiring excessively long validity periods.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentEP2808819B1Method for updating certificates in a portable device
Publication Date: 2019.07.10 SYSTANCIA
  • EP2808819B1 patent drawingFigure 1~2
  • EP2808819B1 patent drawingFigure 3
  • EP2808819B1 patent drawingFigure 4

AI summary

The invention relates to a method for updating at least one certificate stored in data storage means of a portable device capable of being connected to a client workstation, said client workstation being connected via a network to a server storing a list of certificates, said method comprising the implementation of steps of: - generation by the data processing means of the client workstation of a request to retrieve from the server a list of actions ordered by a server administrator and transmission of said request to said server; - determination (403) by the data processing means of the client workstation of at least one certificate to be updated on the portable device; - for each certificate to be updated determined, generation (406) and transmission (407) by the data processing means of the client workstation of a request for the issuance of a new certificate to a certification authority via said server;- updating (411) by the server's data processing means of said certificate list stored on the server from the new certificates issued by the certification authority; - generation and transmission, by the client's data processing means, of a retrieval request (412) of said new certificates to said server; - installation (414) by the client's data processing means on said portable device of said retrieved new certificates.