Automated Certificate Update for Portable Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for updating digital certificates on portable devices, such as smart cards used by healthcare professionals, are inefficient and require manual intervention, leading to potential certificate expiration and security risks due to the lack of automated and transparent updating processes.
Innovation Solution
A method for automatically updating certificates on portable devices connected to a client station via a network, involving the client station generating requests for new certificates, executing actions, and installing them, without requiring administrative or physical procedures from the certificate holder, ensuring secure and timely updates.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Extent of automation
If manual certificate update procedures are used, then human supervision and control are maintained, but the update process requires significant user intervention and time
Solution Approach 1:
The system enables self-service certificate updates by allowing the portable device to automatically request, receive, and install new certificates from the server without requiring user intervention. The device autonomously manages the entire certificate renewal process including generating update requests, receiving authentication, and installing updated certificates.
Solution Approach 2:
The system performs preliminary actions by proactively detecting expiring certificates before their validity period ends and initiating the update process in advance. The server sends authentication requests to users beforehand, and the device automatically receives and installs new certificates before the old ones expire, ensuring continuous validity.
2Loss of time
If automated certificate updates are implemented, then user time and administrative overhead are reduced, but security risks may increase due to reduced human supervision
Solution Approach 1:
The system implements feedback mechanisms where the server sends authentication requests to users for certificate updates, and the device provides status information about the update process. Users receive notifications and can approve or reject update requests, maintaining human oversight while enabling automated execution upon approval.
Solution Approach 2:
The server acts as an intermediary between the portable device and the certificate authority. It mediates the update process by receiving update requests from the device, obtaining user authentication, retrieving new certificates from the authority, and securely transmitting them to the device. This intermediary role maintains security control while enabling automation.
3Productivity
If certificates are updated manually in person, then security and authenticity are ensured through physical authentication, but the process is inefficient and requires summoning users at regular intervals
Solution Approach 1:
The system replaces the mechanical process of in-person certificate updates with an automated electronic system. Instead of physically summoning users to update their certificates, the device automatically communicates with the server over a network, transmitting update requests and receiving new certificates electronically, thereby eliminating the need for physical presence and manual intervention.
4Duration of action of stationary object
If certificate validity periods are extended, then fewer updates are needed, but the risk of using outdated certificates increases
Solution Approach 1:
The system implements periodic certificate updates by automatically detecting when certificates are approaching expiration and initiating renewal processes at regular intervals. The server monitors certificate validity periods and sends update requests periodically, ensuring certificates are refreshed before expiration without requiring excessively long validity periods.
Data Source
Figure 1~2
Figure 3
Figure 4
AI summary
The invention relates to a method for updating at least one certificate stored in data storage means of a portable device capable of being connected to a client workstation, said client workstation being connected via a network to a server storing a list of certificates, said method comprising the implementation of steps of: - generation by the data processing means of the client workstation of a request to retrieve from the server a list of actions ordered by a server administrator and transmission of said request to said server; - determination (403) by the data processing means of the client workstation of at least one certificate to be updated on the portable device; - for each certificate to be updated determined, generation (406) and transmission (407) by the data processing means of the client workstation of a request for the issuance of a new certificate to a certification authority via said server;- updating (411) by the server's data processing means of said certificate list stored on the server from the new certificates issued by the certification authority; - generation and transmission, by the client's data processing means, of a retrieval request (412) of said new certificates to said server; - installation (414) by the client's data processing means on said portable device of said retrieved new certificates.