Certificate-Based Authentication for Small Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Small computer networks face challenges in implementing straightforward authentication and management due to the diversity of platforms and operating systems, making it difficult to control, manage, and maintain machines securely across different devices.

Innovation Solution

A certificate-based authentication technology where client machines use private-public key pairs to authenticate with a server, allowing secure communication and management, independent of the operating system or platform, with administrators generating and managing certificates for network access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional authentication methods are used in small networks, then platform-specific control and management are achieved, but unified authentication across diverse devices becomes difficult

Engineering Contradiction:
Improveauthentication compatibilityVSAvoidauthentication implementation
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal certificate-based authentication system that works across multiple platforms (Windows, macOS, Linux, mobile devices) by using standardized X.509 certificates and TLS protocols. The server maintains a centralized certificate store that can authenticate any device regardless of its operating system, providing platform-independent authentication capability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces a centralized authentication server as an intermediary between client devices and network resources. This server acts as a mediator by verifying certificates, managing the certificate repository, and facilitating authentication without requiring platform-specific implementation details, thus simplifying the authentication process across diverse devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If certificate-based authentication is implemented, then secure communication between client machines is achieved, but certificate management complexity increases

Engineering Contradiction:
Improvecommunication securityVSAvoidcertificate management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements automatic certificate enrollment and renewal mechanisms where client devices can automatically obtain certificates from the server without manual intervention. The system handles certificate validation, storage, and renewal automatically, reducing the management burden on users while maintaining security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The authentication server provides feedback mechanisms to clients about certificate validity, enrollment status, and renewal requirements. This feedback loop allows the system to automatically manage certificate lifecycles, alert administrators to issues, and maintain secure authentication without increasing operational complexity.

Inventive Principle:
Principle #23Feedback

3Ease of operation

If administrators manually manage certificates for each device, then precise control over network access is achieved, but time consumption for device onboarding increases

Engineering Contradiction:
Improvenetwork access controlVSAvoiddevice onboarding time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent implements pre-configured certificate templates and automatic enrollment procedures that are prepared in advance. When a new device joins the network, it can automatically obtain a pre-configured certificate from the server without requiring manual administrator intervention, significantly reducing onboarding time while maintaining access control policies.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables self-service certificate enrollment where devices can automatically register themselves with the authentication server, obtain appropriate certificates based on their device type and intended use, and begin secure communication without manual administrator involvement, thus reducing onboarding time while maintaining control.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9270471B2Client-client-server authentication
Publication Date: 2016.02.23 MICROSOFT TECHNOLOGY LICENSING LLC
  • US9270471B2 patent drawing
  • US9270471B2 patent drawing
  • US9270471B2 patent drawing

AI summary

Described is a technology by which machines of a (typically small) network have associated public key-based certificates for use in authentication with a server and validation of other machines in the network. This provides an inexpensive and straightforward mechanism to control, manage and maintain client machines, as well as to allow valid client machines to securely communicate with one another and recognize machines that are not valid on the network. Certificates are maintained on the server and checked for validity as needed.