Electronic Certificate Provisioning for Automatic Renewal Across Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The manual process of adding, updating, and setting electronic certificates in multiple information processing apparatuses is burdensome and time-consuming, particularly when many devices need to be managed.

Innovation Solution

An information processing apparatus is equipped with a mechanism to automatically generate a public key pair, request and obtain electronic certificates via a certificate authority, and enable their use in applications, reducing the need for manual intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual storage and management of electronic certificates is performed for each information processing apparatus, then authentication security is maintained, but user workload increases and time consumption increases

Engineering Contradiction:
Improveauthentication securityVSAvoiduser workload
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The information processing apparatus automatically generates its own public key pair, requests electronic certificates from a certificate authority, and manages certificate updates without requiring manual user intervention. The system performs self-certification and self-renewal operations, eliminating the need for users to manually store, update, or manage certificates across multiple devices.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by automatically generating public key pairs and obtaining electronic certificates before they are needed for authentication. The apparatus proactively manages certificate validity periods and performs updates before expiration, preventing authentication failures before they occur.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If manual update of electronic certificates is performed when validity period expires, then authentication continues to work, but time consumption increases

Engineering Contradiction:
Improveauthentication continuityVSAvoidtime consumption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The apparatus automatically monitors its own certificate validity period and performs self-renewal without user intervention. The system handles the entire update process including generating new key pairs, requesting certificates from CAs, and configuring applications, eliminating manual update operations.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs certificate updates in advance before the validity period expires by continuously monitoring certificate status and initiating renewal processes proactively, ensuring authentication continuity without last-minute manual interventions.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If separate electronic certificates are managed for each communication application, then communication security is optimized, but device complexity increases

Engineering Contradiction:
Improvecommunication securityVSAvoidcertificate management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system uses a unified certificate management mechanism that handles multiple communication applications (TLS, IPSEC, IEEE802.1X) through a single integrated process. The apparatus obtains one electronic certificate that can be applied across different communication protocols, eliminating the need to manage separate certificates for each application while maintaining security optimization.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250365165A1Information processing apparatus, method of controlling the same, and storage medium
Publication Date: 2025.11.27 CANON KK
  • US20250365165A1 patent drawing
  • US20250365165A1 patent drawing
  • US20250365165A1 patent drawing

AI summary

An information processing apparatus generates a public key pair in accordance with a certificate issuance request, generates a certificate signing request based on the public key pair and transmits an electronic certificate issuance request to an external apparatus. The information processing apparatus receives a response transmitted from the external apparatus as a response to the electronic certificate issuance request, obtains an electronic certificate included in the received response and causes an application to enable its use of the obtained electronic certificate.