Certificate Bundle Phase Transitions for Virtual Cloud Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems face challenges in transitioning network entities within virtual cloud networks during certificate bundle distribution processes, leading to potential downtime and inefficiencies.

Innovation Solution

A method is employed to transition network entities through phases of a certificate bundle distribution process based on aggregate metrics, ensuring transition criteria are met to avoid downtime by conditioning transitions on computed aggregate progress.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If certificate bundles are distributed to all network entities simultaneously, then security updates are applied quickly, but network downtime increases and reliability decreases

Engineering Contradiction:
Improvecertificate distribution speedVSAvoidnetwork availability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the network entities into multiple groups or phases for staged certificate bundle distribution. Instead of updating all entities simultaneously, the system divides them into manageable subsets that can be updated sequentially, allowing continuous operation while distributing the update load across different time periods.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary actions by distributing certificate bundles to a subset of network entities before completing the distribution to all entities. This allows the system to prepare and test certificate updates in advance on selected entities, ensuring validity and compatibility before full-scale deployment, thereby maintaining network availability.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If certificate bundles are distributed to a subset of network entities, then network availability is maintained, but distribution time increases

Engineering Contradiction:
Improvenetwork availabilityVSAvoiddistribution duration
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent employs periodic action by distributing certificate bundles in repeated cycles to different subsets of network entities. Each cycle updates a specific group while others continue operating normally, creating a rhythmic pattern of updates that maintains overall network availability while progressively completing distribution to all entities over time.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The patent implements dynamics by adaptively adjusting the subset selection and distribution pacing based on network conditions, entity readiness, and validation results. The system dynamically determines which entities to update next based on real-time feedback, optimizing the distribution timeline while maintaining network availability.

Inventive Principle:
Principle #15Dynamics

3Productivity

If transitions between phases are automated, then operational efficiency improves, but system complexity increases

Engineering Contradiction:
Improveoperational efficiencyVSAvoidphase management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements feedback mechanisms where the system continuously monitors the validity status of certificate bundles and the operational state of network entities. Based on this feedback, the system automatically determines when to transition between distribution phases, adjusting the update process dynamically without requiring complex manual intervention while maintaining operational efficiency.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent enables self-service by allowing network entities to automatically receive, validate, and apply certificate bundles without manual intervention. The system autonomously manages the distribution process, including phase transitions, by monitoring entity readiness and certificate validity, thereby improving operational efficiency while the automation handles the complexity internally.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12562966B2Transitioning network entities associated with a virtual cloud network through a series of phases of a certificate bundle distribution process
Publication Date: 2026.02.24 ORACLE INT CORP
  • US12562966B2 patent drawing
  • US12562966B2 patent drawing
  • US12562966B2 patent drawing

AI summary

Network entities associated with a virtual cloud network are transitioned through a certificate bundle distribution process for distributing new certificate authority certificates to the network entities. Operations may include executing, in relation to each of the network entities, a first operation associated with a first phase of the process; obtaining, for each particular network entity, individual entity information associated with a progress of a particular network entity in relation to the first phase; computing, based on the individual entity information, an aggregate metric indicative of an aggregate progress of the network entities in relation to the first phase; determining, based on the aggregate metric, that one or more transition criteria are satisfied for transitioning the network entities from the first phase to a second phase of the process; and executing, in relation to each of the network entities, a second operation associated with the second phase of the process.