Certificate Discovery via Passive PKI Handshake Mirroring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security monitoring solutions in networks are intrusive and trigger alarms in network monitoring systems, failing to adequately check Public Key Infrastructure (PKI) data for compliance with standards, and lack the ability to capture client certificate information during secure connection handshakes.

Innovation Solution

Implementing a non-intrusive security monitoring mechanism in network switches that captures and analyzes PKI data via an analysis port, mirroring security data from handshake communications to an external system for compliance evaluation, enabling comprehensive analysis of certificate usage and compliance with standards.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If existing security monitoring solutions are deployed to capture PKI data, then security compliance analysis capability is improved, but false alarms are triggered in network monitoring systems

Engineering Contradiction:
ImprovePKI data capture accuracyVSAvoidfalse alarms
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a network tap as an intermediary device that passively captures PKI data from network traffic without actively injecting probes or alerts into the monitored network. This intermediary approach allows security compliance analysis while avoiding the harmful effect of triggering false alarms in network monitoring systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates a copy of network traffic containing PKI data through the network tap, analyzing the copied data rather than the original traffic flow. This copying mechanism enables comprehensive PKI data capture and compliance analysis without interfering with normal network operations or triggering security alerts.

Inventive Principle:
Principle #26Copying

2Reliability

If intrusive security monitoring is implemented to capture handshake data, then certificate compliance checking is improved, but network operations are disrupted

Engineering Contradiction:
Improvecertificate compliance verificationVSAvoidnetwork operation continuity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The monitored network systems perform their own certificate compliance verification through the captured PKI data, without requiring external intervention or disruption to their operations. The passive capture approach allows systems to self-verify compliance while maintaining normal operational flow.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

By copying network traffic to an analysis port for PKI data extraction, the system enables compliance verification without interrupting the original network operations. The copy mechanism preserves operational continuity while providing comprehensive certificate validation capability.

Inventive Principle:
Principle #26Copying

3Measurement precision

If comprehensive PKI data analysis is performed to ensure security compliance, then compliance evaluation thoroughness is improved, but data processing complexity increases

Engineering Contradiction:
Improvecompliance evaluation accuracyVSAvoiddata analysis system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the compliance evaluation process into distinct functional modules: PKI data capture from network traffic, extraction of relevant certificate information, validation against compliance requirements, and reporting. This segmentation reduces overall system complexity while maintaining comprehensive evaluation accuracy.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The analysis port serves as an intermediary that receives copied traffic and feeds PKI data to the compliance analysis system, separating the monitoring function from the analysis function. This intermediary architecture simplifies the data processing pipeline while enabling thorough compliance evaluation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12519770B2Intelligent certificate discovery in physical and virtualized networks
Publication Date: 2026.01.06 EDISON VAULT LLC
  • US12519770B2 patent drawing
  • US12519770B2 patent drawing
  • US12519770B2 patent drawing

AI summary

Mechanisms are provided, in a communication device associated with a first computing device, for capturing security data exchanged between the first computing device and a second computing device. The mechanisms receive a data message from either the first computing device or the second computing device. The data message is part of an operation for establishing a secure communication connection between the first computing device and the second computing device. The mechanisms filter the received data message for security data passed in the received data message and mirror the security data to an analysis port of the communication device. Moreover, the mechanisms output, via the analysis port, the security data to a data collection and analysis system that analyzes the security data with regard to security requirement compliance.