Certificate Distribution Device Security Level Selection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for distributing certificates and private keys to multiple devices over a network face challenges in achieving both efficiency and security, particularly when using a certificate distribution server that requires network connectivity between the user terminal and the server.

Innovation Solution

A certificate distribution device connected to multiple device groups via a network, which displays a selection screen for users to choose devices and their security levels, allowing secure and efficient distribution of certificates and private keys to selected devices over the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If certificates and private keys are distributed via network using a certificate distribution server, then distribution efficiency is improved, but security is worsened due to network connectivity requirements

Engineering Contradiction:
Improvedistribution efficiencyVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies local quality by differentiating security requirements across devices through security levels. Each device is assigned a specific security level (first, second, or third) based on its security integrity, and the certificate distribution server selectively distributes certificates according to these localized security requirements rather than applying a uniform security approach to all devices

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent changes the security parameter by introducing security levels as a variable attribute. The certificate distribution server modifies its distribution behavior based on the security level parameter of each device, allowing efficient network-based distribution to high-security-integrity devices while blocking distribution to low-security-integrity devices, thus resolving the contradiction between distribution efficiency and security

Inventive Principle:
Principle #35Parameter changes

2Reliability

If direct installation using physical medium is used, then security is improved, but distribution efficiency deteriorates when large number of devices are involved

Engineering Contradiction:
ImprovesecurityVSAvoiddistribution efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent introduces a certificate distribution server as an intermediary between the physical medium and multiple devices. The server receives certificates from a certificate authority, evaluates device security integrity, and selectively distributes certificates via network to devices meeting security requirements. This intermediary approach eliminates the need for physical medium installation while maintaining security through automated evaluation and selective distribution

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9363246B2Certificate distribution device and method for same, and computer program
Publication Date: 2016.06.07 ALAXALA NETWORKS
  • US9363246B2 patent drawing
  • US9363246B2 patent drawing
  • US9363246B2 patent drawing

AI summary

Distribution of a certificate and a private key via a network includes a certificate/private key storage unit by which a certificate and a private key prepared for distribution to one or more devices are stored; a security level storage unit by which a security level for each device belonging to a device group is stored; and a display/instruction unit by which a selection screen prompting a user to select one or more devices from the device group is displayed. An instruction for the selection made by the user is received; and a certificate/private key distribution unit by which, via the network, the certificate and the private key for each device are distributed to the one or multiple devices for which the instruction for selection was made. For each device, the selection screen displays the device security level.