Digital Certificate Filtering via Intrinsic and Derived Attributes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In computing environments, conventional certificate management systems struggle to identify and provide suitable digital certificates for applications due to the variability in digital certificate suitability, which can lead to insecure communications and inefficient certificate utilization.

Innovation Solution

A digital certificate management system that generates profiles for various digital certificates by extracting intrinsic and derived attributes, compares these attributes to application requirements, and filters suitable certificates, ensuring optimal certificate selection and provision for secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If conventional certificate management systems provide all available certificates to customer systems, then certificate availability is improved, but security and efficiency deteriorate due to inappropriate certificate usage

Engineering Contradiction:
Improvecertificate availabilityVSAvoidsecurity
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The patent segments the certificate selection process by dividing certificates into different categories based on their attributes (e.g., SSL/TLS certificates, code signing certificates, email certificates) and matching them to specific application requirements. This segmentation allows the system to provide the right certificate for the right application, improving security while maintaining availability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the parameters of certificate management by introducing attribute-based filtering criteria (such as certificate type, validity period, key algorithm, and purpose) to match certificates with applications. This parameter-based approach transforms the generic certificate provision process into a precise matching process, ensuring security without compromising availability.

Inventive Principle:
Principle #35Parameter changes

2Quantity of substance

If conventional certificate management systems provide all available certificates to customer systems, then certificate availability is improved, but resource efficiency deteriorates due to unnecessary certificate processing

Engineering Contradiction:
Improvecertificate availabilityVSAvoidefficiency
Core Design Contradiction:
Quantity of substanceVSProductivity

Solution Approach 1:

The patent applies preliminary action by pre-analyzing and categorizing certificates in the certificate store according to their attributes before they are needed. When an application requests a certificate, the system can quickly filter and match from the pre-categorized options, avoiding the inefficiency of processing all certificates at request time. This maintains full certificate availability while dramatically improving efficiency.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces parameter-based filtering (changing the management approach from generic to attribute-specific) to efficiently match certificates with applications. By defining specific parameters such as certificate type, validity, and purpose, the system can rapidly filter the certificate pool without manual intervention, maintaining availability while improving productivity.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If attribute-based filtering is implemented to match certificates with applications, then security and efficiency are improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service by enabling the certificate management system to automatically analyze application requirements and match them with appropriate certificates based on predefined attributes. The system autonomously performs the filtering and selection process without requiring complex manual configuration or intervention, thereby improving security while keeping the operational complexity manageable.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent applies universality by creating a multi-functional attribute-based filtering framework that can handle various certificate types (SSL/TLS, code signing, email) and application scenarios through a single unified mechanism. This universal approach improves security across different use cases without requiring separate complex systems for each certificate type, thus limiting the increase in overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10652030B1Digital certificate filtering based on intrinsic and derived attributes
Publication Date: 2020.05.12 AMAZON TECH INC
  • US10652030B1 patent drawing
  • US10652030B1 patent drawing
  • US10652030B1 patent drawing

AI summary

A method and system for generating multiple profiles corresponding to different digital certificates. The profile includes intrinsic attributes and derived attributes associated with a digital certificate. The system enables a customer system to filter digital certificates based on a suitability of the various digital certificates for use with a given application to be executed by or on behalf of the customer system. The suitability may be determined based on a comparison of certificate requirements associated with a customer system's request and one or more of the intrinsic attributes and derived attributes.