Portable Certificate Management Apparatus for Secure Device Updates
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In installations without a communication connection to a registration authority or certification authority, the frequent visits required for certificate updating and management are inefficient, as they necessitate multiple trips by service engineers to check and install new operative certificates.
Innovation Solution
A computer apparatus that establishes a connection with a device to transmit a certificate valid for a first time period, receives a further certificate request for a second time period, and breaks the connection, allowing for subsequent retrieval of the new certificate from the certification authority, thereby reducing the need for direct communication with the certification authority and minimizing on-site visits.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Extent of automation
If the device is directly connected to the certification authority for certificate updates, then certificate management can be automated, but the device must remain connected to public networks which compromises security
Solution Approach 1:
The portable computer acts as an intermediary between the certification authority and the device. It establishes a temporary connection to the certification authority to download certificates, then transmits them to the device through a separate coupling process, eliminating the need for the device to directly connect to public networks.
Solution Approach 2:
The certificate management process is segmented into distinct phases: (1) The portable computer connects to the certification authority to obtain certificates, (2) The portable computer couples to the device to transmit certificates, (3) The connection is broken after transmission. This segmentation allows automated certificate management while maintaining security by decoupling the device from public networks.
2Reliability
If service engineers visit the installation frequently for certificate updates, then certificates can be kept current, but the number of visits and time required increases
Solution Approach 1:
The device is enabled to autonomously generate certificate requests and receive certificates through the portable computer without requiring service engineer intervention for each update. The system performs self-service certificate management by allowing the device to initiate certificate requests and receive updates through the intermediary portable computer.
Solution Approach 2:
The portable computer retrieves certificates from the certification authority in advance before coupling to the device. This preliminary action allows certificates to be prepared and ready for transmission, reducing the time required during actual device updates and minimizing the need for frequent service engineer visits.
3Productivity
If the connection between the computer apparatus and the device remains established for multiple operations, then multiple certificates can be transmitted in one session, but the connection remains open longer potentially exposing security risks
Solution Approach 1:
The system uses periodic, time-limited coupling sessions between the portable computer and the device. Each coupling establishes a temporary connection for certificate transmission, then the connection is broken. This periodic action allows multiple certificates to be transmitted in organized sessions while limiting exposure time by systematically closing connections after each transmission cycle.
Data Source
AI summary
A computer apparatus for transmitting a certificate to a device in an installation is provided. The computer apparatus has a coupling unit for establishing and breaking a connection between the computer apparatus and the device, a processing unit for transmitting a certificate to the device by means of the established connection, wherein the certificate is valid for a first time period and is issued by a certification authority based on a certificate request, and a receiving unit for receiving a further certificate request from the device by means of the established connection, wherein the further certificate request is designed to request a certificate for a second time period, wherein the coupling unit is designed to break the connection after the certificate is transmitted and the further certificate request is received.
