Certificate Manager Proxy for Secure CA Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mobile device management systems face challenges in efficiently tracking and managing certificates across client devices, particularly due to limitations in memory capabilities and the need for secure, centralized certificate management that can validate, renew, and revoke certificates while maintaining privacy.

Innovation Solution

A system comprising a certificate manager that acts as a proxy to a certificate authority, enabling secure certificate tracking, validation, renewal, and revocation by storing and managing certificates, and maintaining the certificate authority in a private network while operating on a public network, using protocols like SCEP and IPSEC for certificate issuance and management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If certificates are stored and managed directly on client devices with limited memory, then certificate management is decentralized and accessible, but memory capacity is insufficient and security is compromised

Engineering Contradiction:
Improvecertificate storage capacityVSAvoidcertificate management security
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The patent introduces a certificate manager as an intermediary component that mediates between client devices and the certificate authority. The certificate manager stores certificate information centrally while providing controlled access to client devices, thus resolving the contradiction between decentralized accessibility and centralized security requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments certificate management functions into distinct components: the certificate authority that issues certificates, the certificate manager that stores and manages certificate information, and client devices that use certificates. This segmentation allows each component to have optimized capabilities without the limitations of the others.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If the certificate authority is exposed on a public network for easy access, then certificate issuance is convenient, but security and privacy of the certificate authority are compromised

Engineering Contradiction:
Improvecertificate issuance accessibilityVSAvoidcertificate authority security risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The certificate manager acts as a mediator between the public network and the certificate authority. It handles all certificate-related operations on the public network while the certificate authority remains isolated on a private network, thus providing ease of access without exposing security risks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the certificate manager function from the certificate authority itself, separating the public-facing certificate management operations from the private certificate authority. This extraction allows the certificate authority to remain secure while still providing accessible certificate services.

Inventive Principle:
Principle #2Taking out (Extraction)

3Device complexity

If manual certificate tracking is implemented without automated systems, then system complexity is reduced, but time consumption for certificate validation, renewal, and revocation increases

Engineering Contradiction:
Improvecertificate management system complexityVSAvoidcertificate operation time
Core Design Contradiction:
Device complexityVSLoss of time

Solution Approach 1:

The certificate manager implements automated feedback mechanisms by continuously monitoring certificate expiration dates and automatically initiating renewal processes. It also provides real-time tracking of certificate status, eliminating the need for manual checking and reducing time loss while maintaining manageable system complexity.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system enables self-service certificate management where the certificate manager automatically performs validation, renewal, and revocation operations without requiring manual intervention. This automation significantly reduces time consumption while the modular design keeps system complexity manageable.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10805091B2Certificate tracking
Publication Date: 2020.10.13 SAP SE
  • US10805091B2 patent drawing
  • US10805091B2 patent drawing
  • US10805091B2 patent drawing

AI summary

Disclosed herein are system, method, and computer program product embodiments for certificate tracking. An embodiment operates by a computer implemented method that includes receiving, by at least one processor of a certificate manager, a first request from a client device and sending a second request for a root certificate to a certificate authority. The method further includes receiving the root certificate from the certificate authority and sending a third request to the certificate authority for one or more additional certificates. The method further includes receiving the one or more additional certificates from the certificate authority and storing the root certificate and the one or more additional certificates. The certificate manager and the certificate authority can be located on different networks.