Digital Security Certificate Platform Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional public key infrastructure (PKI) implementations for digital security certificates face challenges in scalability, manageability, and risk mitigation, especially in distributed computing and cloud services, leading to cumbersome manual processes and increased risks of encryption key compromise and service outages.

Innovation Solution

A digital security platform that provides a layer of abstraction over multiple distributed and dissimilar PKI providers, intelligently routing certificate requests based on availability, load, region, cost, and specific requirements, allowing for dynamic selection and distribution of certificate issuance tasks among multiple certificate authorities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual processes are used for certificate issuance, then certificate authorities can be managed individually, but the process becomes cumbersome and slow

Engineering Contradiction:
Improvecertificate issuance processVSAvoidcertificate issuance speed
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The patent introduces an intermediary system that sits between users and multiple certificate authorities, automatically managing the certificate issuance process. This intermediary receives requests, evaluates them against criteria, selects appropriate CAs, and coordinates issuance, thereby eliminating manual processes while maintaining individual CA management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service certificate issuance by allowing users to submit requests that are automatically processed through evaluation criteria and routed to appropriate certificate authorities without manual intervention. The automated workflow includes request processing, CA selection, and certificate delivery, significantly improving issuance speed.

Inventive Principle:
Principle #25Self-service

2Device complexity

If wildcard certificates are used to reduce the number of certificates, then management complexity decreases, but breach scope increases

Engineering Contradiction:
Improvecertificate management complexityVSAvoidbreach scope
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the certificate management process by issuing individual certificates for specific services and domains rather than using wildcard certificates. This segmentation limits the scope of potential breaches to individual certificates while maintaining manageable complexity through automated processes.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system changes the parameter of certificate scope from broad (wildcard) to specific (individual), while compensating for the increased number of certificates through automated management capabilities that reduce operational complexity.

Inventive Principle:
Principle #35Parameter changes

3Ease of manufacture

If self-signed certificates are used temporarily, then deployment is simplified, but security trust is reduced

Engineering Contradiction:
Improvecertificate deploymentVSAvoidsecurity trust
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent implements preliminary actions by pre-configuring evaluation criteria and pre-establishing relationships with multiple certificate authorities. This allows the system to quickly issue trusted certificates without temporary self-signed certificates, simplifying deployment while maintaining security trust from the outset.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If reliance on single vendors is reduced, then risk mitigation improves, but system complexity increases

Engineering Contradiction:
Improverisk mitigationVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal system that can work with multiple certificate authorities through standardized interfaces and evaluation criteria. This multi-functional architecture manages complexity by providing a unified approach to working with diverse CAs, improving risk mitigation without proportionally increasing system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system changes the parameter of vendor diversity from a complexity burden to a managed feature by introducing evaluation criteria and automated selection mechanisms that standardize interactions with multiple certificate authorities.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10320570B2Digital security certificate selection and distribution
Publication Date: 2019.06.11 MICROSOFT TECHNOLOGY LICENSING LLC
  • US10320570B2 patent drawing
  • US10320570B2 patent drawing
  • US10320570B2 patent drawing

AI summary

Systems, apparatuses, services, platforms, and methods are discussed herein that provide digital security services and enhance digital security certificate issuance for communication systems. In one example, a digital security platform is presented that includes a client interface service configured to receive requests for digital security certificates from one or more requesting entities. The digital security platform includes a certificate service configured to process the requests against evaluation criteria to select certificate authorities to handle the requests, and handler processes configured to interface with associated ones of the selected certificate authorities for issuance and delivery of the digital security certificates.