Client-Side Certificate Validation for Trusted Network Privileges

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computer security measures for determining device connectivity to an organization's network are vulnerable to attacks and require specialized knowledge or equipment.

Innovation Solution

A computer security method involving a predefined policy to send and validate certificates signed by a certificate authority, ensuring security privileges are granted only when the device is within a trusted network, using a predefined policy to specify the certificate authority for validation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional network connectivity checking methods are used, then network access control is implemented, but security is vulnerable to attacks and requires specialized knowledge or equipment

Engineering Contradiction:
Improvenetwork securityVSAvoidspecialized knowledge and equipment requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a certificate authority as an intermediary that issues digital certificates to authorized devices. Instead of directly checking network connectivity, the system uses certificate validation as a mediator to verify device authorization, eliminating the need for specialized security equipment while maintaining high security standards.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces traditional mechanical/network connectivity checking methods with cryptographic certificate validation. Instead of using specialized hardware or complex network probing techniques, the system uses software-based public key infrastructure to verify device identities, simplifying the system while improving security reliability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If certificate validation is performed at the client side, then security is improved and specialized equipment is eliminated, but communication overhead increases

Engineering Contradiction:
Improvesecurity validationVSAvoidcertificate validation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs certificate validation as a preliminary action before granting network access or security privileges. By validating certificates upfront during the connection establishment phase, the system avoids repeated validation overhead during subsequent communications, optimizing the balance between security and performance.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20260081912A1Computer security based on client-side checking of secure computer network communications
Publication Date: 2026.03.19 ISLAND TECH INC
  • US20260081912A1 patent drawing
  • US20260081912A1 patent drawing

AI summary

A computer security method including sending a communication from a first computer to a second computer via a computer network, where the sending is performed in accordance with a predefined policy indicating an identity of the second computer in association with a predefined computer security privilege, receiving at the first computer a certificate sent from the second computer via the computer network in response to the communication, where the certificate is signed with a private key of a certificate authority, determining, responsive to receipt of the certificate at the first computer, and using a public key of the certificate authority, whether the certificate is valid, and granting the predefined computer security privilege at the first computer responsive to determining that the certificate is valid.