Cloud Certificate Authority Management System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing a public key infrastructure (PKI) that uses third-party certificate authorities is resource-intensive and complex, especially when multiple authorities are involved, making it difficult for entities to securely generate and manage digital certificates.

Innovation Solution

A system and method for entities to generate and manage private certification authorities, allowing them to create, issue, and revoke certificates securely, with features like user interfaces for inputting information, generating keys, and setting policies, as well as providing audit reports and certificate revocation lists.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If entities use third-party certificate authorities to generate digital certificates, then certificate issuance is simplified, but managing public key infrastructure requires a great amount of computing resources and becomes difficult when multiple authorities are involved

Engineering Contradiction:
Improveease of certificate managementVSAvoidcomplexity of public key infrastructure
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces a cloud-based certificate authority service as an intermediary between entities and the public key infrastructure. This mediator handles the complexity of managing multiple certificate authorities, hierarchical structures, and certificate lifecycle operations remotely, allowing entities to obtain digital certificates without directly managing the complex PKI infrastructure themselves

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If entities use multiple certificate authorities in a hierarchy, then security and trust are enhanced, but managing the public key infrastructure requires a great amount of computing resources

Engineering Contradiction:
Improvesecurity and trust of digital certificatesVSAvoidcomputing resources required for management
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts the computationally intensive tasks of managing hierarchical certificate authorities from entity systems and relocates them to a cloud-based service. The extraction includes generating and managing root and intermediate certificate authorities, maintaining certificate revocation lists, and handling certificate validation, thereby reducing the computing resources required at entity premises while preserving the security benefits of multi-authority hierarchies

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If entities manage their own private certification authorities, then control and security are improved, but the complexity of generating and managing certificate authorities increases

Engineering Contradiction:
Improvesecurity control of certificate authoritiesVSAvoidcomplexity of certificate authority management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a self-service model where entities can independently generate and manage their own private certificate authorities through automated cloud-based services. The system provides self-service capabilities for creating hierarchical certificate authority structures, issuing certificates, and managing revocation without requiring entities to manually configure complex security infrastructure, thereby maintaining security control while reducing operational complexity

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11533185B1Systems for generating and managing certificate authorities
Publication Date: 2022.12.20 AMAZON TECH INC
  • US11533185B1 patent drawing
  • US11533185B1 patent drawing
  • US11533185B1 patent drawing

AI summary

Systems and method for generating and managing certificate authorities. For instance, a certificate service may provide one or more user interfaces for creating certificate authorities, such as a root certificate authority, a subordinate certificate authority, and/or an intermediate certificate authority. For example, a user may use a user device to create a certificate hierarchy. The certificate service may also provide one or more user interfaces for issuing certificates using the certificate authorities. One or more computing resources may then use the end-entity certificates issued from the certificate authority hierarchy for authentication and/or encryption. For security purposes, the certificate authority may also allow the user to set policies representing users that are able to access and/or utilize the certificate authorities to perform actions, such as issuing certificates. The certificate service may also generate audit reports indicating certificates that are created using the certificate authorities.