Cloud Sub-Certificate Generation for Terminal Device Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current certificate management systems in terminal devices lack efficient methods for generating and managing sub-certificates, leading to challenges in secure communication and synchronization between cloud and terminal devices.

Innovation Solution

A method and apparatus for sending and receiving sub-certificates, where the cloud acquires a root certificate, generates a target sub-certificate including a sub-certificate of a functional module, and sends it to the terminal device, enabling improved management and synchronization of sub-certificates for secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If certificate management is performed locally in terminal devices, then communication security is improved, but device complexity increases

Engineering Contradiction:
Improvecommunication securityVSAvoidcertificate issuance module
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the certificate issuance function from the terminal device and relocates it to the cloud server. The terminal device no longer needs to locally generate certificates, but instead receives pre-generated sub-certificates from the cloud, thereby reducing device complexity while maintaining communication security through cloud-managed certificates.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a cloud server as an intermediary between certificate authorities and terminal devices. The cloud server acts as a mediator that receives root certificates, generates sub-certificates, and distributes them to terminal devices, simplifying the certificate management process for terminal devices while ensuring security through centralized control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If sub-certificates are generated locally in terminal devices, then communication flexibility is improved, but management capability deteriorates

Engineering Contradiction:
Improvecommunication flexibilityVSAvoidcertificate management capability
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent implements preliminary action by having the cloud server pre-generate and distribute sub-certificates to terminal devices before they are needed for communication. This allows terminal devices to have ready-to-use certificates without needing complex local generation capabilities, improving ease of management while maintaining communication flexibility through pre-configured sub-certificates for different functional modules.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If multiple sub-certificates are managed locally, then functional module communication is improved, but synchronization difficulty increases

Engineering Contradiction:
Improvefunctional module communicationVSAvoidcertificate synchronization
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The cloud server serves as an intermediary that manages and synchronizes multiple sub-certificates for different functional modules. Instead of terminal devices managing multiple certificates locally with complex synchronization requirements, the cloud server centrally manages all sub-certificates and distributes them as needed, reducing synchronization complexity while enabling functional module communication.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11784830B2Method for sending certificate, method for receiving certificate, cloud and terminal device
Publication Date: 2023.10.10 BEIJING BAIDU NETCOM SCI & TECH CO LTD
  • US11784830B2 patent drawing
  • US11784830B2 patent drawing
  • US11784830B2 patent drawing

AI summary

A method includes acquiring a root certificate of a first node; generating a target sub-certificate based on the root certificate, where the target sub-certificate includes a first sub-certificate of a first functional module of a first application associated with the first node; and sending the target sub-certificate to a terminal device. The target sub-certificate is used for the first functional module of the first application in the terminal device communicating through the target sub-certificate. In such a manner, a capability of managing the first sub-certificate of the first functional module in the terminal device can be improved.