Digital Certificate Subscription Model for Automated Renewal

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing process for deploying and renewing digital certificates is time-consuming and repetitive, requiring frequent authentication and verification processes, which burdens both certificate authorities and users, and is dependent on the certificate's validity period.

Innovation Solution

Implementing a subscription model that issues long-lived digital certificates, valid for several years, with periodic authentication and verification checks, and automatic payment processing, reducing the need for frequent renewal actions and breaking the dependency on the validity period.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If digital certificates are issued with short validity periods requiring frequent renewal, then security is maintained through regular authentication, but the renewal process becomes repetitive and time-consuming

Engineering Contradiction:
ImprovesecurityVSAvoidrenewal time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs authentication and verification actions in advance before the certificate expires, allowing the certificate to be automatically renewed without requiring user intervention at the moment of expiration. The system proactively reaches out to the subscriber for authentication before the renewal deadline, thus resolving the contradiction by maintaining security through pre-authentication while eliminating time loss from repetitive renewal processes.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables automatic certificate renewal where the infrastructure itself handles the renewal process without requiring manual user action for each renewal cycle. The subscriber provides authentication credentials once, and the system automatically manages subsequent renewals, maintaining security through periodic authentication while eliminating the repetitive manual renewal process that consumes time.

Inventive Principle:
Principle #25Self-service

2Reliability

If full payment is required upfront for digital certificates, then certificate authorities receive immediate compensation, but users face high initial costs and must repeat the payment process at each renewal

Engineering Contradiction:
Improvepayment assuranceVSAvoidpayment convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent divides the certificate payment into periodic installments rather than requiring full upfront payment. The subscriber pays a portion of the certificate cost initially, with the remainder paid in periodic installments over the certificate's validity period. This segmentation resolves the contradiction by providing payment assurance through structured installment collection while dramatically improving payment convenience by spreading costs over time rather than requiring large upfront payments at each renewal.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements periodic payment collection where installments are automatically deducted at regular intervals during the certificate's validity period. This periodic action maintains payment assurance through systematic collection while improving ease of operation by automating the payment process and eliminating the need for users to manually repeat full payment at each renewal cycle.

Inventive Principle:
Principle #19Periodic action

3Reliability

If multiple authentication and verification steps are performed at each renewal, then certificate validity is ensured, but the renewal process becomes complex and burdensome

Engineering Contradiction:
Improveauthentication accuracyVSAvoidrenewal process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs authentication and verification steps in advance before the certificate expires, allowing the subscriber to complete all necessary security checks beforehand. This preliminary action resolves the contradiction by ensuring authentication accuracy through complete verification while reducing renewal process complexity by eliminating the need to repeat multiple authentication steps at the moment of renewal.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system automatically manages the authentication and verification process, reducing the burden on users. Once the subscriber provides initial authentication credentials, the system handles subsequent verification steps automatically, maintaining authentication accuracy while simplifying the renewal process by eliminating manual intervention in repetitive verification steps.

Inventive Principle:
Principle #25Self-service

4Reliability

If certificates are renewed annually or biennially, then security is maintained through periodic validation, but users must repeatedly go through the entire renewal process

Engineering Contradiction:
Improvesecurity validationVSAvoidrenewal efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system initiates authentication and verification processes before the certificate expires, allowing renewal preparations to be completed in advance. This preliminary action resolves the contradiction by maintaining security validation through periodic authentication while improving renewal efficiency by preventing the need for rushed or repeated renewal actions at expiration.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system automatically manages certificate renewal operations, performing validation and extension without requiring user intervention at each renewal cycle. This self-service approach maintains security validation through automated periodic checks while dramatically improving renewal efficiency by eliminating repetitive manual renewal processes.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9794248B2Alternative approach to deployment and payment for digital certificates
Publication Date: 2017.10.17 DIGICERT INC
  • US9794248B2 patent drawing
  • US9794248B2 patent drawing
  • US9794248B2 patent drawing

AI summary

A method for managing payment of digital certificates includes receiving a request to issue a digital certificate to a subscriber, capturing and saving payment information of the subscriber, performing a first authentication and verification of the subscriber at a first time, and performing at least one additional authentication and verification of the subscriber at least once every authentication period. A long-lived certificate is issued to the subscriber provided the subscriber is authenticated and verified. The long-lived certificate is valid for an expiration period. However, the long-lived certificate is revoked if (1) the additional authentications and verification produce invalid results, or (2) if payment is not received during a payment period. The authentication period is shorter than the expiration period and there are at least a first and a second authentication period within the expiration period. The expiration period is longer than the authentication period.