Dual PKI Network Authentication Provisioning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Small organizations often lack the necessary IT expertise to effectively secure their network resources from unauthorized access, as configuring and maintaining network security competes with other demands and may introduce security vulnerabilities due to inadequate IT staffing and hasty provisioning processes.
Innovation Solution
The implementation of a dual Public Key Infrastructure (PKI) scheme, comprising a global PKI and a per-organization PKI, where certificates are issued and managed by a cloud-based authentication server, enabling secure authentication and provisioning of new client devices while allowing authorized access, even in the absence of a dedicated PKI management server.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If automated provisioning is used to prepare new devices for network use, then device provisioning speed is improved, but security vulnerabilities are introduced if security policies are not properly applied
Solution Approach 1:
Security policies and authentication mechanisms are pre-configured and automatically applied during the device provisioning process. The system performs preliminary security checks and certificate validations before granting network access, ensuring that security measures are embedded in the provisioning workflow rather than added afterward.
Solution Approach 2:
A certificate authority (CA) system acts as an intermediary between the automated provisioning system and network resources. The CA issues and manages digital certificates that authenticate devices and users, providing a security layer that mediates access control without manual intervention while maintaining automated provisioning efficiency.
2Reliability
If comprehensive security measures are implemented to protect network resources, then network security is improved, but complexity of configuration and maintenance increases
Solution Approach 1:
The security system operates autonomously through automated certificate management, validation, and revocation processes. The CA system self-manages security credentials without requiring manual configuration by IT staff, and the system automatically enforces security policies, reducing the complexity burden on operators while maintaining comprehensive security.
Solution Approach 2:
Security parameters such as certificate validity periods, renewal thresholds, and revocation criteria are configured as adjustable system parameters rather than fixed complex rules. This allows security policies to be modified through simple parameter changes rather than reconfiguring entire security architectures, reducing maintenance complexity.
3Manufacturing precision
If manual security configuration is performed to ensure proper security policy application, then security accuracy is improved, but time consumption and IT staffing requirements increase
Solution Approach 1:
Manual security configuration tasks are replaced by automated electronic systems that perform certificate issuance, validation, and management. The CA system electronically automates what would otherwise require manual security administrator intervention, maintaining policy application accuracy while eliminating the time consumption and staffing requirements of manual processes.
4Reliability
If IT staff are allocated to handle security tasks, then security monitoring capability is improved, but availability for other user support tasks decreases
Solution Approach 1:
The security monitoring system operates autonomously through automated logging, alerting, and response mechanisms managed by the CA infrastructure. Security events are automatically detected and handled without requiring continuous IT staff attention, freeing personnel to focus on user support tasks while maintaining robust security monitoring capability.
Data Source
AI summary
Apparatus and methods are provided for protecting network resources, particularly in association with automatic provisioning of new client devices. A global PKI (Public Key Infrastructure) scheme is rooted at a globally available server. Roots of PKIs for individual organizations also reside at this server or another globally available resource. To enable access to an organization's network, one or more authenticators are deployed, which may be co-located with access points or other network components. After a client device enabler (CDE) and an authenticator perform mutual authentication with certificates issued within the global PKI, the CDE is used to provision a new client device for the organization. After the client is provisioned, it and an authenticator use certificates issued within the per-organization PKI to allow the client access to the network.


