Dual PKI Network Authentication Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Small organizations often lack the necessary IT expertise to effectively secure their network resources from unauthorized access, as configuring and maintaining network security competes with other demands and may introduce security vulnerabilities due to inadequate IT staffing and hasty provisioning processes.

Innovation Solution

The implementation of a dual Public Key Infrastructure (PKI) scheme, comprising a global PKI and a per-organization PKI, where certificates are issued and managed by a cloud-based authentication server, enabling secure authentication and provisioning of new client devices while allowing authorized access, even in the absence of a dedicated PKI management server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If automated provisioning is used to prepare new devices for network use, then device provisioning speed is improved, but security vulnerabilities are introduced if security policies are not properly applied

Engineering Contradiction:
Improvedevice provisioning speedVSAvoidnetwork security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

Security policies and authentication mechanisms are pre-configured and automatically applied during the device provisioning process. The system performs preliminary security checks and certificate validations before granting network access, ensuring that security measures are embedded in the provisioning workflow rather than added afterward.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

A certificate authority (CA) system acts as an intermediary between the automated provisioning system and network resources. The CA issues and manages digital certificates that authenticate devices and users, providing a security layer that mediates access control without manual intervention while maintaining automated provisioning efficiency.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive security measures are implemented to protect network resources, then network security is improved, but complexity of configuration and maintenance increases

Engineering Contradiction:
Improvenetwork securityVSAvoidsecurity configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security system operates autonomously through automated certificate management, validation, and revocation processes. The CA system self-manages security credentials without requiring manual configuration by IT staff, and the system automatically enforces security policies, reducing the complexity burden on operators while maintaining comprehensive security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Security parameters such as certificate validity periods, renewal thresholds, and revocation criteria are configured as adjustable system parameters rather than fixed complex rules. This allows security policies to be modified through simple parameter changes rather than reconfiguring entire security architectures, reducing maintenance complexity.

Inventive Principle:
Principle #35Parameter changes

3Manufacturing precision

If manual security configuration is performed to ensure proper security policy application, then security accuracy is improved, but time consumption and IT staffing requirements increase

Engineering Contradiction:
Improvesecurity policy application accuracyVSAvoidprovisioning time
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

Manual security configuration tasks are replaced by automated electronic systems that perform certificate issuance, validation, and management. The CA system electronically automates what would otherwise require manual security administrator intervention, maintaining policy application accuracy while eliminating the time consumption and staffing requirements of manual processes.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Reliability

If IT staff are allocated to handle security tasks, then security monitoring capability is improved, but availability for other user support tasks decreases

Engineering Contradiction:
Improvesecurity monitoring capabilityVSAvoiduser support availability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The security monitoring system operates autonomously through automated logging, alerting, and response mechanisms managed by the CA infrastructure. Security events are automatically detected and handled without requiring continuous IT staff attention, freeing personnel to focus on user support tasks while maintaining robust security monitoring capability.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUSRE48821E1Apparatus and methods for protecting network resources
Publication Date: 2021.11.16 POWERCLOUD SYST
  • USRE48821E1 patent drawing
  • USRE48821E1 patent drawing
  • USRE48821E1 patent drawing

AI summary

Apparatus and methods are provided for protecting network resources, particularly in association with automatic provisioning of new client devices. A global PKI (Public Key Infrastructure) scheme is rooted at a globally available server. Roots of PKIs for individual organizations also reside at this server or another globally available resource. To enable access to an organization's network, one or more authenticators are deployed, which may be co-located with access points or other network components. After a client device enabler (CDE) and an authenticator perform mutual authentication with certificates issued within the global PKI, the CDE is used to provision a new client device for the organization. After the client is provisioned, it and an authenticator use certificates issued within the per-organization PKI to allow the client access to the network.