Dynamic Certificate Management for Network Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Managing certificates and authenticators in computerized networks is challenging due to the presence of unused or expired certificates, long-lasting connections, and the complexity of virtualized environments and cloud computing, which can lead to security vulnerabilities and difficulties in controlling access rights.
Innovation Solution
An intermediate device is introduced to monitor and manage access requests, obtain authenticators, and control communications by acting as an intermediate node between user devices and hosts, providing authentication, monitoring, and auditing functions, including the ability to set conditions on authenticator usage and revoke access as needed.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If certificates are issued with long validity periods or no expiry, then certificate management complexity is reduced, but security risk increases due to unused or expired certificates remaining valid
Solution Approach 1:
The patent applies dynamics by making certificate validity dynamic rather than static. Connection certificates are issued with limited validity periods and are automatically revoked when connections close, whereas authentication certificates maintain longer validity for user identification. This dynamic approach balances management simplicity with security by ensuring certificates expire or are revoked based on their usage context.
Solution Approach 2:
The patent segments certificate functionality into two distinct types: authentication certificates for identifying users and connection certificates for securing communications. Each type has different validity characteristics - authentication certificates have longer validity while connection certificates have short, connection-bound validity. This segmentation allows tailored management strategies for each certificate type, reducing overall management complexity while maintaining security.
2Duration of action of moving object
If connections are kept open for long periods, then service continuity is improved, but security vulnerability increases due to potential unauthorized access
Solution Approach 1:
The patent applies dynamics by making connection certificates transient and connection-bound rather than persistent. Connection certificates are issued for the duration of a specific connection and are automatically revoked when the connection closes. This dynamic approach allows connections to be maintained as long as needed while ensuring that each connection has its own limited-validity certificate, reducing the risk of unauthorized access through expired or revoked certificates.
3Manufacturing precision
If multiple types of authenticators are used for different host types, then access control precision is improved, but device complexity increases
Solution Approach 1:
The patent segments authenticator functionality into distinct types: authentication certificates for user identification and connection certificates for communication security. It further segments connection certificates by host type (legacy vs. cloud), with each type using appropriate authentication mechanisms (password-based or public key). This segmentation enables precise access control for different scenarios while providing structured management through an intermediary device that handles the complexity of selecting and managing appropriate authenticators.
Solution Approach 2:
The patent introduces an intermediary device that acts as a mediator between users and hosts, managing the complexity of multiple authenticator types. The intermediary device stores both authentication and connection certificates, handles certificate issuance and revocation, and selects appropriate authenticators based on host type and connection requirements. This intermediary absorbs the management complexity while enabling precise access control through tailored certificate usage.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Apparatuses and methods for authenticating a user to a host by an agent are disclosed. In the method the agent receives a connection request to the host from the user. In response to the received connection request, the agent determines an ephemeral authenticator, and acquires using the ephemeral authenticator a second authenticator. The second authenticator is based at least in part on use of the ephemeral authenticator. The agent then authenticates the user to the host using the second authenticator.