Hierarchical Certificate-Based Connections Without Dynamic Lists
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Managing hierarchical relationships and allowed connections in computer networks is challenging due to the complexity of dynamically updating and distributing connection lists among multiple computer network devices, especially in large deployments with varying tenants and manufacturers.
Innovation Solution
Implementing a computer network device that uses certificates from certificate authorities for different layers in the network hierarchy to selectively establish connections based on tenant and MSP affiliations, eliminating the need for dynamic list updates.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a controller provides computer network devices with lists of allowed connections, then connection management is enabled, but the complexity of maintaining and distributing lists increases
Solution Approach 1:
The patent replaces the mechanical system of manual list maintenance and distribution with an automated certificate-based authentication system. Instead of controllers manually providing and updating connection lists, the system uses certificate authorities to issue digital certificates that automatically enable devices to verify allowed connections without intervention.
Solution Approach 2:
The patent implements self-service by enabling computer network devices to autonomously verify connection permissions using their own private keys and the public key infrastructure. Devices independently authenticate each other through certificate validation without requiring continuous controller intervention or manual list updates.
2Adaptability or versatility
If controllers dynamically update connection lists, then adaptability to changing networks is improved, but time and resources for management increase
Solution Approach 1:
The patent applies preliminary action by having the certificate authority pre-issue and distribute digital certificates to all authorized devices before they need to connect. This advance preparation eliminates the need for real-time list updates, as devices already possess the authentication credentials needed for future connections.
Solution Approach 2:
The system replaces dynamic mechanical list updates with a static certificate-based verification mechanism. Once certificates are issued and distributed, the authentication system automatically adapts to network changes without requiring manual redistribution of connection lists.
3Area of stationary object
If connection lists are distributed to multiple devices, then network coverage is expanded, but the complexity of ensuring consistent updates increases
Solution Approach 1:
The patent introduces a certificate authority as an intermediary that centrally manages and issues digital certificates to all devices. This intermediary ensures consistent authentication across the entire network by controlling the distribution of cryptographic credentials, eliminating the complexity of coordinating direct peer-to-peer list updates.
Solution Approach 2:
The patent implements universality through a single certificate authority infrastructure that serves all devices across the entire network. The same certificate-based mechanism universally handles authentication for all connection types and devices, simplifying management compared to device-specific connection lists.
Data Source
AI summary
A computer network device that implements a data plane is described. During operation, the computer network device may receive, associated with a second computer network device, a request to establish a connection, where the request includes an instance of a first type of certificate associated with a first certificate authority for a first layer in a hierarchy in the network, and/or an instance of a second type of certificate associated with a second certificate authority for a second layer in the hierarchy, where the first layer is lower in the hierarchy than the second layer. Then, the computer network device may selectively establish a connection in the network with the second computer network device based at least in part on the instance of the first type of certificate and/or the instance of the second type of certificate.


