Hierarchical Certificate-Based Connections Without Dynamic Lists

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing hierarchical relationships and allowed connections in computer networks is challenging due to the complexity of dynamically updating and distributing connection lists among multiple computer network devices, especially in large deployments with varying tenants and manufacturers.

Innovation Solution

Implementing a computer network device that uses certificates from certificate authorities for different layers in the network hierarchy to selectively establish connections based on tenant and MSP affiliations, eliminating the need for dynamic list updates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a controller provides computer network devices with lists of allowed connections, then connection management is enabled, but the complexity of maintaining and distributing lists increases

Engineering Contradiction:
Improveconnection managementVSAvoidlist maintenance and distribution
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent replaces the mechanical system of manual list maintenance and distribution with an automated certificate-based authentication system. Instead of controllers manually providing and updating connection lists, the system uses certificate authorities to issue digital certificates that automatically enable devices to verify allowed connections without intervention.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent implements self-service by enabling computer network devices to autonomously verify connection permissions using their own private keys and the public key infrastructure. Devices independently authenticate each other through certificate validation without requiring continuous controller intervention or manual list updates.

Inventive Principle:
Principle #25Self-service

2Adaptability or versatility

If controllers dynamically update connection lists, then adaptability to changing networks is improved, but time and resources for management increase

Engineering Contradiction:
Improvenetwork adaptabilityVSAvoidmanagement time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by having the certificate authority pre-issue and distribute digital certificates to all authorized devices before they need to connect. This advance preparation eliminates the need for real-time list updates, as devices already possess the authentication credentials needed for future connections.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system replaces dynamic mechanical list updates with a static certificate-based verification mechanism. Once certificates are issued and distributed, the authentication system automatically adapts to network changes without requiring manual redistribution of connection lists.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Area of stationary object

If connection lists are distributed to multiple devices, then network coverage is expanded, but the complexity of ensuring consistent updates increases

Engineering Contradiction:
Improvenetwork coverageVSAvoidconsistent update management
Core Design Contradiction:
Area of stationary objectVSDevice complexity

Solution Approach 1:

The patent introduces a certificate authority as an intermediary that centrally manages and issues digital certificates to all devices. This intermediary ensures consistent authentication across the entire network by controlling the distribution of cryptographic credentials, eliminating the complexity of coordinating direct peer-to-peer list updates.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements universality through a single certificate authority infrastructure that serves all devices across the entire network. The same certificate-based mechanism universally handles authentication for all connection types and devices, simplifying management compared to device-specific connection lists.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12368704B2Certificate-based connections reflecting a network architecture
Publication Date: 2025.07.22 RUCKUS IP HOLDINGS LLC
  • US12368704B2 patent drawing
  • US12368704B2 patent drawing
  • US12368704B2 patent drawing

AI summary

A computer network device that implements a data plane is described. During operation, the computer network device may receive, associated with a second computer network device, a request to establish a connection, where the request includes an instance of a first type of certificate associated with a first certificate authority for a first layer in a hierarchy in the network, and/or an instance of a second type of certificate associated with a second certificate authority for a second layer in the hierarchy, where the first layer is lower in the hierarchy than the second layer. Then, the computer network device may selectively establish a connection in the network with the second computer network device based at least in part on the instance of the first type of certificate and/or the instance of the second type of certificate.