Hierarchical Work Tree for Asynchronous Certificate Configuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional cloud-based management solutions for Mobile Device Management (MDM) face limitations in scalability, security, IT administrator experience, end user experience, and developer experience, including increased latency, decreased reliability, and inefficiencies in certificate management, leading to redundant work and potential access issues.

Innovation Solution

The solution involves configuring devices to have certificates through asynchronous work requests, using a hierarchical work tree to order and execute tasks, ensuring reliable certificate delivery, tracking, and renewal, while centralizing processing in a single Certificate Management Service to streamline operations and enhance security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional cloud-based management solutions use multiple services for certificate management, then functionality is provided, but latency increases and reliability decreases

Engineering Contradiction:
Improvecertificate delivery reliabilityVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple certificate management services into a single unified service. This consolidation eliminates the reliability issues and latency problems caused by multiple distributed services while maintaining all necessary certificate management functionalities in one integrated system.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The unified certificate management service provides universal functionality by handling multiple certificate operations (issuance, renewal, revocation, tracking) within a single service architecture, replacing the need for multiple specialized services and improving both reliability and reducing complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Productivity

If iterative brute force techniques are used to configure device certificates, then certificate configuration is achieved, but redundant work is performed and computational resources are consumed

Engineering Contradiction:
Improvecertificate configuration efficiencyVSAvoidcomputational resource consumption
Core Design Contradiction:
ProductivityVSLoss of energy

Solution Approach 1:

The system performs preliminary actions by pre-planning and ordering certificate configuration tasks before execution. This allows the system to avoid redundant computational work by determining the exact sequence of operations needed, eliminating brute force retry mechanisms and reducing overall computational resource consumption.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms that track the state of certificate configuration tasks and provide visibility into why performance operations may be failing. This feedback loop allows the system to adjust its approach and avoid redundant work by learning from previous attempts and understanding the root causes of failures.

Inventive Principle:
Principle #23Feedback

3Reliability

If heuristics are used to determine certificate renewal timing, then automated renewal is attempted, but end users may lose access due to delays or failures

Engineering Contradiction:
Improvecertificate renewal reliabilityVSAvoidcertificate renewal timing accuracy
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system uses feedback mechanisms to monitor certificate expiration timelines and automatically initiate renewal processes at appropriate intervals. This feedback-driven approach replaces unreliable heuristics with a systematic method that tracks certificate states and triggers renewals based on actual timing requirements, preventing user access loss.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary renewal actions by initiating certificate renewal processes before certificates actually expire. This preliminary action ensures that renewals are completed in advance, eliminating the risk of user access loss that occurs when heuristic-based timing fails to account for processing delays or failures.

Inventive Principle:
Principle #10Preliminary action

4Adaptability or versatility

If conventional solutions are used for certificate lifecycle management, then basic management is provided, but control over lost devices or departed employees is lost

Engineering Contradiction:
Improvecertificate lifecycle controlVSAvoidcertificate revocation reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The unified certificate management service implements comprehensive feedback mechanisms that track certificate states throughout their entire lifecycle. This enables reliable revocation and control actions when devices are lost or employees depart, as the system maintains continuous visibility and control over all certificate operations rather than relying on incomplete conventional solutions.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP4150856B1Configuring a device to have certificate(s) by ordering asynchronous work requests
Publication Date: 2024.04.17 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP4150856B1 patent drawingFigure 1
  • EP4150856B1 patent drawingFigure 2
  • EP4150856B1 patent drawingFigure 3

AI summary

Techniques are described herein that are capable of configuring a device to have certificate(s) by ordering asynchronous work requests. Portions of work that are to be performed to configure a device to have certificate(s) are performed based at least in part on a triggering event that indicates that the device is to be configured. Asynchronous work requests that are configured to, when executed, initiate performance of the respective portions of the work are generated. A hierarchical work tree that includes hierarchical nodes that represent the respective portions of the work is generated. The hierarchical work tree defines an order in which the portions of the work are to be performed. The asynchronous work requests are executed in the order defined by the hierarchical work tree, which initiates creation of the certificate(s) and delivery of the certificate(s) to the device.