Identity Management System Proxying Certificate Operations via Registration Authority

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing identity management systems require user intervention for certificate operations, which can be inconvenient and may compromise security due to direct access to Certificate Authorities (CAs) by clients.

Innovation Solution

An identity management system integrates a Registration Authority (RA) as a trusted manager within the CA, using Kerberos authentication to establish secure connections with clients, allowing certificate operations to be performed transparently without user intervention by proxying requests through the RA to the CA.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If user intervention is required for certificate operations, then security control is maintained, but ease of operation deteriorates

Engineering Contradiction:
Improveease of operationVSAvoidsecurity control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an identity management system as an intermediary between clients and certificate authorities. This mediator automatically performs certificate operations (requesting, renewing, revoking certificates) without requiring direct user intervention, while maintaining security through authenticated communication channels. The intermediary resolves the contradiction by automating operations that would otherwise require manual user input, thereby improving ease of operation while preserving security controls.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If direct access to Certificate Authorities is allowed, then ease of operation improves, but security deteriorates

Engineering Contradiction:
Improveease of operationVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The identity management system serves as a trusted intermediary that proxies all client requests to certificate authorities. Clients do not directly access CAs; instead, they communicate through the identity management system which validates requests and manages certificate operations. This intermediary architecture improves ease of operation by providing a unified access point while eliminating direct security risks associated with client-C A communications.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the certificate management functionality into distinct components: client agents for initiating requests, identity management system for processing and validation, and certificate authorities for issuing certificates. This segmentation isolates the security-critical CA operations from direct client access, allowing ease of operation at the client interface while maintaining security at the CA interface through the segmented architecture.

Inventive Principle:
Principle #1Segmentation

3Productivity

If automated certificate operations are implemented, then productivity improves, but device complexity increases

Engineering Contradiction:
ImproveproductivityVSAvoiddevice complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The identity management system is designed as a universal platform that handles multiple certificate operations (requesting, renewing, revoking, managing) through a single integrated system. Rather than implementing separate automated solutions for each operation, the system provides multi-functional capability, improving productivity across all certificate lifecycle events while avoiding the complexity multiplication that would result from multiple separate systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9225525B2Identity management certificate operations
Publication Date: 2015.12.29 RED HAT INC
  • US9225525B2 patent drawing
  • US9225525B2 patent drawing
  • US9225525B2 patent drawing

AI summary

A method and system for identity management certificate operations is described.