LAN Server Automated Certificate Issuance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for delivering and authenticating trusted security certificates in computer systems often require secondary channels, which can be cumbersome and lack automation, especially for two-way authentication within local area networks.

Innovation Solution

A local area network server issues security certificates to client devices through a network transaction, using a self-signed or trusted security certificate for automated two-way authentication and encryption, eliminating the need for secondary authentication mechanisms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security certificates are delivered through secondary channels (postal mail, courier), then certificate authentication reliability is improved, but device complexity and operational ease deteriorate due to manual delivery processes

Engineering Contradiction:
Improvecertificate authentication reliabilityVSAvoiddelivery process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces the mechanical secondary channel delivery system (postal mail, courier) with an electronic network-based certificate issuance system. The server automatically generates and transmits certificates through network transactions, eliminating the need for physical delivery mechanisms while maintaining authentication reliability through cryptographic verification.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The server automatically issues certificates to client devices through network transactions without requiring manual intervention from certificate authorities or physical delivery. The system performs self-service certificate issuance and verification, where the server both issues and validates certificates through automated network-based authentication processes.

Inventive Principle:
Principle #25Self-service

2Productivity

If automated network-based certificate issuance is implemented, then productivity and ease of operation are improved, but certificate trust verification becomes more difficult

Engineering Contradiction:
Improvecertificate issuance efficiencyVSAvoidcertificate trust verification difficulty
Core Design Contradiction:
ProductivityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements a feedback mechanism where the server verifies client device identities through network transactions before issuing certificates. The server receives authentication requests, verifies device identities, and provides feedback by issuing certificates only to verified devices. This automated feedback loop maintains trust verification while enabling efficient certificate issuance.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The server acts as an intermediary between client devices and the certificate validation process. It mediates the authentication by verifying device identities and issuing certificates that serve as trusted intermediaries for future communications, simplifying the trust verification process while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If self-signed or trusted certificates are used on the server, then adaptability is improved, but measurement precision of certificate authenticity deteriorates

Engineering Contradiction:
Improvecertificate type flexibilityVSAvoidcertificate authenticity verification precision
Core Design Contradiction:
Adaptability or versatilityVSMeasurement precision

Solution Approach 1:

The patent allows the server to use different certificate types (self-signed or trusted certificates) as configurable parameters. The system adapts to different security requirements by changing the certificate authenticity parameter, where self-signed certificates provide adaptability for various deployment scenarios while trusted certificates provide higher authenticity verification precision when available.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9281947B2Security mechanism within a local area network
Publication Date: 2016.03.08 MICROSOFT TECHNOLOGY LICENSING LLC
  • US9281947B2 patent drawing
  • US9281947B2 patent drawing
  • US9281947B2 patent drawing

AI summary

A local area network server may issue security certificates to client devices on the network for two-way authentication across the network. The certificates may be issued through a transaction performed over the network and, in some cases, may be automated. The server may have a self signed or a trusted security certificate which may serve as a basis for issuing certificates to various clients. After a certificate is issued, future communications on the network may be authenticated by both the server and client, and the communications may be encrypted using the certificates.