Managed Device Individual Certificate Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current management systems face challenges in securely authenticating communication devices over the Internet, particularly in ensuring the integrity and confidentiality of information, as they rely on common public key certificates that lack unique IDs, making them vulnerable to spoofing and tampering.

Innovation Solution

The implementation of a managed device and management system that obtains individual certificates with unique IDs, allowing for secure communication by validating the ID sent to the managing device and generating individual public key certificates, thereby enhancing security by preventing unauthorized access and ensuring the authenticity of communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If common public key certificates are used for authentication, then communication can be established, but security is compromised due to lack of unique device identification

Engineering Contradiction:
Improveauthentication securityVSAvoidcertificate management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the certificate system by introducing individual certificates with unique device IDs that are distinct from the common public key certificate. This segmentation allows each device to be uniquely identified while maintaining the existing common certificate infrastructure, thereby improving authentication security without completely redesigning the certificate management system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds a new dimension to certificate management by introducing individual certificates as a supplementary layer to the existing common public key certificate. This dimensional addition enables unique device identification without disrupting the established certificate validation mechanism, resolving the contradiction between security improvement and system complexity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If individual certificates with unique IDs are implemented, then spoofing and tampering are prevented, but the system complexity increases

Engineering Contradiction:
Improvecommunication integrityVSAvoidcertificate validation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by pre-distributing individual certificates with unique device IDs to all devices before they engage in communication. This advance preparation ensures that devices are already equipped with their unique identifiers, eliminating the need for complex real-time certificate generation or assignment during communication establishment, thus preventing spoofing while managing system complexity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary mechanism where the managing device validates and distributes individual certificates to controlled devices. This intermediary role simplifies the overall system by centralizing certificate management responsibilities, allowing individual certificates to prevent spoofing and tampering while the managing device handles the complexity of validation and distribution.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of manufacture

If common certificates are used without unique IDs, then device deployment is simplified, but devices are vulnerable to unauthorized access

Engineering Contradiction:
Improvedevice deployment easeVSAvoidunauthorized access vulnerability
Core Design Contradiction:
Ease of manufactureVSObject-affected harmful factors

Solution Approach 1:

The patent merges the advantages of both common certificates and unique identification by combining individual certificates with unique device IDs with the existing common public key certificate infrastructure. This merging allows devices to benefit from the simplified deployment of common certificates while simultaneously gaining the security of unique identification, thus preventing unauthorized access without sacrificing deployment ease.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent achieves universality by designing a dual-certificate system where both common public key certificates and individual certificates with unique IDs coexist and work together. This multi-functional approach allows the system to maintain the broad compatibility and ease of deployment associated with common certificates while adding the security benefits of unique identification, protecting against unauthorized access across diverse device deployments.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7734910B2Managed device, management system, method for controlling a managed device and medium
Publication Date: 2010.06.08 RICOH CO LTD
  • US7734910B2 patent drawing
  • US7734910B2 patent drawing
  • US7734910B2 patent drawing

AI summary

A managed device obtains an individual certificate with an ID of the managed device when the managed device is in a direct-managed state and determines that the certificate set as the certifying information for communicating with a managing device is a common certificate without an ID of the managed device.