Managed Device Individual Certificate Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current management systems face challenges in securely authenticating communication devices over the Internet, particularly in ensuring the integrity and confidentiality of information, as they rely on common public key certificates that lack unique IDs, making them vulnerable to spoofing and tampering.
Innovation Solution
The implementation of a managed device and management system that obtains individual certificates with unique IDs, allowing for secure communication by validating the ID sent to the managing device and generating individual public key certificates, thereby enhancing security by preventing unauthorized access and ensuring the authenticity of communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If common public key certificates are used for authentication, then communication can be established, but security is compromised due to lack of unique device identification
Solution Approach 1:
The patent segments the certificate system by introducing individual certificates with unique device IDs that are distinct from the common public key certificate. This segmentation allows each device to be uniquely identified while maintaining the existing common certificate infrastructure, thereby improving authentication security without completely redesigning the certificate management system.
Solution Approach 2:
The patent adds a new dimension to certificate management by introducing individual certificates as a supplementary layer to the existing common public key certificate. This dimensional addition enables unique device identification without disrupting the established certificate validation mechanism, resolving the contradiction between security improvement and system complexity.
2Reliability
If individual certificates with unique IDs are implemented, then spoofing and tampering are prevented, but the system complexity increases
Solution Approach 1:
The patent implements preliminary action by pre-distributing individual certificates with unique device IDs to all devices before they engage in communication. This advance preparation ensures that devices are already equipped with their unique identifiers, eliminating the need for complex real-time certificate generation or assignment during communication establishment, thus preventing spoofing while managing system complexity.
Solution Approach 2:
The patent introduces an intermediary mechanism where the managing device validates and distributes individual certificates to controlled devices. This intermediary role simplifies the overall system by centralizing certificate management responsibilities, allowing individual certificates to prevent spoofing and tampering while the managing device handles the complexity of validation and distribution.
3Ease of manufacture
If common certificates are used without unique IDs, then device deployment is simplified, but devices are vulnerable to unauthorized access
Solution Approach 1:
The patent merges the advantages of both common certificates and unique identification by combining individual certificates with unique device IDs with the existing common public key certificate infrastructure. This merging allows devices to benefit from the simplified deployment of common certificates while simultaneously gaining the security of unique identification, thus preventing unauthorized access without sacrificing deployment ease.
Solution Approach 2:
The patent achieves universality by designing a dual-certificate system where both common public key certificates and individual certificates with unique IDs coexist and work together. This multi-functional approach allows the system to maintain the broad compatibility and ease of deployment associated with common certificates while adding the security benefits of unique identification, protecting against unauthorized access across diverse device deployments.
Data Source
AI summary
A managed device obtains an individual certificate with an ID of the managed device when the managed device is in a direct-managed state and determines that the certificate set as the certifying information for communicating with a managing device is a common certificate without an ID of the managed device.


