Automated Management Tunnel Deployment via Pre-provisioned Certificates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network management systems require extensive manual configuration for establishing communication channels between network devices, involving certificate and key assignment, which is inefficient.

Innovation Solution

Pre-configuring managed and management devices with unique certificates and identifiers, allowing them to establish secure communication channels automatically based on stored authorization information, with optional encryption and authentication using public keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual configuration is used for establishing communication channels with certificates and keys, then security and authentication are ensured, but deployment efficiency and time consumption deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoiddeployment efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary actions by automatically generating certificates and cryptographic keys before the communication channel is actually needed. The management device pre-configures trusted root certificates and automatically creates device certificates, eliminating the need for manual certificate configuration during deployment.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables self-service by allowing devices to automatically generate their own cryptographic credentials and establish secure channels without human intervention. The managed device can autonomously request certificates, and the management device automatically issues and configures them, making the system self-configuring.

Inventive Principle:
Principle #25Self-service

2Reliability

If manual configuration of certificates and keys is performed, then authentication and authorization are secured, but system complexity and configuration effort increase

Engineering Contradiction:
ImproveauthenticationVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements self-service by enabling devices to automatically generate cryptographic keys and certificates, and to autonomously configure their communication channels. The management device automatically manages the certificate lifecycle, including generation, distribution, and renewal, without requiring manual configuration.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The management device acts as an intermediary that simplifies the authentication process by automatically managing certificate issuance and device registration. It mediates between the need for secure authentication and the desire for simple deployment by handling all cryptographic configuration tasks automatically.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Manufacturing precision

If extensive manual configuration is used for network device management, then proper credential assignment is achieved, but time consumption and operational efficiency worsen

Engineering Contradiction:
Improvecredential assignment accuracyVSAvoidconfiguration time
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The system performs preliminary actions by automatically generating and assigning cryptographic credentials before deployment is needed. The management device pre-configures trusted root certificates and automatically creates device-specific certificates, ensuring proper credential assignment occurs automatically rather than manually.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system replaces the mechanical manual configuration process with an automated computational system. Instead of manually copying and pasting certificates and keys, the system uses automated algorithms to generate cryptographic credentials, assign them to devices, and configure communication channels programmatically.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS8510812B2Computerized system and method for deployment of management tunnels
Publication Date: 2013.08.13 ATHENA SECURITY LLP
  • US8510812B2 patent drawing
  • US8510812B2 patent drawing
  • US8510812B2 patent drawing

AI summary

Embodiments of the present invention provide a framework for facilitating the deployment of management tunnels between management and managed devices. The tunnel may be initiated either from the management device or from the managed device. When the channel is first established, the credentials of the respective devices are verified. To this end, each of the devices may be pre-provisioned with unique identifier, as well as certificate assigned by a certificate authority together with associated private key. Upon initial setup of the tunnel, the identity of the management device may be provided by the administrator. Alternatively, the devices may be pre-configured by the manufacturer to participate in a web of trust, with each device capable to accept recommendations for an identity of the management server from the other member devices. Finally, a management device locator server may be provided to facilitate easy configuration.