Manager-Agent Certificate Verification for Secure Device Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing device management systems do not adequately address the need for certificate verification during communication between a manager and an agent, which is crucial for enhancing security, especially when they operate on different hosts.

Innovation Solution

Implementing a verification mechanism in both the manager and agent to determine whether to perform certificate verification based on registered certificates and settings, ensuring secure encrypted communication by verifying server certificates when necessary.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If certificate verification is performed between manager and agent, then communication security is enhanced, but system complexity increases

Engineering Contradiction:
Improvecommunication securityVSAvoidverification mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by having the manager and agent perform certificate verification before establishing encrypted communication. The verification setting is determined in advance based on registered certificates, and certificate acquisition and verification are performed before actual data transmission begins, ensuring security is established proactively rather than reactively

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms where the manager and agent exchange verification settings and certificate information bidirectionally. The verification unit in each component receives certificate information from the other component and adjusts verification behavior accordingly, creating a feedback loop that ensures mutual authentication and proper security configuration

Inventive Principle:
Principle #23Feedback

2Reliability

If certificate verification is performed for agent, then impersonation prevention is improved, but communication overhead increases

Engineering Contradiction:
Improveimpersonation preventionVSAvoidcommunication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs certificate verification as a preliminary action before actual data transmission begins. The verification setting is determined in advance based on registered certificates, and all certificate exchange and validation occurs during the connection establishment phase rather than during ongoing data communication, minimizing impact on data transmission time

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies local quality by implementing certificate verification selectively based on the specific verification setting for each component pair. Not all communications require full certificate verification - the system determines the appropriate verification level locally for each manager-agent connection based on their registered certificates and security requirements, avoiding unnecessary verification overhead in lower-risk scenarios

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20260019283A1Device management system, manager, control method for manager, and recording medium
Publication Date: 2026.01.15 CANON KK
  • US20260019283A1 patent drawing
  • US20260019283A1 patent drawing
  • US20260019283A1 patent drawing

AI summary

In a device management system comprising a manager that manages a network device and an agent that relays communication between the manager and the network device, the manager comprises a setting unit that sets a verification setting indicating whether to perform verification of a certificate of the agent when performing encrypted communication with the agent; and a verification unit that performs verification of a certificate by determining whether to perform verification of the certificate of the agent when performing encrypted communication with the agent, based on a certificate registered in the manager and the verification setting, and the agent comprises a verification unit that performs verification of a certificate by determining whether to perform verification of the certificate of the manager when performing encrypted communication with the manager, based on a certificate registered in the agent.