Network Access Certificate Issuance via Attribute Matching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for user authentication in computer networks lack a precise method to verify identity, leading to issues such as redundant account creation, password management problems, and increased costs due to inefficient single sign-on solutions that often require middle tiers or proxy systems, which are impractical in certain scenarios.

Innovation Solution

A method and system that provide digital certificates for network access by querying a first system for user attributes matching predefined criteria, allowing direct interaction without a middle tier, and issuing certificates with specific characteristics tailored to each network or application, enabling granular control over access levels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional single sign-on systems are used, then user authentication is simplified, but middle tiers or proxy systems are required which increase system complexity and are impractical in certain scenarios

Engineering Contradiction:
Improveuser authenticationVSAvoidsystem architecture
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent extracts the authentication function from the traditional middle-tier architecture by implementing direct certificate-based authentication between the user's device and the network. Digital certificates containing user attributes are validated directly by the network access point, eliminating the need for complex proxy systems while maintaining simplified user authentication.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If user accounts are created for each network access, then access control is precise, but account redundancy increases leading to increased storage requirements and costs

Engineering Contradiction:
Improveaccess controlVSAvoidstored data
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent implements universal digital certificates that can be used across multiple networks and applications. A single certificate containing user attributes can be presented to multiple networks, eliminating the need to create separate accounts for each network. This maintains precise access control through attribute validation while reducing account redundancy and storage requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If digital certificates with granular access control are implemented, then security is enhanced, but certificate management and attribute validation become more complex

Engineering Contradiction:
ImprovesecurityVSAvoidcertificate management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent performs preliminary actions by pre-defining user attributes and access criteria in the digital certificate before network access is required. User attributes such as authorization levels, permitted networks, and time restrictions are embedded in the certificate during issuance. This eliminates the need for complex real-time attribute validation and certificate management during network access, simplifying the overall system while maintaining enhanced security.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9825936B2System and method for providing a certificate for network access
Publication Date: 2017.11.21 RUCKUS IP HOLDINGS LLC
  • US9825936B2 patent drawing
  • US9825936B2 patent drawing
  • US9825936B2 patent drawing

AI summary

Provided is a system and method for providing a certificate, and more specifically a certificate for network access upon a second system. The method includes, identifying a first system having at least one processor and a plurality of users, each user having at least one attribute; receiving from a third party at least one required attribute for certificate based network access; receiving from a user known to the first system a request for certificate based network layer network access to a second system having at least one processor, the request having at least one identifier; querying the first system with the at least one identifier for attributes associated with the user requesting the certificate based network layer network access to a second system; evaluating the attributes associated with the user requesting the certificate to the at least one predefined attribute; and in response to at least one attribute associated with the user requesting the certificate correlating to the at least one predefined attribute, providing from a system other than the first system, as requested by the user a certificate with at least one characteristic for certificate based network layer network access on the second system, the second system distinct from the first system. An associated system for providing a Certificate is also provided.