Network Access Certificate Verification via Device Characteristics

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems lack a precise method to authenticate users in digital spaces, leading to challenges in identifying individuals and controlling access to network resources, especially when employees use personal devices for work purposes.

Innovation Solution

A method and system that provide digital certificates for network access by verifying device characteristics and vouchers, ensuring that only authorized devices with specific criteria can access the network, thereby controlling access and preventing misuse of digital identities across different devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If digital certificates are issued to users for network access, then user authentication is improved, but device control and access scope management deteriorate

Engineering Contradiction:
Improveuser authenticationVSAvoiddevice control
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the digital certificate into multiple components: the user identity portion and the device characteristics portion. This allows the system to authenticate the user while simultaneously controlling which specific devices can access the network, resolving the contradiction between authentication reliability and device control complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent embeds device characteristics information within the digital certificate structure itself, creating a nested relationship where device control parameters are contained within the authentication certificate. This enables both user authentication and device control to be handled through a single integrated mechanism.

Inventive Principle:
Principle #7Nested doll (Nesting)

2Measurement precision

If individualized configuration is provided for each employee, then access control precision is improved, but system complexity and deployment time deteriorate

Engineering Contradiction:
Improveaccess control precisionVSAvoidsystem configuration
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent creates a universal certificate issuance process that handles multiple employee types and access levels through a single system. The certificate template mechanism allows different access configurations to be applied universally across different user groups without requiring separate manual configuration for each employee, thus maintaining precision while reducing complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements preliminary configuration through certificate templates that define access parameters in advance. These templates are prepared beforehand and can be automatically applied when certificates are issued to different employee types, eliminating the need for real-time individualized configuration and reducing deployment time while maintaining access control precision.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If digital certificates are used for network access control, then security is improved, but flexibility in device usage deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoiddevice usage flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic device characteristics verification where the certificate validation process checks device parameters at the time of access request. This allows the system to adapt to different device configurations while maintaining security, as the certificate can be validated against current device state rather than requiring static pre-configuration for each possible device scenario.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8843741B2System and method for providing a certificate for network access
Publication Date: 2014.09.23 RUCKUS IP HOLDINGS LLC
  • US8843741B2 patent drawing
  • US8843741B2 patent drawing
  • US8843741B2 patent drawing

AI summary

Provided is a system and method for providing a certificate, and more specifically a certificate for network access upon a second system. The method includes receiving from a user a request made with a first device for network access, the request including a voucher. At least one characteristic of the first device is also determined. Upon verification of the voucher and in response to the first device having at least one characteristic corresponding to at least one predefined device criteria, the user is provided with a certificate with at least one characteristic for network access. An associated system for providing a Certificate is also provided.