Network Address Domain Graphs for Wildcard-Free Certificates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional certificate management systems use wildcard entries to accommodate multiple domains and subdomains, which introduce security vulnerabilities, compliance issues, and inefficiencies in managing domain relationships, especially in complex network environments with CDN proxies.

Innovation Solution

A certificate management system generates a graph representing relationships between access points and domains, subdomains, origin servers, and proxies, creating individual entries for each domain and subdomain without wildcard entries, and continuously updates certificates based on changes in domain relationships.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If wildcard entries are used to represent multiple domains or subdomains in a certificate, then the certificate can accommodate multiple domains, but security vulnerabilities and compliance issues are introduced

Engineering Contradiction:
Improvecertificate domain coverageVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent divides the certificate into multiple separate certificates, each dedicated to a specific domain or subdomain. Instead of using a single certificate with wildcard entries to cover multiple domains, the system creates individual certificates for each domain, eliminating the security risks associated with wildcard entries while maintaining comprehensive domain coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent inverts the conventional approach by not using wildcards to represent multiple domains, but rather creating multiple specific entries to represent individual domains. This inversion of the traditional certificate management approach eliminates the need for wildcard characters and associated security concerns.

Inventive Principle:
Principle #13The other way round (Inversion)

2Ease of operation

If wildcard entries are used to represent multiple domains, then certificate management is simplified, but compliance issues arise

Engineering Contradiction:
Improvecertificate managementVSAvoidcompliance
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system segments the certificate management into domain-specific certificates, where each certificate is explicitly associated with a single domain or subdomain. This segmentation approach simplifies compliance management by eliminating ambiguous wildcard entries and ensuring clear, unambiguous domain-certificate mappings that are easier to audit and manage.

Inventive Principle:
Principle #1Segmentation

3Reliability

If individual entries are created for each domain and subdomain, then security is enhanced, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidcertificate management system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a certificate management system that automatically generates, manages, and updates domain-specific certificates without requiring manual intervention. The system self-manages the complexity of creating and maintaining multiple individual certificates, automatically handling domain additions, removals, and updates while maintaining security through individual domain entries.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent creates a universal certificate management system that handles multiple domains and subdomains through a standardized process. The same system architecture and management approach work for all domains, providing multi-functionality that reduces overall system complexity despite the increased number of individual certificates.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Productivity

If certificates are continuously updated based on domain relationship changes, then data traffic management efficiency is improved, but system complexity increases

Engineering Contradiction:
Improvedata traffic management efficiencyVSAvoidcertificate update mechanism
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements a feedback mechanism where the system continuously monitors domain relationship changes and automatically triggers certificate updates in response. This feedback loop ensures that certificates remain current with domain configurations, improving data traffic management efficiency by ensuring accurate and up-to-date certificate information without requiring manual intervention.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary actions by proactively monitoring for domain relationship changes and preparing certificate updates before they are needed. This anticipatory approach ensures that certificates are updated in advance of any potential issues, maintaining efficient data traffic management while automating the update process to reduce system complexity.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP4580124A1Relationship modeling for network address domains
Publication Date: 2025.07.02 EBAY INC
  • EP4580124A1 patent drawingFigure 1
  • EP4580124A1 patent drawingFigure 2
  • EP4580124A1 patent drawingFigure 3

AI summary

Generating an access point certificate based on a graph that defines relationships between an access point and at least one domain is described. A computing device may generate a graph that defines relationships between a domain and multiple different access points including a serving access point and one or more fallback access points. A device may generate a certificate for accessing data via the domain based on the relationships between the domain and the one or more fallback access points. A device may control access to the data using the certificate. The graph may define a relationship between a network address, an access point, and one or more records associated with at least one domain. Further, the graph may define a first relationship between a network address and a record associated with a domain and a second relationship between the network address and an alias record associated with the domain.