Network Appliance Time Setting via Certificate Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network appliances fail to establish secure connections with time servers due to incorrect time settings, which are not recognized by HTTPS proxies, leading to authentication failures and impaired functionality.

Innovation Solution

A method where a network appliance uses time data from its identity certificate to set a preliminary time, allowing it to authenticate with an HTTPS proxy and subsequently request an accurate time from a time server, thereby resolving the authentication issue.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the network appliance uses its current time setting to authenticate with the HTTPS proxy, then the authentication process can proceed, but the authentication will fail because the time is too far in the past

Engineering Contradiction:
Improveauthentication successVSAvoidtime accuracy
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by extracting the notValidBefore time from the certificate and using it to set a preliminary time on the network appliance before attempting authentication. This preliminary time setting enables the appliance to successfully authenticate with the HTTPS proxy, after which it can obtain the accurate current time from a time server.

Inventive Principle:
Principle #10Preliminary action

2Loss of time

If the network appliance obtains accurate time from a time server, then the time accuracy is improved, but the appliance cannot access the time server because certificate authentication fails due to incorrect time

Engineering Contradiction:
Improvetime accuracyVSAvoidconnection establishment
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

The patent resolves this contradiction by performing preliminary action - extracting the notValidBefore time from the certificate and setting it as the preliminary time on the network appliance before attempting to connect to the time server. This ensures the appliance has sufficient time accuracy to successfully authenticate and obtain the current time from the time server.

Inventive Principle:
Principle #10Preliminary action

3Loss of time

If the network appliance operator manually resets the time, then the time accuracy is restored, but operator intervention is required which reduces automation

Engineering Contradiction:
Improvetime accuracyVSAvoidautomatic time correction
Core Design Contradiction:
Loss of timeVSExtent of automation

Solution Approach 1:

The patent applies self-service by enabling the network appliance to automatically extract the notValidBefore time from its certificate, set this as the preliminary time, authenticate with the HTTPS proxy, and obtain the accurate current time from a time server without requiring any operator intervention. The appliance autonomously corrects its time setting.

Inventive Principle:
Principle #25Self-service

4Duration of action of stationary object

If the network appliance uses hardware clock or on-board battery to maintain time, then the time can be maintained during shutdown, but these components may fail leading to incorrect time

Engineering Contradiction:
Improvetime maintenance during shutdownVSAvoidtime accuracy
Core Design Contradiction:
Duration of action of stationary objectVSReliability

Solution Approach 1:

The patent applies preliminary action by using the notValidBefore time from the certificate to set a preliminary time on the network appliance. This approach does not depend on the reliability of hardware clock or battery, as it establishes a known-good time reference from the certificate itself, enabling subsequent automatic time synchronization with the time server.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8196192B2Setting a preliminary time on a network appliance using a digital certificate
Publication Date: 2012.06.05 RED HAT INC
  • US8196192B2 patent drawing
  • US8196192B2 patent drawing
  • US8196192B2 patent drawing

AI summary

A method and system for setting a time on a network appliance. The method may include attempting to establish a secure connection with a server using a certificate issued for a network appliance, and determining that an attempt to establish a secure connection has failed. The method may further include determining that a possible cause of the failure to establish a secure connection is incorrect time data provided by the network appliance, and updating the time on the network appliance using time data contained in the certificate.