Network Device Certificate Enrollment for Authentication Survivability
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network systems face challenges in maintaining authentication survivability when the authentication server becomes unavailable, leading to disruptions in network connectivity and potential security breaches due to manual certificate management.
Innovation Solution
Implementing a certificate enrollment server to automatically provision unique server certificates to network devices, ensuring that even if one device is compromised, others remain secure and operational.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual certificate management is used for network devices, then deployment simplicity is maintained, but security risk increases and authentication survivability deteriorates when authentication server becomes unavailable
Solution Approach 1:
The patent applies preliminary action by having network devices automatically obtain certificates from the authentication server before they are needed for authentication operations. The certificate management system pre-configures devices with valid certificates, so when the authentication server becomes unavailable, devices already possess the necessary certificates to continue authenticating clients independently, ensuring authentication survivability without manual intervention
Solution Approach 2:
The patent implements self-service by enabling network devices to automatically manage their own certificates through the authentication server without requiring manual configuration. Devices can independently obtain, renew, and update their certificates through automated protocols, eliminating the need for manual certificate management while maintaining security and reliability even when the authentication server is unavailable
2Reliability
If unique server certificates are provisioned to each network device, then security against compromise increases, but certificate provisioning complexity and time increase
Solution Approach 1:
The patent applies self-service by enabling network devices to automatically obtain their own unique certificates directly from the authentication server or certificate authority without requiring manual intervention for each device. The automated certificate provisioning process eliminates the time-consuming manual distribution and installation of certificates while ensuring each device receives a unique certificate for enhanced security
Solution Approach 2:
The patent uses preliminary action by having certificates automatically provisioned to network devices before they are deployed or before they are needed for authentication operations. This pre-provisioning ensures that each device has its unique certificate ready in advance, eliminating the need for time-consuming manual certificate distribution and installation processes
3Device complexity
If authentication server is centralized, then authentication control is simplified, but network connectivity is disrupted when authentication server becomes unavailable
Solution Approach 1:
The patent applies local quality by enabling individual network devices to independently perform authentication operations using their own certificates without requiring continuous communication with the centralized authentication server. Each device has the necessary authentication credentials locally stored, allowing it to authenticate clients independently even when the centralized authentication server is unavailable, thus maintaining network connectivity while preserving centralized certificate management
Data Source
AI summary
In some examples, a network device receives, from an orchestration server, a name for use in obtaining a certificate. The network device sends, to a certificate enrollment server, a certificate request comprising the name, and receives, from the certificate enrollment server, a response to the certificate request, the response including information of the certificate that is based on the name in the certificate request. The network device detects that an authentication server is unavailable for an authentication procedure for a client coupled to the network device. Based on detecting that the authentication server is unavailable, the network device uses the certificate based on the name in the certificate request as part of the authentication procedure between the network device and the client.


