Network Device Manager Integrating SCEP for Automated Certificate Renewal

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Administering security certificates for large-scale enterprise networks is impractical due to the sheer number of devices and the manual process of creating and managing challenge passwords, which requires multiple administrators and is time-consuming.

Innovation Solution

A network device manager integrates with a Simple Certificate Enrollment Protocol (SCEP) server to automate the management of security certificates, including retrieving, validating, renewing, and assigning certificates to devices, using a root certificate and challenge passwords to manage multiple devices efficiently.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual certificate management is used for each device, then security can be maintained, but administrative time and complexity increase significantly

Engineering Contradiction:
ImprovesecurityVSAvoidadministrative time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables self-service automation where the certificate management system automatically performs certificate retrieval, validation, renewal, and assignment without requiring manual administrator intervention for each device. The system autonomously monitors certificate expiration dates and executes renewal processes, eliminating the time-consuming manual management while maintaining security standards across all devices.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

An automated certificate management system acts as an intermediary between the SCEP server and multiple network devices. This intermediary system handles all certificate operations centrally, retrieving certificates from the SCEP server, validating them against the root certificate, and automatically assigning them to appropriate devices. This mediation eliminates the need for administrators to manually manage each device individually while ensuring consistent security enforcement.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple administrators are assigned to manage certificates, then security oversight is improved, but system complexity and coordination requirements increase

Engineering Contradiction:
Improvesecurity oversightVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments certificate management responsibilities into distinct functional modules: certificate retrieval from SCEP server, validation against root certificate, expiration monitoring, renewal execution, and device assignment. Each module operates independently and automatically, allowing security oversight without requiring multiple administrators to coordinate complex manual processes. The segmentation reduces system complexity by automating each segment while maintaining comprehensive security coverage.

Inventive Principle:
Principle #1Segmentation

3Reliability

If certificates are manually renewed before expiration, then network security is maintained, but administrative workload increases

Engineering Contradiction:
Improvenetwork securityVSAvoidadministrative productivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system implements continuous feedback monitoring of certificate expiration dates across all network devices. The automated system regularly queries device certificate status, compares expiration dates against current time, and triggers renewal processes proactively before certificates expire. This feedback mechanism ensures network security is maintained while eliminating the need for administrators to manually track and renew certificates, significantly improving administrative productivity.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary actions by automatically detecting certificates approaching expiration and initiating renewal processes before the certificates actually expire. The system monitors certificate validity periods and executes renewal operations in advance, ensuring continuous security coverage without requiring administrators to manually intervene. This preliminary action approach maintains network security while freeing administrators from repetitive renewal tasks.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3821357B1Systems, apparatus, and computer program products integrating simple certificate enrollment protocol into network device management
Publication Date: 2023.01.04 KYOCERA DOCUMENT SOLUTIONS INC
  • EP3821357B1 patent drawingFigure 1
  • EP3821357B1 patent drawingFigure 2
  • EP3821357B1 patent drawingFigure 3

AI summary

A system, method, computer program product and apparatus provide an improvement to administration and management of security certificates in enterprise scale networks. An exemplary embodiment integrates a network device manager (NDM) (30) with Simple Certificate Enrollment Protocol (SCEP) for administration and management of network equipment and for handling certificates for enterprise-scale implementation. The network device manager (30) may control the settings and is configured to communicate with the firmware of end devices (50). The SCEP thus has a medium in the network device manager (30) through which the SCEP features can be communicated to the end devices (50). In an exemplary embodiment, aspects of the system may for example, automatically check expiration of and renew certificates that are expiring.