Network Management System Automatic Certificate Revocation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security systems face risks of certificate misuse when network elements are removed or changed, as certificates remain valid and can be exploited for unauthorized access, leading to potential attacks.

Innovation Solution

A method and apparatus for automatic revocation of digital certificates by a network management system, which maintains lists of certificate information and generates revocation requests when a network element is changed or discarded, ensuring that certificates are promptly revoked and preventing unauthorized use.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a network element device is removed or changed, then the network configuration is updated, but the certificate on the device remains valid and can be misused for unauthorized access

Engineering Contradiction:
Improvenetwork securityVSAvoidcertificate management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a feedback mechanism where the network management system continuously monitors the status of network element devices and automatically triggers certificate revocation when a device is removed or changed. The system receives status information from the device, determines whether the certificate should be revoked based on predefined criteria, and executes the revocation process, creating a closed-loop control system that maintains security without manual intervention.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent enables the certificate management system to automatically detect device status changes and initiate revocation procedures without requiring manual operator intervention. The network management system self-monitors device status, self-determines revocation necessity, and self-executes the revocation process, reducing operational complexity while maintaining security.

Inventive Principle:
Principle #25Self-service

2Reliability

If manual certificate revocation is performed, then certificate security is maintained, but operational costs increase and error risks arise

Engineering Contradiction:
Improvecertificate validity controlVSAvoidoperational efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements automatic certificate revocation where the network management system autonomously monitors device status, determines revocation necessity, and executes the revocation process without manual intervention. This eliminates human error risks and reduces operational costs while maintaining strict control over certificate validity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system establishes a feedback loop that automatically detects when a network element device is removed or changed, triggers the appropriate revocation action, and confirms completion. This automated feedback mechanism ensures timely certificate invalidation while improving operational efficiency by eliminating manual processes.

Inventive Principle:
Principle #23Feedback

3Ease of operation

If certificate revocation is delayed, then operational simplicity is maintained, but the risk of certificate misuse and network attacks increases

Engineering Contradiction:
Improvecertificate management simplicityVSAvoidcertificate misuse risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements real-time feedback monitoring where the network management system continuously tracks device status and immediately triggers certificate revocation upon detecting removal or changes. This automated real-time response eliminates delays while maintaining operational simplicity through rule-based automatic decision-making.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary configuration of revocation criteria and automated response rules before security incidents occur. By pre-establishing the conditions and actions for certificate revocation, the system can respond immediately when triggered, preventing any delay that would expose the network to misuse risks while keeping the operation simple through predetermined rules.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2942900B1Method, device, and system for improving network security
Publication Date: 2020.03.04 HUAWEI TECH CO LTD
  • EP2942900B1 patent drawingFigure 1a~1b
  • EP2942900B1 patent drawingFigure 2a~2b
  • EP2942900B1 patent drawingFigure 3~5

AI summary

Embodiments of the present invention disclose a method, an apparatus, and a system for increasing network security. The method for increasing network security includes: receiving, by a network management system, a certificate message reported by a network element; generating, by the network management system, a first list; when determining that a certificate corresponding to certificate information in the first list needs to be revoked, generating, by the network management system, a certificate revocation request file according to the certificate information, and removing the certificate information in the first list from the first list; and sending, by the network management system, the certificate revocation request file to a public key infrastructure (PKI) system. According to the method in this embodiment, automatic revocation of a certificate of a device on a network can be performed, thereby reducing a risk of manual revocation error and increasing network security. The embodiments of the present invention further disclose an apparatus and a system for increasing network security.