Offline Certificate Presetting for Secure Network Management Startup

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for presetting network management digital certificates using self-signed certificates are insecure, lack authority verification, and require complex updates due to strong coupling with network management versions, complicating the update process.

Innovation Solution

A method involving obtaining a network management version package and a matching preset certificate package, creating secure storage modules, and storing certificates offline to ensure security and ease of updates, decoupling certificate management from network management versions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If self-signed certificates are preset in modules, then certificate presetting is simple, but security and authority are compromised

Engineering Contradiction:
Improvecertificate presetting simplicityVSAvoidcertificate security and authority
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent segments the certificate management system into two independent parts: certificate issuance (performed offline by authorized personnel using mobile terminals) and certificate usage (performed online by network management modules). This segmentation allows simple presetting while ensuring security through offline authoritative issuance and proper cryptographic key management.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If certificates are strongly coupled with network management version, then certificate installation is straightforward, but updates become complicated

Engineering Contradiction:
Improvecertificate installation easeVSAvoidupdate process complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent extracts the certificate data from the network management version package and stores it independently in the database. Certificates are issued offline and imported separately, decoupling them from version updates. This allows certificates to be updated independently without requiring network management system upgrades, simplifying the update process while maintaining straightforward installation.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent performs certificate issuance and importation as preliminary actions before network management system deployment. By pre-issuing certificates offline and importing them into the database beforehand, the system avoids the need for online certificate generation and eliminates the coupling between certificate updates and version updates, reducing update complexity.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If online certificate generation is used, then certificates can be obtained dynamically, but security gaps occur during startup

Engineering Contradiction:
Improvecertificate dynamic generationVSAvoidsecurity gap during startup
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent performs certificate issuance as a preliminary offline action before network management module startup. Mobile terminals generate and import certificates into the database beforehand, ensuring that certificates are already available and properly secured when the network management system starts up, eliminating security gaps while maintaining adaptability through flexible offline issuance.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP4730699A1Certificate presetting method, device and computer-readable storage medium
Publication Date: 2026.04.22 ZTE CORP
  • EP4730699A1 patent drawingFigure 1~2
  • EP4730699A1 patent drawingFigure 3~5
  • EP4730699A1 patent drawingFigure 6~8

AI summary

The embodiments of the present application disclose a certificate preset method, a device, and a computer-readable storage medium, belonging to the technical field of communication. The method includes: obtaining a network management version package and a preset certificate package matching the network management version package; installing a network management system based on the network management version package; creating a secure storage module corresponding to each network management module in the network management system; and storing the preset certificates in the preset certificate package in the secure storage module, so that each network management module associated with the secure storage module obtains the required preset certificate.