OID-Embedded Identity Certificate Automation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In public key infrastructure systems, users face difficulties in managing identity certificates for public cryptographic keys, particularly in wireless communication devices, where certificates sent via email may lack context due to varying formatting by different Certificate Authorities and the need for manual user intervention to download and import certificates.

Innovation Solution

The method involves the Certificate Authority including an object identifier (OID) pair in the certification request, which is then included in the identity certificate, allowing the wireless mail server to automatically recognize and transmit the certificate to the user device, eliminating the need for user-manual certificate management and ensuring context is maintained.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If certificates are sent via email from Certificate Authorities, then certificate delivery is achieved, but certificates lack context due to varying formatting and require manual user intervention

Engineering Contradiction:
Improvecertificate managementVSAvoidcertificate context
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent applies preliminary action by embedding the object identifier (OID) pair into the certificate request before submission to the Certificate Authority. This pre-configured identifier enables the wireless mail server to automatically recognize and match incoming certificates with their corresponding requests, eliminating the need for manual user intervention and preserving certificate context without requiring post-delivery processing.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If different Certificate Authorities use varying certificate formatting, then certificate issuance flexibility is improved, but automatic recognition and delivery to user devices become difficult

Engineering Contradiction:
Improvecertificate formattingVSAvoidcertificate delivery
Core Design Contradiction:
Adaptability or versatilityVSExtent of automation

Solution Approach 1:

The patent introduces an intermediary mechanism—the object identifier (OID) pair—that acts as a universal bridge between diverse Certificate Authorities and the wireless mail server. This intermediary element is embedded in the certificate request and enables automatic recognition and matching regardless of the Certificate Authority's formatting variations, thus maintaining adaptability while enabling automation through the wireless mail server's ability to match OIDs.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If manual user intervention is required to download and import certificates, then user control is maintained, but user burden and complexity increase

Engineering Contradiction:
Improvecertificate import processVSAvoidcertificate management system
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements self-service by enabling the wireless mail server to automatically perform certificate recognition, matching, and delivery based on the embedded object identifier (OID) pair. The system serves itself by using the pre-configured OID to autonomously complete the entire certificate delivery process without requiring user download or import actions, thereby simplifying the user experience while maintaining systematic complexity management through automation.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9300654B2Method of handling a certification request
Publication Date: 2016.03.29 MALIKIE INNOVATIONS LTD
  • US9300654B2 patent drawing
  • US9300654B2 patent drawing
  • US9300654B2 patent drawing

AI summary

In a certification request, a user device includes an object identifier. When a certification authority generates an identity certificate responsive to receiving the certification request, the certification authority includes the object identifier, thereby allowing improved management of the identity certificate at the user device and elsewhere.