PKI Network Service Integrating MDM Certificate Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Implementing and maintaining a Public Key Infrastructure (PKI) for digital certificates is burdensome, especially for smaller organizations lacking technical staff, and Mobile Device Management (MDM) systems add complexity, making it difficult for administrators to provision certificates to client devices.

Innovation Solution

A security system that provides a PKI as a network service, simplifying the process by using a designated certificate exchange flow protocol to interface with MDM systems, allowing administrators to provision certificates with minimal user interface actions, and supporting various certificate exchange protocols like SCEP and EST.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If an organization implements and maintains an in-house PKI, then digital certificate issuance and management capability is achieved, but system complexity and operational burden increase significantly

Engineering Contradiction:
Improvedigital certificate issuance capabilityVSAvoidPKI system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a certificate authority service as an intermediary between organizations and PKI infrastructure. This service provides PKI functionality remotely, allowing organizations to obtain digital certificates without maintaining complex in-house PKI systems. The certificate authority service mediates the certificate issuance process, handling the computational and administrative burden centrally while providing simplified access to individual organizations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the core PKI functionality from the organization's infrastructure and relocates it to a centralized certificate authority service. By taking out the complex certificate management operations from the local environment and performing them remotely, organizations gain certificate issuance capability without the burden of maintaining the underlying PKI complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

2Productivity

If MDM systems are used to transfer certificates to client devices, then certificate distribution capability is achieved, but operational complexity increases due to additional configuration requirements

Engineering Contradiction:
Improvecertificate distribution capabilityVSAvoidMDM configuration complexity
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The patent merges the certificate issuance and distribution processes into a single integrated workflow. The certificate authority service works in conjunction with MDM systems to combine certificate generation, signing, and deployment operations. This integration allows administrators to provision certificates through a unified process rather than separately configuring certificate authorities and MDM systems, thereby reducing operational complexity while maintaining distribution capability.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If manual certificate exchange processes are used, then certificate provisioning is achieved, but time consumption and administrative effort increase

Engineering Contradiction:
Improvecertificate provisioning accuracyVSAvoidcertificate provisioning time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent enables self-service certificate provisioning through automated workflows. The certificate authority service automatically generates certificates, signs them, and pushes them to client devices through integrated MDM systems without requiring manual certificate exchange. This automation maintains provisioning accuracy through systematic validation while dramatically reducing the time and administrative effort required compared to manual processes.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent performs preliminary actions by pre-configuring the certificate authority service and establishing automated workflows before certificate provisioning is needed. The system is prepared in advance with predefined policies, device profiles, and integration configurations, allowing certificates to be issued and distributed automatically when needed without manual intervention at the time of provisioning.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12041450B2Computer network-based service for generation and installation of digital certificates of a public key infrastructure seamlessly integrating with multiple mobile device management systems
Publication Date: 2024.07.16 DIVERGENT TECHNOLOGIES INC
  • US12041450B2 patent drawing
  • US12041450B2 patent drawing
  • US12041450B2 patent drawing

AI summary

A security system used by an organization maintains a PKI used for issuing digital certificates (hereinafter for brevity also referred to simply as “certificates”) and provides the PKI to the organization as a network service. In order to simplify the use of the PKI for purposes such as obtaining certificates, the security system additionally provides a mechanism for using a designated flow protocol to interface with whichever MDMs the organization uses. This mechanism permits administrators or other users to provision certificates to their organization's client devices with just a few actions within a user interface.