PKI Network Service Integrating MDM Certificate Provisioning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Implementing and maintaining a Public Key Infrastructure (PKI) for digital certificates is burdensome, especially for smaller organizations lacking technical staff, and Mobile Device Management (MDM) systems add complexity, making it difficult for administrators to provision certificates to client devices.
Innovation Solution
A security system that provides a PKI as a network service, simplifying the process by using a designated certificate exchange flow protocol to interface with MDM systems, allowing administrators to provision certificates with minimal user interface actions, and supporting various certificate exchange protocols like SCEP and EST.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If an organization implements and maintains an in-house PKI, then digital certificate issuance and management capability is achieved, but system complexity and operational burden increase significantly
Solution Approach 1:
The patent introduces a certificate authority service as an intermediary between organizations and PKI infrastructure. This service provides PKI functionality remotely, allowing organizations to obtain digital certificates without maintaining complex in-house PKI systems. The certificate authority service mediates the certificate issuance process, handling the computational and administrative burden centrally while providing simplified access to individual organizations.
Solution Approach 2:
The patent extracts the core PKI functionality from the organization's infrastructure and relocates it to a centralized certificate authority service. By taking out the complex certificate management operations from the local environment and performing them remotely, organizations gain certificate issuance capability without the burden of maintaining the underlying PKI complexity.
2Productivity
If MDM systems are used to transfer certificates to client devices, then certificate distribution capability is achieved, but operational complexity increases due to additional configuration requirements
Solution Approach 1:
The patent merges the certificate issuance and distribution processes into a single integrated workflow. The certificate authority service works in conjunction with MDM systems to combine certificate generation, signing, and deployment operations. This integration allows administrators to provision certificates through a unified process rather than separately configuring certificate authorities and MDM systems, thereby reducing operational complexity while maintaining distribution capability.
3Reliability
If manual certificate exchange processes are used, then certificate provisioning is achieved, but time consumption and administrative effort increase
Solution Approach 1:
The patent enables self-service certificate provisioning through automated workflows. The certificate authority service automatically generates certificates, signs them, and pushes them to client devices through integrated MDM systems without requiring manual certificate exchange. This automation maintains provisioning accuracy through systematic validation while dramatically reducing the time and administrative effort required compared to manual processes.
Solution Approach 2:
The patent performs preliminary actions by pre-configuring the certificate authority service and establishing automated workflows before certificate provisioning is needed. The system is prepared in advance with predefined policies, device profiles, and integration configurations, allowing certificates to be issued and distributed automatically when needed without manual intervention at the time of provisioning.
Data Source
AI summary
A security system used by an organization maintains a PKI used for issuing digital certificates (hereinafter for brevity also referred to simply as “certificates”) and provides the PKI to the organization as a network service. In order to simplify the use of the PKI for purposes such as obtaining certificates, the security system additionally provides a mechanism for using a designated flow protocol to interface with whichever MDMs the organization uses. This mechanism permits administrators or other users to provision certificates to their organization's client devices with just a few actions within a user interface.


