Proxy Certificate Chains for Destination Connection Handling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems lack effective methods for monitoring and managing compute assets in cloud environments to detect anomalies and ensure data security, compliance, and asset management efficiently.

Innovation Solution

A data platform is deployed to monitor and analyze data from compute assets using agents that collect and report information, generating polygraphs to identify deviations from typical behavior, with data processing resources performing real-time analytics and user interface resources providing insights to external users.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing systems are used without specialized monitoring, then cloud environments can operate with minimal infrastructure, but effective monitoring and anomaly detection capabilities are insufficient

Engineering Contradiction:
Improveanomaly detection capabilityVSAvoidmonitoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the monitoring function by deploying agents on individual compute assets to collect local data, separating the collection function from the centralized analysis function. This allows distributed monitoring without requiring complex centralized processing infrastructure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces polygraphs as an intermediary data structure that simplifies the communication between agents and the central platform. Polygraphs aggregate and normalize data from multiple agents, serving as a mediator that reduces the complexity of direct point-to-point communication and enables effective anomaly detection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive monitoring of compute assets is implemented, then data security and compliance can be enhanced, but system complexity and resource requirements increase

Engineering Contradiction:
Improvedata security monitoringVSAvoidmonitoring infrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Agents perform self-service by autonomously collecting and reporting data from compute assets without requiring manual configuration or complex setup. The system automatically monitors security events, compliance status, and asset states, reducing the operational burden while maintaining comprehensive monitoring.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The monitoring system is designed with universality through a single platform that handles multiple functions: security monitoring, compliance tracking, asset management, and anomaly detection. This multi-functional approach consolidates what would otherwise require separate systems, reducing overall infrastructure complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If real-time analytics are performed on compute asset data, then anomaly detection effectiveness improves, but processing resources and time consumption increase

Engineering Contradiction:
Improveanomaly detection precisionVSAvoidprocessing resource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The system performs preliminary action by collecting and normalizing data at the agent level before transmission to the central platform. Agents prepare data in advance according to predefined schemas, reducing the processing burden during central analysis and enabling more efficient real-time analytics with lower resource consumption.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts only the necessary information from compute assets through agents that selectively collect data relevant to security, compliance, and operational metrics. By extracting only essential data points rather than transmitting all raw data, the system reduces processing requirements while maintaining detection precision.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12463994B1Handling of certificates by intermediate actors
Publication Date: 2025.11.04 FORTINET INC
  • US12463994B1 patent drawing
  • US12463994B1 patent drawing
  • US12463994B1 patent drawing

AI summary

Handling of certificates by intermediate actors, including: receiving, by a proxy and from a client, a client certificate and a first private key; generating, by the proxy and based on the client certificate and the first private key, an intermediate certificate; generating, by the proxy and in response to a request from the client to connect to a destination, an alternate certificate for the destination; and providing, to the client, a certificate chain comprising the alternate certificate, the intermediate certificate, and the client certificate.