Seamless Certificate Replacement in Hyperconverged Infrastructure

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing certificate management systems in hyperconverged infrastructure environments face downtime and broken SSL trust when replacing digital certificates, impacting communication between endpoints due to the need for manual administration and sequential replacement processes.

Innovation Solution

A seamless certificate management unit that receives a certificate replacement request, places a new certificate while maintaining existing communication using the old certificate, discovers and updates dependent endpoints, and decommissions the old certificate after ensuring seamless transition to the new one, utilizing a certificate dependency table to manage the process without downtime.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual certificate replacement is performed sequentially, then certificate security is improved, but system downtime increases and communication between endpoints is broken

Engineering Contradiction:
Improvecertificate securityVSAvoidsystem downtime
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by installing the new certificate alongside the old certificate before any communication occurs, rather than replacing the old certificate first. This allows the new certificate to be prepared and validated in advance, eliminating the need for downtime during actual replacement.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a certificate management system as an intermediary that automatically discovers dependent endpoints, monitors communication status, and orchestrates the certificate transition process. This intermediary manages the complexity of coordinating multiple endpoints, allowing seamless replacement without manual intervention or downtime.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If automated certificate replacement is implemented, then productivity is improved, but complexity of the system increases

Engineering Contradiction:
Improvecertificate replacement efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system enables self-service by allowing the certificate management system to automatically discover dependent endpoints, monitor communication status, and complete the replacement process without human intervention. The system serves itself by autonomously managing the entire certificate lifecycle and coordination across multiple components.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements a universal certificate management system that handles multiple functions: automatic endpoint discovery, communication monitoring, certificate installation, and transition orchestration. This multi-functional approach consolidates what would otherwise require multiple separate tools and manual processes into a single automated system.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If sequential certificate replacement is used, then ease of operation is maintained, but loss of time increases due to manual administration

Engineering Contradiction:
Improveoperation simplicityVSAvoidadministration time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system eliminates manual administration by implementing self-service automation where the certificate management system independently discovers endpoints, monitors communication, and executes the replacement process. This removes the time-consuming manual steps while maintaining operational simplicity through automated workflows.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent incorporates feedback mechanisms where the system continuously monitors communication status between endpoints during the certificate replacement process. This real-time feedback allows the system to adapt and ensure seamless transition, maintaining ease of operation while dramatically reducing administration time through automated decision-making.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11190364B2Seamless certificate replacement for endpoints in hyperconverged infrastructure
Publication Date: 2021.11.30 VMWARE INC
  • US11190364B2 patent drawing
  • US11190364B2 patent drawing
  • US11190364B2 patent drawing

AI summary

Techniques for seamless certificate replacement for endpoints in hyperconverged infrastructure are disclosed. In one example, a certificate replacement request for an endpoint may be received. Upon receiving the certificate replacement request, a new certificate may be placed in the endpoint such that the endpoint includes an old certificate and the new certificate. Further, dependent endpoints having communication with the endpoint using the old certificate may be discovered and monitored. Furthermore, the new certificate of the endpoint may be placed in the discovered dependent endpoints and existing communication between the endpoint and each of the discovered dependent endpoints using the old certificate may be maintained. Upon completion of the existing communication, next communication between the endpoint and each of the discovered dependent endpoints may be enabled using the new certificate. Then, the old certificate may be decommissioned from the endpoint and the discovered dependent endpoints.