Security Domain Manager Automates Smart Card Configuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing smart card systems require complex manual configuration and management of security information, making it difficult to securely enroll and communicate between components like certificate authorities, directory servers, and key generators.

Innovation Solution

A security domain manager that shares security policies with its members, providing a centralized registry for services and automating the configuration of components, including certificate revocation list distribution and key management, to facilitate secure communication and policy enforcement.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual configuration is used for certificate authority and security components, then security policies can be customized and controlled, but the complexity of configuration and management increases significantly

Engineering Contradiction:
Improvesecurity policy controlVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security components (certificate authority, directory server, key generator) automatically discover each other and configure their communications without manual administrator intervention. The system performs self-configuration by automatically establishing secure channels and exchanging necessary security parameters.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

A security information server acts as an intermediary that automatically manages the configuration data and security parameters for all components. This intermediary centralizes the configuration management, reducing the complexity at individual component levels while maintaining overall security control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manual configuration is used for secure communication between security components, then security can be maintained, but the enrollment process becomes complex and difficult

Engineering Contradiction:
Improvesecure communicationVSAvoidenrollment ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

Security components automatically perform their own enrollment and configuration. The certificate authority, directory server, and key generator autonomously discover each other, establish secure communication channels, and exchange necessary credentials without requiring administrator manual configuration.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary configuration actions automatically during system initialization or component addition. Security parameters, communication channels, and credentials are pre-configured through automated discovery and negotiation before actual operational use, simplifying the enrollment process.

Inventive Principle:
Principle #10Preliminary action

3Loss of time

If automated discovery is implemented for security domain topology, then configuration time is reduced, but system complexity increases

Engineering Contradiction:
Improveconfiguration timeVSAvoidsystem complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The security information server serves as a central intermediary that maintains knowledge of the security domain topology. Components query this intermediary to discover other components and their configurations, automating the topology discovery process while centralizing the complexity management in a single accessible location.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The automated discovery mechanism uses feedback loops where components announce their presence and capabilities to the security information server, which then distributes this information to other components. This feedback-based discovery automates topology mapping without requiring complex manual configuration.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8707024B2Methods and systems for managing identity management security domains
Publication Date: 2014.04.22 RED HAT INC
  • US8707024B2 patent drawing
  • US8707024B2 patent drawing
  • US8707024B2 patent drawing

AI summary

Embodiments of the present invention provide identity management security domains that may be used in an enterprise security system. A security domain provides a centralized registry of services provided by the enterprise security system. For example, certificate authorities and other services, such as key archives, and the like, in the enterprise security system may register information about themselves in the security domain. Authorized users can then discover the location of these services. In some embodiments, the security domain may provide an interface that indicates a topology between services of the enterprise security system. The security domain may also serve as a distribution point for security policies. A security policy may comprise information that indicates, for example, a set of trusted certificate authorities, certificate templates, certificate revocation lists, and the locations of the services in the enterprise security system.