Sensor Certificate Lifecycle Manager for Automated Network Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current enterprise network management systems face challenges in automating the generation and management of EAP-TLS certificates for troubleshooting, which requires manual intervention and poses security risks due to the need for manual download and upload of certificates, and lack control over the certificate lifecycle.

Innovation Solution

Implementing a sensor certificate lifecycle manager within the network management system to automate the generation, provisioning, and management of unique signed certificates for sensors, enabling zero-touch onboarding and centralized control over certificate lifecycle, including revocation and reassignment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual certificate download and upload is used for sensor onboarding, then certificate provisioning can be completed, but security risks increase and manual intervention is required

Engineering Contradiction:
ImproveManual certificate provisioningVSAvoidNetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system enables self-service certificate provisioning where sensors automatically obtain certificates from the certificate authority through automated workflows. The network management system automatically downloads certificates from the certificate authority and provisions them to sensors without requiring manual user intervention, eliminating the security risks associated with manual certificate handling while maintaining ease of operation.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The network management system acts as an intermediary between the certificate authority and sensors. It receives certificate requests from sensors, communicates with the certificate authority to obtain certificates, and then provisions the certificates to the appropriate sensors. This automated intermediary process eliminates the need for manual certificate download and upload, reducing security risks while maintaining operational efficiency.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of manufacture

If manual certificate management is implemented, then certificate provisioning can be performed, but automation level remains low and time-consuming

Engineering Contradiction:
ImproveCertificate provisioning processVSAvoidCertificate management automation
Core Design Contradiction:
Ease of manufactureVSExtent of automation

Solution Approach 1:

Sensors automatically initiate certificate requests and the network management system automatically manages the entire certificate lifecycle including generation, distribution, renewal, and revocation. This self-service automated approach eliminates manual intervention entirely, achieving high automation levels while simplifying the certificate provisioning process through standardized workflows.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by pre-configuring automated workflows for certificate management. When sensors are onboarded, the system automatically initiates certificate requests, receives certificates from the certificate authority, and provisions them to sensors without waiting for manual intervention. This preliminary automation of the entire process eliminates time-consuming manual steps.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If exportable certificates are used for troubleshooting, then authentication can be replicated, but security concerns arise from certificate misuse

Engineering Contradiction:
ImproveAuthentication troubleshooting capabilityVSAvoidCertificate security risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system implements local quality by making certificates non-exportable and device-specific. Each sensor receives a certificate that is bound to its unique identity and can only be used by that specific sensor for authentication purposes. This localized certificate binding maintains the ability to replicate authentication scenarios for troubleshooting while preventing certificate misuse on unauthorized devices.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system uses short-lived, disposable certificates that are automatically generated for specific troubleshooting purposes and automatically revoked after use. Instead of using long-term exportable certificates, the system creates temporary certificates that have limited validity periods and specific usage purposes, eliminating security risks from certificate misuse while maintaining troubleshooting capabilities.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

4Extent of automation

If centralized certificate management is implemented, then control over certificate lifecycle is improved, but system complexity increases

Engineering Contradiction:
ImproveCertificate lifecycle controlVSAvoidNetwork management system complexity
Core Design Contradiction:
Extent of automationVSDevice complexity

Solution Approach 1:

The network management system implements a universal certificate management module that handles multiple certificate operations including generation, distribution, renewal, and revocation through a single integrated interface. This multi-functional approach provides centralized control over the entire certificate lifecycle while avoiding the complexity of multiple separate management systems by consolidating all certificate management functions into one unified system.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11546318B2Sensor certificate lifecycle manager for access authentication for network management systems
Publication Date: 2023.01.03 CISCO TECHNOLOGY INC
  • US11546318B2 patent drawing
  • US11546318B2 patent drawing
  • US11546318B2 patent drawing

AI summary

Systems and methods provided for a sensor certificate lifecycle manager for a network management system of an enterprise network for the automated generation of unique certificates for sensors used to act like a client device in the enterprise network for the purposes of troubleshooting. Furthermore, the network management and command center in association with the sensor certificate lifecycle manager manages a pool of signed unique certificates and have control over the lifecycle of such certificates, such as for revoking, transferring, and reassigning certificates for the sensors.