Server Certificate SAN Merging for Storage Reduction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing methods for creating multiple server certificates for SSL communication in network environments, such as those used in multifunction printers, lead to increased storage capacity requirements, which has not been adequately addressed.
Innovation Solution
A server that creates three types of server certificates: one fluctuating with the network environment, another not fluctuating, and a third combining multiple host names, allowing for efficient transmission of these certificates to support secure communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple server certificates are created to support various protocols and host names, then SSL communication compatibility is improved, but storage capacity requirement increases
Solution Approach 1:
The patent merges multiple host names into a single server certificate by including them in the Subject Alternative Name (SAN) field. This allows one certificate to serve multiple protocols and access methods (DNS name, IP address, email address) simultaneously, eliminating the need to store separate certificates for each host name and thereby reducing storage capacity requirements while maintaining SSL communication compatibility.
Solution Approach 2:
The server certificate is designed with multi-functionality by incorporating multiple host names and various address types (DNS, IP, email) within a single certificate structure. This universal certificate can handle different communication protocols and access methods without requiring separate certificates, thus improving adaptability while minimizing storage usage.
2Adaptability or versatility
If server certificates are created for each interface and protocol, then device discovery capability is improved, but certificate management complexity increases
Solution Approach 1:
The patent combines support for multiple interfaces and protocols into a single server certificate by listing all relevant host names in the SAN field. This merging approach simplifies certificate management by reducing the number of certificates to track and deploy, while still enabling comprehensive device discovery across different protocols and access methods.
Solution Approach 2:
The server certificate achieves multi-functionality by supporting multiple host names, protocols, and address types within one certificate. This universal approach allows the server to handle various device discovery scenarios without requiring separate certificates for each interface or protocol, thereby reducing management complexity while maintaining discovery capability.
3Quantity of substance
If a single server certificate contains multiple host names, then storage capacity is reduced, but certificate security management becomes more challenging
Solution Approach 1:
The patent merges multiple host names into a single certificate structure using the Subject Alternative_name (SAN) extension. This approach reduces storage capacity by consolidating what would otherwise require multiple separate certificates. For security management, the patent maintains proper cryptographic practices by using a single private key paired with the multi-hostname certificate, avoiding the security risks of splitting keys while still achieving storage efficiency.
Data Source
AI summary
The object of the present invention is to reduce the storage capacity necessary to save server certificates while enabling encrypted communication, such as SSL communication, whose convenience is high in the case where a plurality of server certificates is created. The present invention is a server that creates a server certificate that is necessary for encrypted communication and has a creation unit configured to create a first server certificate including information that fluctuates in accordance with a network environment, a second server certificate including information that does not fluctuate in accordance with the network environment, and a third server certificate that puts together information on a plurality of host names of the server, which a user can change and a transmission unit configured to transmit one of the created first, second, and third server certificates to a communication device.


