Server Certificate SAN Merging for Storage Reduction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing methods for creating multiple server certificates for SSL communication in network environments, such as those used in multifunction printers, lead to increased storage capacity requirements, which has not been adequately addressed.

Innovation Solution

A server that creates three types of server certificates: one fluctuating with the network environment, another not fluctuating, and a third combining multiple host names, allowing for efficient transmission of these certificates to support secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple server certificates are created to support various protocols and host names, then SSL communication compatibility is improved, but storage capacity requirement increases

Engineering Contradiction:
ImproveSSL communication compatibilityVSAvoidstorage capacity
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The patent merges multiple host names into a single server certificate by including them in the Subject Alternative Name (SAN) field. This allows one certificate to serve multiple protocols and access methods (DNS name, IP address, email address) simultaneously, eliminating the need to store separate certificates for each host name and thereby reducing storage capacity requirements while maintaining SSL communication compatibility.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The server certificate is designed with multi-functionality by incorporating multiple host names and various address types (DNS, IP, email) within a single certificate structure. This universal certificate can handle different communication protocols and access methods without requiring separate certificates, thus improving adaptability while minimizing storage usage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If server certificates are created for each interface and protocol, then device discovery capability is improved, but certificate management complexity increases

Engineering Contradiction:
Improvedevice discovery capabilityVSAvoidcertificate management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent combines support for multiple interfaces and protocols into a single server certificate by listing all relevant host names in the SAN field. This merging approach simplifies certificate management by reducing the number of certificates to track and deploy, while still enabling comprehensive device discovery across different protocols and access methods.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The server certificate achieves multi-functionality by supporting multiple host names, protocols, and address types within one certificate. This universal approach allows the server to handle various device discovery scenarios without requiring separate certificates for each interface or protocol, thereby reducing management complexity while maintaining discovery capability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Quantity of substance

If a single server certificate contains multiple host names, then storage capacity is reduced, but certificate security management becomes more challenging

Engineering Contradiction:
Improvestorage capacityVSAvoidcertificate security management
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The patent merges multiple host names into a single certificate structure using the Subject Alternative_name (SAN) extension. This approach reduces storage capacity by consolidating what would otherwise require multiple separate certificates. For security management, the patent maintains proper cryptographic practices by using a single private key paired with the multi-hostname certificate, avoiding the security risks of splitting keys while still achieving storage efficiency.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10917398B2Server, control method of server, and storage medium
Publication Date: 2021.02.09 CANON KK
  • US10917398B2 patent drawing
  • US10917398B2 patent drawing
  • US10917398B2 patent drawing

AI summary

The object of the present invention is to reduce the storage capacity necessary to save server certificates while enabling encrypted communication, such as SSL communication, whose convenience is high in the case where a plurality of server certificates is created. The present invention is a server that creates a server certificate that is necessary for encrypted communication and has a creation unit configured to create a first server certificate including information that fluctuates in accordance with a network environment, a second server certificate including information that does not fluctuate in accordance with the network environment, and a third server certificate that puts together information on a plurality of host names of the server, which a user can change and a transmission unit configured to transmit one of the created first, second, and third server certificates to a communication device.