SSL Certificate Application Authentication for Content Repository Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In B2B environments, existing methods for accessing content repositories are vulnerable to password compromise and eavesdropping, leading to potential unauthorized access, as passwords can be compromised at client or server devices and intercepted during network communication.

Innovation Solution

The method uses SSL certificates for authentication, establishing user identifiers and rules based on SSL certificate attributes to verify applications accessing content repositories, eliminating the need for passwords and ensuring secure transactions through mutual SSL processing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If passwords are used for authentication, then ease of operation is improved, but security is worsened due to vulnerability to compromise and eavesdropping

Engineering Contradiction:
Improveauthentication processVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces the mechanical password-based authentication system with an SSL certificate-based system. Instead of using passwords that can be compromised or intercepted, the system uses digital certificates and cryptographic protocols to authenticate applications, thereby maintaining ease of operation while significantly improving security

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces SSL certificates as an intermediary between the application and content repository. The certificate acts as a trusted mediator that verifies the identity of the application without exposing sensitive credentials, thus improving security while maintaining operational simplicity

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If SSL certificates are used for authentication, then security is improved, but device complexity is worsened

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent leverages the universal SSL/TLS infrastructure that is already widely implemented in modern systems. By using standard SSL certificates and protocols, the solution achieves high security without requiring custom authentication mechanisms, thereby limiting the increase in device complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9560038B2Method and apparatus for verifying an application to authorize content repository access using SSL certificates
Publication Date: 2017.01.31 ADOBE INC
  • US9560038B2 patent drawing
  • US9560038B2 patent drawing
  • US9560038B2 patent drawing

AI summary

A computer implemented method and apparatus for verifying an application to authorize content repository access using SSL certificates. The method comprises receiving a request for accessing a content repository from an application wherein the request is to perform one or more transactions on the content repository; and establishing a user identifier and one or more rules for accessing the content repository wherein the one or more rules are established using an authenticated SSL certificate to verify the application.