SSL Certificate Issuance via Hosting Provider Proxy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing process for obtaining an SSL certificate for a Web site is cumbersome and requires significant action from the Subscriber, including coordinating between the Hosting Provider and the Certificate Authority, which can lead to errors and is complicated for those unfamiliar with the process, especially for Web sites using proxy domain name registrations that obscure the owner's identity.

Innovation Solution

The solution involves direct communication between the Hosting Provider and the Certificate Authority, eliminating the need for the Subscriber as an intermediary, where the Hosting Provider generates a key pair and CSR, and the CA verifies the Subscriber's identity, with the CA directly transmitting the Certificate to the Hosting Provider for installation on the Web site.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the Subscriber acts as an intermediary to coordinate between the Hosting Provider and Certificate Authority, then the SSL certificate can be obtained, but the process becomes cumbersome and error-prone

Engineering Contradiction:
ImproveSSL certificate issuance reliabilityVSAvoidSSL enablement process simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent extracts the Subscriber from the coordination process between Hosting Provider and Certificate Authority. The CA now communicates directly with the Hosting Provider, eliminating the Subscriber's intermediary role and the associated coordination errors while maintaining certificate issuance reliability

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The Hosting Provider becomes the new intermediary that receives verification requests from the CA and relays them to the Subscriber. This structured mediation through the Hosting Provider's control panel reduces errors compared to direct Subscriber coordination

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If proxy domain name registration is used to protect owner identity, then privacy is improved, but SSL certificate verification becomes more difficult

Engineering Contradiction:
ImproveIdentity verification reliabilityVSAvoidOwner contact information accessibility
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The Hosting Provider acts as an intermediary that the CA can contact through controlled channels. The Hosting Provider receives verification requests from the CA and forwards them to the Subscriber via the control panel, enabling identity verification while maintaining the privacy benefits of proxy registration

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The control panel serves multiple functions: it manages domain registration, handles SSL certificate requests, and facilitates verification communication. This universal interface enables the Subscriber to maintain privacy while still allowing necessary verification processes to occur

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If the Subscriber manually coordinates the SSL certificate process, then flexibility is maintained, but the complexity of the process increases

Engineering Contradiction:
ImproveProcess flexibilityVSAvoidSSL enablement process complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The Hosting Provider's control panel provides self-service functionality for SSL certificate management. The Subscriber can initiate certificate requests and receive notifications through the control panel without manual coordination, reducing complexity while maintaining the flexibility to choose different certificate types and CAs

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS7702902B2Method for a web site with a proxy domain name registration to receive a secure socket layer certificate
Publication Date: 2010.04.20 GO DADDY OPERATING CO LLC
  • US7702902B2 patent drawing
  • US7702902B2 patent drawing
  • US7702902B2 patent drawing

AI summary

The present invention provides systems and methods for enabling encrypted communication capabilities for a Subscriber's Web Site, thereby allowing Customers to access the Subscriber's Web Site in a secure manner. The Subscriber may register a domain name associated with the Subscriber's Web Site using a proxy domain name service, thereby hindering its Customers ability to verify the owner of the Subscriber's Web Site. A Hosting Provider hosts the Subscriber's Web Site and a Certificate Authority (CA) verifies the identity of the Subscriber. In combination the Hosting Provider and CA provide the Subscriber's Web Site with Secure Sockets Layer (SSL) encrypted communications capability. The Hosting Provider and CA communicate directly with each other as needed, typically via the Internet, without using the Subscriber as an intermediary in their communications.