Centralized Third Tier Server Certificate Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In distributed application environments, particularly those with third tier servers in non-continuous client-server connections, managing and verifying server certificates is cumbersome and insecure, as each server application maintains local certificate databases, requiring extensive effort and potential manual user intervention, which can lead to security vulnerabilities.

Innovation Solution

A central procedure at the client system manages and recognizes third tier server certificates, storing accepted certificates in a common database, and transmitting fingerprints and server information to server systems for verification, eliminating the need for local certificate databases on servers and ensuring secure connections without continuous client-server activity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If each server application maintains local certificate databases, then certificate verification can be performed independently on each server, but the complexity of certificate management increases significantly and security vulnerabilities arise

Engineering Contradiction:
Improvecertificate verification capabilityVSAvoidcertificate management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the certificate management functionality from multiple distributed server applications into a single centralized certificate manager component. This centralization consolidates what were previously multiple separate local certificate databases into one unified management system, reducing overall complexity while maintaining verification capabilities across all servers.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The centralized certificate manager is designed as a universal component that serves multiple server applications simultaneously. Instead of each server having its own dedicated certificate management system, the universal certificate manager provides certificate verification services to all servers, eliminating redundancy and simplifying management.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If manual user interaction is required for certificate acceptance, then security decisions can be made by users, but the ease of operation decreases and administrative effort increases

Engineering Contradiction:
Improvesecurity decision qualityVSAvoidcertificate management ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The certificate manager implements automated self-service functionality by establishing secure connections to certificate authorities and automatically retrieving, verifying, and managing certificates. This eliminates the need for manual user interaction in routine certificate management tasks while maintaining security through automated verification processes.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by proactively obtaining certificates from certificate authorities before they are needed for server operations. The certificate manager automatically retrieves and validates certificates in advance, so that when servers need to establish secure connections, the certificates are already available and verified, eliminating the need for manual intervention at critical moments.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If secure connections are established with third tier servers, then data transmission security is improved, but the complexity of managing certificate exchanges increases

Engineering Contradiction:
Improvedata transmission securityVSAvoidcertificate exchange management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The certificate manager acts as an intermediary between the server applications and the certificate authorities. It handles all certificate exchange operations centrally, mediating between the need for secure connections and the complexity of certificate management. The intermediary automatically manages the entire certificate lifecycle including retrieval, verification, and distribution to relevant servers.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If local certificate databases are maintained on each server, then verification can occur without continuous client-server connection, but the loss of time for certificate updates increases

Engineering Contradiction:
Improveverification capability without continuous connectionVSAvoidcertificate update time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The certificate manager performs preliminary actions by obtaining and caching certificates from certificate authorities in advance, before they are needed for verification. This allows servers to perform local verification without continuous connection to the client or certificate authority, while the certificates are automatically updated in the background at appropriate intervals, minimizing the time loss for updates.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8990415B2Method and system for authenticating servers in a distributed application environment
Publication Date: 2015.03.24 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US8990415B2 patent drawing
  • US8990415B2 patent drawing
  • US8990415B2 patent drawing

AI summary

The present invention discloses a method and system for authenticating third tier servers in a distributed application environment by using a central procedure for recognizing and managing third tier server certificates at the client system side. Third tier server certificates which have been accepted by the central procedure are stored in a common database of the distributed application environment and the client system transmits via a secure connection to the server systems all necessary information of said third tier server certificates being accepted as trustworthy for determining to accept or to decline a third tier server. In a preferred embodiment of the present invention only fingerprints of third tier server certificates being accepted as trustworthy together with server name which has transmitted said third tier server certificate, and certificate name are transferred via a secure connection to the server systems of the distributed application environment.