Token Certificate Renewal Without Re-enrollment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional certificate systems require re-enrollment of tokens for certificate renewal, which involves generating a new key pair and reformating the token, making the process cumbersome and time-consuming.

Innovation Solution

A method and system for renewing digital certificates on tokens that allows the renewed certificate to reuse the same key as the original certificate, eliminating the need for new key generation and token reformatting, thereby simplifying and speeding up the renewal process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional certificate systems require re-enrollment of tokens for certificate renewal, then the certificate can be renewed with a new key pair, but the process becomes cumbersome and time-consuming

Engineering Contradiction:
Improvecertificate renewalVSAvoidrenewal process time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by generating a new key pair and creating the renewed certificate in advance on the certificate system before the token is physically re-enrolled. This allows the renewal process to be completed remotely and efficiently, reducing the time the token needs to be offline and the complexity of the renewal process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The certificate system acts as an intermediary that handles the complex key pair generation and certificate creation processes remotely. Instead of requiring direct interaction between the token and the enrollment system, the certificate system mediates the renewal process by receiving the old certificate, generating new credentials, and returning the renewed certificate to the token.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If conventional certificate systems require re-enrollment of tokens for certificate renewal, then the certificate can be renewed, but the token requires reformatting which increases process complexity

Engineering Contradiction:
Improvecertificate renewalVSAvoidtoken reformatting process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The invention extracts the complex key pair generation and certificate creation operations from the token reformatting process. By performing these operations remotely on the certificate system and only transferring the final renewed certificate to the token, the patent separates the computationally intensive tasks from the physical token manipulation, thereby reducing overall process complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system creates a copy of the certificate renewal process that can be executed remotely. Instead of requiring the token to physically go through reformatting and re-enrollment, the certificate system generates a renewed certificate (a copy with updated expiration date and new key pair) and transfers it to the token, simplifying the physical operations required.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS8683196B2Token renewal
Publication Date: 2014.03.25 RED HAT INC
  • US8683196B2 patent drawing
  • US8683196B2 patent drawing
  • US8683196B2 patent drawing

AI summary

A method and system for renewing certificates stored on tokens is described.