Trusted Device Mediates Enterprise Certificate Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Businesses face challenges in securely provisioning personal computing devices for enterprise network access without relying on third-party services, as users often need to register and download software, which can limit access to corporate network resources.

Innovation Solution

A system utilizing a trusted computing device as an intermediary to generate and securely export access certificates to personal computing devices, allowing direct access to enterprise networks through bi-directional wireless communication and public-key infrastructure, eliminating the need for third-party services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If third-party service providers are used for device registration and software download, then secure access to corporate network resources is achieved, but device complexity and reliance on external services increases

Engineering Contradiction:
Improvesecure access to corporate networkVSAvoidregistration and software installation process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the third-party service provider from the provisioning process by implementing direct peer-to-peer communication between the personal computing device and the enterprise network. The personal device directly obtains authentication credentials from the enterprise network without requiring intermediate third-party services, thereby eliminating dependency on external providers while maintaining secure access.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a trusted computing device as an intermediary that facilitates direct communication between the personal computing device and the enterprise network. This intermediary enables the personal device to obtain authentication credentials directly from the enterprise network without requiring third-party service providers, thus simplifying the provisioning process while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If third-party service providers are used for device provisioning, then authentication security is maintained, but access to corporate network resources becomes limited

Engineering Contradiction:
Improveauthentication securityVSAvoidaccess to corporate network resources
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent removes the limiting influence of third-party service providers by establishing direct authentication between personal computing devices and the enterprise network. This extraction eliminates the intermediary layer that previously restricted access, allowing personal devices to directly access a broader range of corporate network resources while maintaining authentication security through direct credential verification.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements a universal authentication mechanism that enables personal computing devices to access multiple types of corporate network resources directly. The authentication system is designed to be broadly applicable, allowing devices to connect to various network services without being constrained by third-party provider limitations, thus enhancing both security and versatility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If users register with third-party providers and download software, then secure access is established, but ease of operation decreases

Engineering Contradiction:
Improvesecure accessVSAvoiddevice provisioning process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent extracts the complex software installation and registration steps from the provisioning process by implementing direct peer-to-peer authentication. Personal computing devices can connect to the enterprise network without requiring users to download and install third-party software or complete lengthy registration forms, significantly simplifying the operation while maintaining secure access through direct credential verification.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The trusted computing device acts as an automated intermediary that handles the authentication process without requiring manual user intervention for software installation or registration. This intermediary enables seamless connection by automatically verifying credentials and establishing secure communication, making the provisioning process as easy as simply connecting to the network.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Ease of operation

If direct access to enterprise networks is enabled, then ease of operation and user convenience are improved, but security risks increase

Engineering Contradiction:
Improvedirect network accessVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a trusted computing device as a security intermediary that mediates between the personal computing device and the enterprise network. This intermediary performs thorough authentication of personal devices before allowing direct access to the enterprise network, thereby enabling ease of operation while mitigating security risks through controlled verification of credentials and trust establishment.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9621540B2Secure provisioning of computing devices for enterprise connectivity
Publication Date: 2017.04.11 INTEL CORP
  • US9621540B2 patent drawing
  • US9621540B2 patent drawing
  • US9621540B2 patent drawing

AI summary

Technologies for securely provisioning a personal computing device for enterprise connectivity includes a trusted computing device for wirelessly communicating with the personal computing device, generating a key pair for the personal computing device, generating a certificate signing request, sending the certificate signing request on behalf of the personal computing device, receiving an access certificate for enterprise connectivity, and securely exporting the access certificate and a private key of the key pair to the personal computing device.