Trusted Device Mediates Enterprise Certificate Provisioning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Businesses face challenges in securely provisioning personal computing devices for enterprise network access without relying on third-party services, as users often need to register and download software, which can limit access to corporate network resources.
Innovation Solution
A system utilizing a trusted computing device as an intermediary to generate and securely export access certificates to personal computing devices, allowing direct access to enterprise networks through bi-directional wireless communication and public-key infrastructure, eliminating the need for third-party services.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If third-party service providers are used for device registration and software download, then secure access to corporate network resources is achieved, but device complexity and reliance on external services increases
Solution Approach 1:
The patent extracts the third-party service provider from the provisioning process by implementing direct peer-to-peer communication between the personal computing device and the enterprise network. The personal device directly obtains authentication credentials from the enterprise network without requiring intermediate third-party services, thereby eliminating dependency on external providers while maintaining secure access.
Solution Approach 2:
The patent introduces a trusted computing device as an intermediary that facilitates direct communication between the personal computing device and the enterprise network. This intermediary enables the personal device to obtain authentication credentials directly from the enterprise network without requiring third-party service providers, thus simplifying the provisioning process while maintaining security.
2Reliability
If third-party service providers are used for device provisioning, then authentication security is maintained, but access to corporate network resources becomes limited
Solution Approach 1:
The patent removes the limiting influence of third-party service providers by establishing direct authentication between personal computing devices and the enterprise network. This extraction eliminates the intermediary layer that previously restricted access, allowing personal devices to directly access a broader range of corporate network resources while maintaining authentication security through direct credential verification.
Solution Approach 2:
The patent implements a universal authentication mechanism that enables personal computing devices to access multiple types of corporate network resources directly. The authentication system is designed to be broadly applicable, allowing devices to connect to various network services without being constrained by third-party provider limitations, thus enhancing both security and versatility.
3Reliability
If users register with third-party providers and download software, then secure access is established, but ease of operation decreases
Solution Approach 1:
The patent extracts the complex software installation and registration steps from the provisioning process by implementing direct peer-to-peer authentication. Personal computing devices can connect to the enterprise network without requiring users to download and install third-party software or complete lengthy registration forms, significantly simplifying the operation while maintaining secure access through direct credential verification.
Solution Approach 2:
The trusted computing device acts as an automated intermediary that handles the authentication process without requiring manual user intervention for software installation or registration. This intermediary enables seamless connection by automatically verifying credentials and establishing secure communication, making the provisioning process as easy as simply connecting to the network.
4Ease of operation
If direct access to enterprise networks is enabled, then ease of operation and user convenience are improved, but security risks increase
Solution Approach 1:
The patent introduces a trusted computing device as a security intermediary that mediates between the personal computing device and the enterprise network. This intermediary performs thorough authentication of personal devices before allowing direct access to the enterprise network, thereby enabling ease of operation while mitigating security risks through controlled verification of credentials and trust establishment.
Data Source
AI summary
Technologies for securely provisioning a personal computing device for enterprise connectivity includes a trusted computing device for wirelessly communicating with the personal computing device, generating a key pair for the personal computing device, generating a certificate signing request, sending the certificate signing request on behalf of the personal computing device, receiving an access certificate for enterprise connectivity, and securely exporting the access certificate and a private key of the key pair to the personal computing device.


