Wildcard Certificate Provisioning for Browser-Trusted Local Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions for providing digital certificates in local IT infrastructures, such as those in hospitals, face challenges with self-signed certificates not being trusted by modern browsers and the complexity and cost of setting up internal trust authorities, while service providers struggle to issue certificates based on local domains without proving ownership.
Innovation Solution
A method for providing digital certificates to devices within a local IT infrastructure using a server outside the infrastructure, which involves receiving a device identification dataset, determining a key creation dataset, sending this to the device, and requesting a wildcard certificate from a certificate authority based on a domain name, allowing self-service initiation and minimizing service provider work.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If self-signed certificates are used for every device in local IT infrastructure, then secured communication between local devices is enabled, but modern internet browsers block the communication or show security warnings
Solution Approach 1:
The patent introduces an intermediary certificate authority service that issues certificates signed by a trusted external CA (such as Let's Encrypt). This intermediary resolves the contradiction by providing certificates that are both trusted by browsers (satisfying ease of operation) and enable secured communication (satisfying reliability). The service acts as a mediator between the local IT infrastructure and the external certificate authority.
Solution Approach 2:
The patent implements a self-service mechanism where devices in the local IT infrastructure can automatically obtain certificates without manual intervention. The system autonomously interacts with the certificate authority service, performs domain verification, and retrieves certificates. This self-service approach resolves the contradiction by enabling reliable secured communication while maintaining browser compatibility, without requiring users to manually configure complex certificate infrastructure.
2Adaptability or versatility
If an Internal Trust Authority is used within local IT infrastructure, then digital certificates can be issued and managed locally, but the setup process becomes complicated and cost-intensive
Solution Approach 1:
The patent extracts the complex certificate authority functionality from the local IT infrastructure and relocates it to an external service provider. Instead of deploying and maintaining a full internal trust authority, the system uses an external CA service that can be accessed over the network. This extraction resolves the contradiction by providing local certificate management capabilities (adaptability) while eliminating the complexity and cost of setting up and maintaining internal infrastructure.
Solution Approach 2:
The patent employs a universal certificate authority service that can serve multiple clients and domains through a single external infrastructure. The external CA service provides multi-functional capabilities, handling certificate issuance, renewal, and revocation for various devices and domains within the local IT infrastructure. This universal approach resolves the contradiction by enabling comprehensive local certificate management without requiring dedicated internal trust authority infrastructure for each client.
3Ease of manufacture
If a service provider uses a domain controlled by the service provider for certificates, then certificates can be issued, but requests directed to those domains cannot be resolved to a local IP address within the local IT infrastructure
Solution Approach 1:
The patent uses a copying approach where the service provider obtains a certificate for a domain they control (such as a subdomain of their domain), then uses this certificate to secure communication for local services. The certificate is effectively copied or reused across different contexts. This resolves the contradiction by enabling certificate issuance (ease of manufacture) while maintaining domain resolution capability, as the certificate can be applied to local services accessed through local domain names or IP addresses.
Solution Approach 2:
The patent segments the domain structure by using subdomains or specific domain patterns that can be controlled by the service provider while still allowing local resolution. For example, using patterns like <device-id>.service-provider.com that can be resolved locally through DNS configuration. This segmentation resolves the contradiction by enabling the service provider to control the certificate domain while maintaining the ability to resolve requests to local IP addresses through appropriate DNS settings.
4Adaptability or versatility
If the service provider requests a certificate based on a local IT infrastructure domain, then certificates can be issued for local domains, but the service provider cannot prove ownership of the domain
Solution Approach 1:
The patent implements preliminary action by having the service provider pre-configure DNS records or other verification mechanisms that prove domain control before requesting certificates. The system performs preliminary domain verification by setting up DNS TXT records or CNAME records that the certificate authority can verify. This preliminary action resolves the contradiction by enabling the service provider to obtain certificates for local domains (adaptability) while providing the necessary proof of domain ownership or control (reliability).
Solution Approach 2:
The patent uses an intermediary verification mechanism where a trusted third party or automated system verifies the service provider's domain ownership before issuing certificates. The verification process acts as an intermediary that confirms the service provider's authority to use the domain without requiring direct physical control. This intermediary verification resolves the contradiction by enabling local domain certificates (adaptability) while maintaining reliable domain ownership proof through automated verification processes.
Data Source
AI summary
A method for providing a digital certificate to a device, comprises: receiving a device identification dataset, uniquely identifying the device; determining a key creation dataset including a certificate identifier, the certificate identifier being based on the device identification dataset; sending the key creation dataset to the device; receiving a certificate creation request related to a first domain name based on the key creation dataset from the device, the first domain name including the certificate identifier; sending the certificate creation request or a modified certificate creation request to a certificate authority; and providing the digital certificate to the device, the digital certificate being a wildcard certificate based on the first domain name signed by the certificate authority.


