Wireless Mail Server Certificate Extraction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In public key infrastructure systems, users face difficulties in managing identity certificates, particularly when certificates are delivered via email, as it requires manual recognition and download by the user device, which can be cumbersome, especially for non-technical users, and may lack context due to delays between request and delivery.

Innovation Solution

A method where the wireless mail server automatically scans incoming messages for attached certificates, extracts them, and transmits them to the user device over a configuration channel, eliminating the need for on-device user management and ensuring the certificate includes an object identifier for improved management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If certificates are delivered via email requiring manual recognition and download by the user device, then the certificate delivery mechanism is simple and widely compatible, but the ease of operation deteriorates as it is cumbersome for non-technical users and may lack context due to delays between request and delivery

Engineering Contradiction:
Improvecertificate delivery compatibilityVSAvoiduser operation simplicity
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent introduces an intermediary system (certificate management system) between the certificate authority and the user device. This intermediary automatically receives certificates from the CA, extracts relevant information including context about the certification request, and delivers them to the appropriate user devices without requiring manual user intervention. This resolves the contradiction by maintaining email-based delivery compatibility while eliminating the operational burden on users.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If certificates are delivered manually via email, then the delivery mechanism is simple, but the loss of information increases as certificates may lack context due to delays between request and delivery

Engineering Contradiction:
Improvedelivery system complexityVSAvoidcertificate context information
Core Design Contradiction:
Device complexityVSLoss of information

Solution Approach 1:

The patent implements preliminary action by having the certificate management system automatically extract and attach context information about the certification request to the certificate before delivery. This includes information about what the certificate is for, when it was requested, and other relevant metadata. By preparing this information in advance and attaching it to the certificate, the system prevents information loss that would otherwise occur due to delays between request and delivery.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If automatic certificate extraction and transmission is implemented, then the ease of operation improves by eliminating manual user management, but the device complexity increases as it requires server-side automation

Engineering Contradiction:
Improveuser operation simplicityVSAvoidsystem architecture complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements self-service by enabling the certificate management system to automatically perform all certificate delivery operations without human intervention. The system monitors for incoming certificates from the CA, automatically extracts them, determines the appropriate destination devices, and transmits them through appropriate channels. This automation eliminates the need for user action while managing the complexity through standardized protocols and automated decision-making logic.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP2180634B1Method of handling a certification request
Publication Date: 2018.04.04 BLACKBERRY LTD
  • EP2180634B1 patent drawingFigure 1
  • EP2180634B1 patent drawingFigure 2
  • EP2180634B1 patent drawingFigure 3

AI summary

In a certification request, a user device includes an object identifier. When a certification authority generates an identity certificate responsive to receiving the certification request, the certification authority includes the object identifier, thereby allowing improved management of the identity certificate at the user device and elsewhere.