Bootstrap Message Protection in Device Management Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current bootstrap message transmission in mobile device management networks is insecure, as it relies on non-secret keys like IMSI or ESN for encryption, allowing attackers to hijack or impersonate devices by creating or eavesdropping on these messages, which contain credentials.

Innovation Solution

A method and apparatus that involve a first network unit receiving a request to bootstrap a device, transmitting subscriber information to a second network unit to obtain a bootstrap key, and using this key to protect the bootstrap message, ensuring only the network and device possess the secret key, thus preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If non-secret keys like IMSI or ESN are used for encryption of bootstrap messages, then the bootstrap process can be initiated, but the security of the bootstrap message is compromised allowing attackers to hijack or impersonate devices

Engineering Contradiction:
Improvebootstrap process initiationVSAvoidsecurity of bootstrap message
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the secret key material from the device side and places it exclusively on the network side (DM server and authentication center). The bootstrap message is encrypted using this extracted secret key that only the network possesses, rather than using shared or device-side keys like IMSI/ESN. This extraction of the secret from the device resolves the security vulnerability while maintaining bootstrap functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an authentication center as an intermediary that generates and manages the secret key used for encrypting bootstrap messages. This intermediary entity mediates between the DM server and the device, providing secure key management. The authentication center acts as a trusted third party that enables secure communication without requiring the device to store or manage secret key material.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the bootstrap message contains credentials such as username and password, then the device can be authenticated, but attackers can eavesdrop and impersonate the device

Engineering Contradiction:
Improvedevice authenticationVSAvoideavesdropping and impersonation attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent converts the potential harm of transmitting credentials over the air interface into a benefit by using the same transmission mechanism for both purposes. The bootstrap message containing credentials is encrypted with a secret key that only the network possesses, transforming the vulnerable clear-text transmission into a secure authenticated communication channel. The harm of over-the-air transmission is converted into benefit through network-side secret key encryption.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Solution Approach 2:

The patent changes the encryption parameter from using device-side identifiers (IMSI, ESN) to using network-side secret keys. This parameter change in the encryption mechanism fundamentally alters the security properties of the bootstrap message transmission, making eavesdropping and impersonation attacks infeasible while maintaining the ability to authenticate devices.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If the IMSI or ESN is used as the encryption key, then the bootstrap message can be protected, but these identifiers have not been designed to be secret

Engineering Contradiction:
Improveintegrity protection of bootstrap messageVSAvoidweak protection against attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the secret key functionality from device identifiers (IMSI, ESN) and relocates it to the network infrastructure. Instead of using these public identifiers for encryption, the system extracts and uses dedicated secret keys that exist only on the network side (DM server and authentication center). This extraction resolves the fundamental mismatch between using non-secret identifiers for secret key purposes.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10313116B2Apparatuses and a method for protecting a bootstrap message in a network
Publication Date: 2019.06.04 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US10313116B2 patent drawing
  • US10313116B2 patent drawing
  • US10313116B2 patent drawing

AI summary

The embodiments of the present invention relate to apparatuses in the form of a first network unit and a device, and also relates to a method for enabling protection of a bootstrap message in a device management network system. The method comprises: receiving at the first network unit, a request to bootstrap the device; transmit a request for a bootstrap key, to a second network unit; receiving a message comprising the bootstrap key and further comprises trigger information and transmitting the trigger information to the device to trigger generation of the bootstrap key internally in the device. Thereafter a protected bootstrap message can be transmitted to the device from the first network unit, and when the device verifies and/or decrypts the bootstrap message, device management (DM) sessions can start between the device and the first network unit.