Bootstrap Message Protection in Device Management Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current bootstrap message transmission in mobile device management networks is insecure, as it relies on non-secret keys like IMSI or ESN for encryption, allowing attackers to hijack or impersonate devices by creating or eavesdropping on these messages, which contain credentials.
Innovation Solution
A method and apparatus that involve a first network unit receiving a request to bootstrap a device, transmitting subscriber information to a second network unit to obtain a bootstrap key, and using this key to protect the bootstrap message, ensuring only the network and device possess the secret key, thus preventing unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If non-secret keys like IMSI or ESN are used for encryption of bootstrap messages, then the bootstrap process can be initiated, but the security of the bootstrap message is compromised allowing attackers to hijack or impersonate devices
Solution Approach 1:
The patent extracts the secret key material from the device side and places it exclusively on the network side (DM server and authentication center). The bootstrap message is encrypted using this extracted secret key that only the network possesses, rather than using shared or device-side keys like IMSI/ESN. This extraction of the secret from the device resolves the security vulnerability while maintaining bootstrap functionality.
Solution Approach 2:
The patent introduces an authentication center as an intermediary that generates and manages the secret key used for encrypting bootstrap messages. This intermediary entity mediates between the DM server and the device, providing secure key management. The authentication center acts as a trusted third party that enables secure communication without requiring the device to store or manage secret key material.
2Reliability
If the bootstrap message contains credentials such as username and password, then the device can be authenticated, but attackers can eavesdrop and impersonate the device
Solution Approach 1:
The patent converts the potential harm of transmitting credentials over the air interface into a benefit by using the same transmission mechanism for both purposes. The bootstrap message containing credentials is encrypted with a secret key that only the network possesses, transforming the vulnerable clear-text transmission into a secure authenticated communication channel. The harm of over-the-air transmission is converted into benefit through network-side secret key encryption.
Solution Approach 2:
The patent changes the encryption parameter from using device-side identifiers (IMSI, ESN) to using network-side secret keys. This parameter change in the encryption mechanism fundamentally alters the security properties of the bootstrap message transmission, making eavesdropping and impersonation attacks infeasible while maintaining the ability to authenticate devices.
3Reliability
If the IMSI or ESN is used as the encryption key, then the bootstrap message can be protected, but these identifiers have not been designed to be secret
Solution Approach 1:
The patent extracts the secret key functionality from device identifiers (IMSI, ESN) and relocates it to the network infrastructure. Instead of using these public identifiers for encryption, the system extracts and uses dedicated secret keys that exist only on the network side (DM server and authentication center). This extraction resolves the fundamental mismatch between using non-secret identifiers for secret key purposes.
Data Source
AI summary
The embodiments of the present invention relate to apparatuses in the form of a first network unit and a device, and also relates to a method for enabling protection of a bootstrap message in a device management network system. The method comprises: receiving at the first network unit, a request to bootstrap the device; transmit a request for a bootstrap key, to a second network unit; receiving a message comprising the bootstrap key and further comprises trigger information and transmitting the trigger information to the device to trigger generation of the bootstrap key internally in the device. Thereafter a protected bootstrap message can be transmitted to the device from the first network unit, and when the device verifies and/or decrypts the bootstrap message, device management (DM) sessions can start between the device and the first network unit.


